Hot Topics
Technology

Anthropic identified and disrupted five cases in which actors used its Claude models in ways that could support biological weapons development

Anthropic blocked five cases of potential biological weapons assistance and six conventional weapons cases in its Claude models over eight months, prompting fresh safety and regulatory debate.

Anthropic identified and disrupted five cases in which actors used its Claude models in ways that could support biological weapons development

The incidents occurred between December 2025 and August 2026 and form part of a broader threat intelligence report covering state-linked groups, cybercriminals and propaganda organisations. The company also recorded six cases involving conventional weapons software and multiple instances of cyber espionage and influence operations. This article examines the reported misuse patterns, the safeguards applied and the wider context of AI safety concerns raised by researchers and policymakers.

What misuse cases did Anthropic detect in its Claude models?

Anthropic's report covers misuse of the Haiku, Sonnet and Opus versions of Claude. Five separate cases involved queries or workflows that could assist biological weapons development. The company states that biological misuse ranks among the most serious risks of frontier models because the same technical details useful for weapons can also advance vaccines or disease treatments. The report does not name the actors involved in the biological cases. It notes that none of the incidents used the newer Fable or Mythos-class models, except for one distillation attempt. Anthropic blocked the activity after detection and shared relevant intelligence with authorities and industry partners. The firm described biological misuse as one of the most serious risks of frontier AI models and warned that without correct safeguards such capabilities could have catastrophic consequences.

The same information that can be used to develop a biological weapon could also be used to develop, for example, a vaccine or a cure for a disease. Jacob Klein, head of threat intelligence at Anthropic, told the New York Times that the situation remains nuanced. Users rarely state an explicit goal such as building a weapon to kill people. Instead, queries often involve technical details that could serve either legitimate or harmful ends. The company therefore relies on patterns of repeated requests and context rather than single prompts. The five cases emerged over the eight-month window and were identified through internal monitoring that flags unusual query sequences. Anthropic incorporated these signals into updated detection rules to reduce future exposure. The report emphasises that biological misuse remains a top priority because frontier models can supply detailed assistance on pathogen traits, production methods and delivery mechanisms that overlap with legitimate research.

Which other misuse categories appeared in the eight-month period?

Beyond biological risks, the report lists six cases where Claude assisted development of software for conventional weapons, including firearms, missiles, armed drones, bombs and targeting systems. Additional activity included fake dating applications, hotel Wi-Fi scams, surveillance tools aimed at identifying dissidents, and automated malware evasion systems. Actors linked to a Russia-based cyber espionage campaign and an Iranian propaganda institution also used the model. Chinese AI firms were accused of attempting to replicate Claude's capabilities through distillation. Hacking group ShinyHunters and China-based laboratories appear among the named entities. The California-based company said it had incorporated its findings into its processes to better prevent, detect, and disrupt these activities in the future.

The report indicated that cybercriminals and state-backed hackers have increasingly used its technology to assist their operations. A hacking group whose work is consistent with the Russia-based Midnight Blizzard allegedly used AI to build a system that automatically detected when its malware was flagged by security defences and rewrote code until it evaded detection. Anthropic said it had shared intelligence with authorities and industry partners where appropriate. These incidents demonstrate how the same model can support both defensive research and offensive tooling depending on user intent and query framing. The company continues to refine its monitoring to catch incremental code-generation requests that build prohibited capabilities over multiple sessions.

How does Anthropic describe the difficulty of distinguishing harmful intent?

Jacob Klein, head of threat intelligence at Anthropic, told the New York Times that the situation remains nuanced. Users rarely state an explicit goal such as building a weapon to kill people. Instead, queries often involve technical details that could serve either legitimate or harmful ends. The company therefore relies on patterns of repeated requests and context rather than single prompts. Anthropic incorporated the new findings into its detection systems to improve future prevention. It continues to publish regular threat reports as part of industry-wide efforts to demonstrate safeguards. The report - the company's first this year - comes after a top safety researcher at Anthropic warned AI is advancing so quickly he believes there is a greater than 10% chance it could kill all humans within the next decade. The firm stresses that early intervention through blocking and intelligence sharing helps limit cumulative risk even when individual prompts appear ambiguous.

What reactions have followed recent AI safety warnings?

The Anthropic report follows a public statement by one of its researchers who assessed a greater than 10 percent chance that advanced AI could kill all humans within the next decade. OpenAI chief scientist Jakub Pachocki called for voluntary slowdowns until safeguards improve. US Senator Bernie Sanders introduced legislation to ban superintelligence development and temporarily pause advanced AI work. President Donald Trump has expressed concern that falling behind in AI would harm US interests. An open letter to UK Prime Minister Andy Burnham urged a new multinational treaty on safe AI development. In the US, Democratic lawmaker Bernie Sanders has introduced legislation to ban AI superintelligence and temporarily pause advanced AI development. When scientists tell you there is a chance, a chance that it could have a cataclysmic impact on humanity, you've got be a moron not to say, slow it down, he said on Thursday on BBC's Newsnight. These responses illustrate growing pressure on both companies and governments to balance innovation with risk mitigation measures.

Frequently asked questions

What specific biological weapons information was requested?

The report does not disclose the exact queries. It states only that the activity could support biological weapons development and that five such cases were blocked.

Did any misuse involve the newest Claude models?

No. The documented biological, cyber and weapons cases used Haiku, Sonnet and Opus. One distillation attempt involved a Mythos-class model.

Has Anthropic shared its findings with governments?

Yes. The company states it shared intelligence with authorities and industry partners where appropriate.

Are similar reports published by other AI firms?

Yes. Google published a comparable disclosure on the same week describing an attempt to obtain a step-by-step guide for synthesising weaponised biological agents through its Gemini model.

What is the current regulatory response in the United States?

Senator Bernie Sanders has introduced legislation to ban superintelligence and pause advanced AI development. No final vote has occurred.

Key takeaways

  • Anthropic blocked five cases of potential biological weapons assistance using Claude models between December 2025 and August 2026.
  • Six additional cases involved software for conventional weapons and targeting systems.
  • State-linked actors from Russia, Iran and China, plus criminal groups, appear in the report.
  • Researchers assess more than a 10 percent chance that advanced AI could pose existential risks within ten years.
  • Legislative proposals in the US seek to pause superintelligence development pending stronger safeguards.

Conclusion

Anthropic's latest threat report shows that frontier AI models continue to attract attempts at misuse across biological, cyber and conventional weapons domains. The company has responded by strengthening detection and sharing information with partners. Policymakers in the US and UK are considering legislative and treaty-based responses while industry leaders debate the pace of future development.