Published Sep 11, 2026 | 11:32 AM ⚊ Updated Sep 11, 2026 | 11:33 AM
Image used for representational purpose. (AI generated)
Synopsis: Anthropic says researchers used Claude for potentially risky biological research, including chikungunya gain-of-function and avian influenza mammalian-adaptation experiments. The AI company blocked high-risk requests, restricted access to stronger models, banned accounts and disrupted attempts to bypass safeguards. The cases highlight growing challenges in distinguishing legitimate scientific research from potentially dangerous biological applications.
Were researchers who turned to Claude to explore how viruses spread, evade immune responses or adapt to mammals inadvertently engaging in research that could support biological weapons development?
The question arose after Anthropic outlined five cases in its report, Detecting and countering misuse of AI: September 2026, where users applied Claude to research that could support biological weapons development. Anthropic detected the activity and moved to tighten safeguards around its models.
The cases cover chikungunya, avian influenza, orthopoxviruses, venom peptides and toxins. Anthropic banned the accounts and fed the findings into its safety systems. The company stated that the cases do not prove Claude produced a biological weapon.
“Biological misuse is one of the most serious risks of frontier AI models. Without the correct safeguards, such capabilities could have catastrophic consequences,” Anthropic said.
In May 2026, Anthropic’s biological safety classifier blocked a request to help draft a grant application involving gain-of-function research on chikungunya virus. The work targeted the virus’s transmissibility and its ability to dodge the immune system.
“The grant sought to identify enhancing mutations in the chikungunya virus, engineer them into infectious clones, and select for virulence in vivo. The virus would become progressively more harmful as it repeatedly infected live animals,” Anthropic said.
Chikungunya spreads through mosquitoes and already circulates naturally, which raises a separate concern. Anthropic noted that a deliberate release of the virus would blend into a natural outbreak, making it hard to trace.
The institutional link attached to the grant added to the worry. The application described the work as civilian, but Anthropic found it was set to run inside a military research institute.
Anthropic traced the request through an intermediary platform serving life sciences researchers, including virologists tied to civilian and military institutions. The platform operated from regions where Anthropic does not offer service and routed traffic through US infrastructure to get around regional blocks.
“The developers of this platform used Claude through grey market resellers and synthetic accounts. The developer’s desire to improve the user experience of academic researchers led them to build a fallback mechanism that sent refused requests to a competitor’s model,” Anthropic said.
Anthropic banned the accounts and worked with partners to shut down the relay networks. The operator returned within days, rebuilding access through fresh identities and consumer subscriptions.
The report also noted that Claude had assisted with the platform’s own code. Anthropic said the tool had written much of the routing system after it was presented as a fix for over-refusal.
The chikungunya research itself continued, with Claude providing editorial help on the resulting documents. Anthropic said these papers described the viral changes as a loss of function rather than a gain, a framing the company read as an attempt to mask the true nature of the work.
Also Read: ‘AI could kill us all by the end of the decade’: Anthropic researcher resigns with stark warning
The chikungunya case did not stand alone. In May 2026, Anthropic found a researcher outside the US using Claude in research on highly pathogenic avian influenza, known as bird flu. The work examined how the virus adapts to mammals and how it causes disease beyond the airway.
“There is near-zero population immunity in humans, and when spillovers occur, the effects are fatal in roughly half of confirmed human cases. Despite this, the viruses do not yet spread efficiently between people,” Anthropic said.
The report also flagged disease appearing outside the lungs in some strains. Anthropic said H5 viruses have reached the brain in several mammal species and in many human cases, which would complicate diagnosis and treatment if it emerged in a pandemic strain.
The researcher reached Claude from an unsupported region through US virtual server infrastructure and a privacy-focused email account. The exchange ran for weeks and built up to thousands of messages.
“The researcher leveraged Claude’s knowledge of the scientific literature to assist in study planning and design, data analysis, and the interpretation and prioritisation of experiments,” Anthropic said.
Anthropic’s safeguards kept the researcher confined to weaker models throughout the exchange. The company said the work ran on Claude Sonnet 4 and Haiku 4.5, and that the uplift stayed limited to clerical support in analysis and study design.
Anthropic frames the dual nature of biological research as the core problem behind these cases. Work that helps detect a natural pandemic threat can just as easily help build one.
“Biological capabilities are dual use: they can be used for beneficial or harmful purposes, and it is often difficult to distinguish between them,” Anthropic said.
The report also argued that this grey area favours sophisticated actors over obvious ones. Anthropic said overt intent tends to signal a less capable actor, while skilled users extract help through interactions that look ordinary on the surface but reveal warning signs once reviewed in full.
Anthropic identified three further cases involving orthopoxviruses, venom peptides and toxins. One case ran through a reseller relay rather than a single user, serving more than a dozen customers who exchanged tens of thousands of messages with Claude in days.
“The grant itself was one customer’s run entirely on Opus 5 in about an hour, in which the user used Claude to draft the application end to end, including the hypothesis, experimental design and statistical plans,” Anthropic said.
A separate case involved a venom peptide atlas built around a stated therapeutic goal. Anthropic said the underlying system also held scaffolds tied to paralytic targets, structures controlled under international dual-use export rules.
In a fifth case, a researcher worked with Claude on the computational redesign of several toxins while withholding key details from progress reports. Anthropic said the researcher directed Claude to keep the identity of the toxins and viral proteins deliberately vague.
Anthropic banned both accounts in May 2026 for breaching its Supported Regions Policy. The company said these cases exposed the limits of relying on classifiers alone, since intent in highly technical dual-use work often stays hidden from automated review.
Anthropic pushed back against reading these cases as proof that Claude has already helped build a biological weapon. The company reviewed 30 days of activity tied to state institutions of concern and found around 35 research efforts, most of them ordinary civilian science.
“We take these cases as evidence not of the imminence of biological threats currently uplifted by Claude, but rather as evidence that significant dual-use research efforts are associated with state actors of concern,” Anthropic said.
The company said these actors routinely work to evade access controls through relays, data retention loopholes and model switching, often with full awareness of the dual-use nature of their research.
Anthropic closed its report by pointing to where it believes the industry needs to head next. The company said future protection will need to combine safety filters on the highest-risk content with trusted user programmes that allow verified researchers continued access.
Also Read:
Patients are bringing AI diagnoses to fertility clinics. Doctors say AI can explain, but not decide
How AI-powered handheld devices are bringing breast and cervical cancer screening to Telangana PHCs
(Edited by R Rajesh Kumar.)