Anthropic disclosed that it disrupted five instances in which actors attempted to use its AI models in ways that could support the development of biological weapons. The company outlined real-world case studies it uncovered and disrupted between December and August. In two of those cases, researchers reportedly sought Claude's assistance for gain-of-function research on dangerous viruses — experiments that enhance pathogens in the lab to better understand their characteristics and pandemic potential.
Why this matters
The assessment emphasizes that biological capabilities are dual-use: the same tools can serve beneficial research or be repurposed for harm. The report notes it is difficult to determine intent, particularly when sophisticated or state-associated actors evade access controls.
The report states, "We take these cases as evidence not of the imminence of biological threats currently uplifted by Claude, but rather as evidence that significant dual-use research efforts are associated with state actors of concern who routinely evade our access controls." It adds that safeguarding access will require account and institutional signals to verify user legitimacy and data retention to identify misuse.
Technical context and growing concerns
Anthropic's most recent models have been launched with safeguards that restrict access to biological research queries that could be misused. Still, other developments are raising alarms: a Stanford research team last month reported using a different generative AI to design a synthetic virus — the first known instance of the technology being used to create an organism not found in nature.
In a survey by the Institute for Security and Technology conducted this month, more than 100 national security experts were asked about AI and biological risk; 70% said they believe AI meaningfully increases the risk of developing a bioweapon, or will do so within two to three years. Experts say AI's chief threat is lowering the barrier to entry for less-skilled actors and states, and that the primary concern is biology capable of unleashing pandemics rather than chemical attacks.
What AI can do that raises risk
Researchers from Fordham, Johns Hopkins, Oxford, Stanford, Columbia and New York University warned earlier this year that current models have capabilities that could be misused. According to their analysis, models can design new caps that enclose viral DNA, forecast pathogen evolution, create nucleic acid sequences in DNA or RNA that evade safety-screening software, and design viral genomes that are more potent when synthesized in laboratories.
They also cautioned that AI developers are releasing new, more efficient biological models often without basic safety assessments — a practice that would not be tolerated in other parts of life-sciences research.
Threat level and policy responses
A key worry is that advanced AI enables malicious actors to carry out complex technical tasks with little expertise. Training models on data linking a virus's genetics to real-world traits — such as transmissibility or immune evasion — could lower the barrier for creating dangerous pathogens, the experts warn.
There are increasing calls for government review of emerging AI models and for safety standards similar to those applied to other sensitive technologies, replacing the current system of voluntary consultations between AI labs and federal officials. One potential focal point is the Department of Commerce's Center for AI Standards and Innovation (CAISI), established last year to guide national standard-setting.
Tom Inglesby, director of the Johns Hopkins Center for Health Security, told Axios: "We have this moment to step back and say what do we want this future of AI to look like and what's part of that ecosystem?" He added that the public needs to know whether the most powerful models developed in the country are being reviewed for high-end national security risks.
Some experts argue for systems built for specific research functions — such as Google DeepMind's AlphaFold — that do not operate as autonomous agents. Hamza Chaudhry, AI and national security lead at the Future of Life Institute, warned that adding autonomy introduces uncertainty that could be dangerous because future behavior may become unpredictable, and autonomy can increase as quickly as intelligence.
What to watch next
Policymakers' response to these warnings is the central question. Proposed measures in Congress include a "kill switch" bill that would give the government authority to deactivate AI models capable of causing catastrophic harm, and another proposal that would create a legal framework for AI developers to coordinate against emerging AI-specific security risks.
Anthropic's disclosures highlight how rapidly AI is reshaping the life sciences and underscore gaps in the patchwork of laws and institutions that currently oversee high-risk research.



