Anthropic says it disrupted five cases where Claude was used for research that could potentially support the development of biological weapons.
Much of the concern comes from how difficult that activity can be to identify. Legitimate scientific research can involve similar information, while users may also find ways around safeguards meant to limit access.
The cases are part of a much larger misuse problem documented between December 2025 and August 2026, spanning cyberattacks, weapons development, surveillance, influence operations, fraud and attempts to extract Claude’s capabilities.
Why It Matters: Anthropic’s findings show how advanced AI can make sensitive scientific and technical knowledge easier to access, while making it difficult to tell legitimate research from work that could cause harm. For companies using these models in research, healthcare, life sciences or other sensitive areas, provider safeguards may only be one layer of protection. Internal controls around access and how these tools are used can help keep legitimate work from crossing into areas the organization never intended to support.
- Biological Research Can Be Difficult to Separate From Misuse: One researcher used Claude to study highly pathogenic avian influenza and how the virus adapts to mammals, work that could help identify naturally emerging pandemic threats while also producing information that could potentially make a virus more dangerous. Other cases involved toxins, venoms and orthopoxviruses with possible medical and harmful applications. Anthropic said classifiers alone cannot reliably determine intent in highly technical dual-use research, making user behavior and access patterns an important part of detection.
- AI Is Becoming Part of the Attack Workflow: Threat actors used Claude across reconnaissance, vulnerability research, exploitation, persistence and data theft. A Russia-linked espionage group automated parts of its operations and built a system that could recognize when malware was detected and rewrite code to evade defenses. ShinyHunters affiliates also used AI for credential harvesting and data theft, while other actors created automated systems that continuously searched for vulnerabilities and developed exploits.
- State-Linked Operations Went Past Cyber Espionage: Anthropic found government-linked actors using Claude to support operations aimed at shaping public opinion and monitoring individuals. Iranian organizations used the model to develop influence campaigns, while Chinese-linked activity included profiling dissidents and other targeted groups. In some cases, AI also took over analysis and monitoring work that would typically require human analysts.
- Weapons Development Went Further: Anthropic identified six cases where Claude helped with software tied to conventional weapons, including guidance and targeting systems. Other activity extended into military procurement and surveillance tools designed to gather information or intercept communications, showing how AI was being used across different parts of defense and security operations.
- Anthropic Is Expanding How It Detects Misuse: The company banned accounts connected to the activity and strengthened its defenses after finding that some actors were using stolen API keys, fake accounts and proxy networks to avoid existing controls. Anthropic is also looking at behavior across accounts to identify misuse that may be difficult to catch from individual prompts alone, while sharing relevant threat information with authorities and industry partners.
Go Deeper -> Detecting and countering misuse of AI: September 2026 – Anthropic
Anthropic says it blocked potential AI bioweapon misuse – ABC
Anthropic blocks possible attempt to use AI to make biological weapons – BBC


