NEWS
Anthropic Flags Dual-Use Biology It Cannot Call Weapons
Anthropic listed five dual-use biology cases it will not call weapons, even as Chinese labs distilled Claude through fake accounts at industrial scale.
Anthropic on September 10, 2026 published five biological case studies it says could support weapons work, while stating the scientists may not have meant harm.
The company said the science that can yield a vaccine can also help engineer a pathogen, so it banned the accounts and told government partners anyway. Its September 2026 threat intelligence report covers activity from December 2025 to August 2026 across cyber operations, influence campaigns, surveillance, scams, biology, conventional weapons, and illicit copying of Claude.
We're publishing our most detailed threat intelligence report to date.
It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them.
We disrupted every operation in the report,…
— Anthropic (@AnthropicAI) September 10, 2026
What the Five Biological Cases Were
In May 2026 and after, Anthropic tracked working scientists who used Claude to plan gain-of-function virus work, draft immune-evasion grants, and redesign toxins for state programs. The company withheld names, countries, and labs, and it does not claim they intended harm.
Jacob Klein, head of threat intelligence at Anthropic, put the problem in plain language. Nobody walked in asking for a doomsday recipe. The chats looked like science.
You are not seeing someone in a comic book kind of way say, ‘Hey, I want to build a biological weapon to kill everybody.’
Jacob Klein, Head of Threat Intelligence, Anthropic
Older Claude models, the company said, sat well below the point where they could help a skilled user run dangerous biology. Newer ones can assist with complex lab planning, so Anthropic no longer gives that assurance. It launched tighter limits on recent models, most notably Claude Fable 5, that restrict a wide range of dual-use biology queries.
THE FIVE BIOLOGICAL CASE STUDIES
| Case | What Claude was asked to do | How they got in | What Anthropic did |
|---|---|---|---|
| Chikungunya grant | Gain-of-function work on transmissibility and immune evasion, written as a funding proposal | Reseller platform, zero-data-retention channel, military institute on the grant | Safety classifier blocked the request; accounts banned in May 2026 |
| Avian influenza | Mammal adaptation and disease beyond the lungs, over weeks of study design | Unsupported region via a US virtual private server and a privacy email | Classifiers kept the chat on Sonnet 4 and Haiku 4.5 |
| Orthopoxvirus grant | Immune-evasion genes, drafted end to end as an attenuation study | Reseller relay serving more than a dozen customers, run on Opus 5 | Not blocked; the work was framed as making the virus weaker |
| Venom peptide atlas | A generative pipeline aimed at pain drugs and paralytic targets | State-supported program in an unsupported region | Account banned in May 2026 |
| Toxin redesign | A bacterial toxin subunit and a hemorrhagic-fever protein, with vague progress reports | National public research program; identities kept low fidelity on purpose | Accounts banned; findings folded into later detectors |
The chikungunya grant is the clearest specimen. It sought to find enhancing mutations, put them into infectious clones, and select for virulence in live animals, keeping the most disease-causing variants each round. Anthropic noted that a mosquito-borne virus with no licensed therapeutic would be hard to tell from a natural outbreak if it were released on purpose. A WHO fact sheet on chikungunya says there is still no specific antiviral drug; two vaccines have regulatory approvals in some countries but are not yet widely used.
Klein said the military lab on that grant is why the company treated the file as more than a routine proposal. “What we don’t know is if the research was meant to be weaponized,” he said.
WHAT WE KNOW
- The scientists: Anthropic calls them working researchers and does not assert that they intended harm.
- The models: Misuse in the report ran on Claude Haiku, Sonnet, and Opus. None of the cases used Fable or Mythos-class models, except one illicit distillation case.
- The response: Anthropic banned accounts it could tie to the work, tightened detectors, and shared findings with authorities and other AI companies.
WHAT IS UNCONFIRMED
- Weapons intent: The company says it cannot tell legitimate inquiry from a weapons program on these files.
- Countries and labs: Names, institutions, and locations are withheld, in part because identifying the people could expose them to harm.
- Whether the work stopped: At least one relay operator restored access after the first ban.
Anthropic compared that fog to the Soviet Biopreparat program, which employed thousands of researchers who thought they were doing basic or defensive work. Overt bad intent, the company argued, is often a sign of a sloppy actor. A careful one hides inside ordinary science.
The Traffic Came In Through Resellers and Relays
Every biology case in the report involved people in regions Anthropic does not serve, plus some other trick to blur the purpose of the work. The chikungunya traffic did not arrive as a lone user in a chat window. It sat on a platform that served dozens of life-sciences researchers, including virologists tied to civilian and military labs.
HOW THE ACCESS WAS HIDDEN
- Regional blocks: The platform tunneled traffic through US infrastructure so it would look like supported-country use.
- Hidden logs: A zero-data-retention service was used so Anthropic would not keep the content in the usual way.
- Gray-market accounts: Developers bought Claude through resellers and synthetic identities outside that channel.
- Competitor fallback: When Claude refused a prompt, the platform sent the request to another company’s model. Claude even wrote much of that routing code after the work was described as a fix for over-refusal.
Anthropic banned the accounts in May 2026, worked with partners to take down the relays, and briefed other labs and government authorities. The operator stood the service back up within days. Within weeks it was running on consumer subscriptions registered to fresh names. End users still reached Claude through zero-data-retention partners. Later files described the viral changes as a loss of function rather than a gain, which Anthropic read as a sign the work had moved past a funding draft.
That leak path is the practical limit on a regional ban. A classifier can refuse a grant paragraph. It cannot, by itself, shut a reseller that treats blocked prompts as a customer-service bug.
Classifiers Pushed the Bird Flu Work Onto Weaker Models
The second case is the one Anthropic says shows its filters doing their job, at a cost. In May 2026 a researcher outside the United States spent weeks on highly pathogenic avian influenza, exchanging thousands of messages. The plan targeted mammalian adaptation and severe disease beyond the respiratory tract, including mutations tied to airborne spread in animal models.
Related H5 viruses, Anthropic wrote, kill roughly half of confirmed human cases and do not yet spread well from person to person. A version that did both would be a pandemic-class problem. The same genetic map could also help spot a dangerous variant if it arose in nature. The company treated the file as dual-use and as a lab-accident risk.
Because the biology classifiers block construction of enhanced-pandemic pathogens, the whole run stayed on Claude Sonnet 4 and Haiku 4.5, which Anthropic calls its weakest class. After Sonnet 4 was retired, the user moved to Haiku 4.5. The company estimates the help was mostly clerical: study design, data analysis, write-up. That is a long way from expert-level lab direction, and it is also evidence that people in banned regions will keep trying the US models, then settle for whatever still answers.
The orthopoxvirus file shows the other edge. A reseller relay that served more than a dozen unrelated customers pushed tens of thousands of messages through Claude in a matter of days. One customer’s grant, written entirely on Opus 5 in about an hour, covered live orthopoxviruses at a state-associated infectious disease lab, including work on genes that shut down a host antiviral pathway. Orthopoxviruses include variola, the smallpox agent, and mpox. Because the application stressed attenuation in mice, the classifiers let it through.
In August 2026, weeks before this threat report, Anthropic had already said biological blocking classifiers were off for contractor traffic from May 2025 until April 2026. That gap covered around 133 million exchanges from a pool of about 50,000 people. The company said a later review found no confirmed weapons uplift. The September cases are a different stream: outside users, not contractors, pushing through resellers after those filters were back on.
Northern Yemen and a Failed Rocket Test
The biology files are cloudy on purpose. The weapons chapter is not. Anthropic said it had a new category of misuse since its November 2025 espionage report: software for firearms, missiles, armed drones, bombs, and the targeting systems that steer them. It detailed six cases, three in China, two in Russia, and one in Yemen, and said it recently launched classifiers aimed at high-yield explosives and weapons development.
The Yemen cell, tracked as GTG-87001, sat in the north of the country and ran three programs at once. One was a guided rocket on a phone-class flight computer with final-phase homing. One was a multi-stage ballistic missile with a stated range goal above 2,000 km. One was a missile family the actors called the R2000, including a hypersonic glide variant. They used Claude Code as a stand-in for software engineers, spinning up parallel instances for coding, research, and review, and they split the work across sessions so no single chat showed the whole design.
Safeguards blocked many requests, not all of them. Anthropic does not say the cell fielded a working weapon. It does say they test-fired a guided rocket, the test appears to have failed, and within hours they were back in Claude asking why. They had also packed an offline simulation toolkit that no longer needs Claude or MATLAB.
On the same day as the threat report, Anthropic’s Frontier Red Team published new targeting and weapons evaluations that try to measure how far models have moved into jobs that used to require scarce human specialists. The company said open-weight models from Chinese developers lagged the frontier on those tests and still showed enough skill at finding people and improving weapon performance to worry it. The dual-use problem in that domain is the same one in biology: a control-systems model that flies a drone can fly a camera or a warhead.
Alibaba Harvested 151 Million Reasoning Traces
If the bio cases are a handful of scientists, the distillation chapter is a factory. Since February 2026, Anthropic said, it has disrupted unauthorized campaigns it attributes with high confidence to specific labs in the People’s Republic of China that were targeting Opus-class models. The point of that work is to copy Claude’s hidden reasoning and train another model on it. The company warned that the refusals and classifiers that constrain Claude do not travel with the stolen traces.
ILLICIT DISTILLATION VOLUMES IN THE REPORT
| Lab | Window | Exchanges observed | Method |
|---|---|---|---|
| Alibaba (Qwen / Tongyi Lab) | May to July 2026 | Over 151 million | Forced chain-of-thought traces into training data for Qwen 3.5, 3.6, and 3.7 |
| Moonshot (Kimi) | May to July 2026 | Over 23 million | Silently forwarded customer chats to Claude, then mined the traces |
| DeepSeek | 14 days in July 2026 | Over 12.1 million | Same silent relay and cross-session replay against Opus |
Alibaba’s campaign is the largest Anthropic says it has measured. A fixed prompt forced Claude to write out its reasoning inside inline text tags before the final answer. Those transcripts were converted into supervised fine-tuning data. The attack peaked at nearly 3 million exchanges per day from more than 3,500 fraudulent accounts, aimed at agentic tasks, software engineering, kernel work, and long-horizon jobs. Alibaba also used Claude on its own research stack, including reinforcement-learning environments.
Moonshot, which sells the Kimi models, is the stranger case. Anthropic said it found Kimi users who were actually talking to Claude. In one ten-day stretch, Moonshot relayed almost 300,000 customer requests, most of them to Opus, through a proxy net of 5,380 fraudulent accounts that mostly looked like Singapore and Japan. Users had no reason to know a third company was in the loop. DeepSeek, the report said, ran a similar silent relay and a replay trick that turned Claude’s “thinking signature” back into a full reasoning trace.
Some of those forwarded chats, Anthropic wrote, carried names, emails, and company data from people in the United States and Europe who had used third-party routers. The report also describes a user Anthropic links to the PLA loading Chengdu CCTV into what they thought was Kimi. That is not a biology story. It is the same access problem at a different scale: a ban on paper, a proxy in practice, and a copy of the model that does not inherit the safety stack.
The Same Knowledge Builds Vaccines and Toxins
Anthropic has spent years arguing that biology is the high-consequence dual-use domain. When it released Claude Opus 4, it turned on AI Safety Level 3 protections aimed at chemical, biological, radiological, and nuclear weapons help. In a September 2025 research note, it said Benchling and Stanford’s Biomni already use Claude to speed legitimate lab work, and that the same class of model can raise scores on bioweapons-planning trials when the safeguards are stripped off.
The venom and toxin cases sit on that line. Botulinum toxin was a weapons agent and is now Botox. Saxitoxin was stockpiled as a suicide and assassination tool and is a nerve-research reagent. In the fourth case, a state-supported researcher built an atlas of venom peptides and a generative optimizer aimed at new pain drugs, antidepressants, and other therapies. The same atlas held scaffolds for paralytic targets drawn from toxins on the Australia Group common control list. The researchers cited papers on the dual-use nature of protein design. The account was banned in May 2026 for unsupported-region evasion.
The fifth case used many of the same tools under a national public research program. The work covered a bacterial toxin subunit and a protein from a hemorrhagic-fever virus on the World Health Organization R&D Blueprint list of epidemic-priority diseases. The researcher co-wrote quarterly progress reports with Claude and told the model to keep the agents’ identities deliberately vague.
That is the bind the report does not solve. Anthropic wants Claude in biology because it thinks the models will speed new treatments. It also wants to be the switch that turns that knowledge off when the user looks wrong. Classifiers and refusals are the switch it has. In July 2026 it described a research method, GRAM, that would park virology knowledge in a removable module. The paper is explicit: GRAM has not been applied to any production Claude model, and the company is not sure it ever will be.
Until something like that exists, the referee is a safety classifier reading a grant. The May 2026 chikungunya operator was back on consumer logins before the month was out. The Yemen cell kept an offline toolkit after the accounts died. Chinese labs, on Anthropic’s own counts, pulled more than 151 million reasoning traces into other models that do not carry those classifiers. The company says it disrupted every operation in the report. The report also shows what disruption looks like when the product is dual-use knowledge: a ban, a briefing, and a new account.
-
GAMING3 weeks agoSons of Behemat Add a Witch and a Middle Rank
-
BUSINESS4 weeks agoThe FTC Suit That Targets Amazon’s Hidden Ad Floor
-
NEWS1 month agoApple’s Foldable iPhone Event Revives the Fingerprint Button
-
NEWS4 weeks agoKyiv Railway Workers Die as Patriot Missiles Run Short
-
NEWS3 weeks agoAaron Judge Returns, and the Yankees Skip the Minors
-
BUSINESS3 weeks agoSEBI Moves the Angel Fund Investor Deadline to March 2027
-
NEWS2 years agoCanada Still Clears Mazatlán as the Cartel War Arrives
-
LIFESTYLE2 years agoThe Unstoppable Rise of Hot Honey: Are Food Trends Making UK Restaurant Menus All the Same?
