Anthropic has blocked multiple accounts using its Claude AI models for research that could support biological weapons development, the company disclosed Thursday. The finding emerged from a 30-day review that identified roughly 35 distinct research efforts with potentially concerning activity, though Anthropic acknowledged it could not determine whether the users intended harm or were conducting legitimate scientific work.
The report details five case studies where users circumvented regional blocks and obscured their research purposes to evade safeguards. The examples span gain-of-function research, infectious diseases including bird flu, and novel venoms and toxins. Anthropic said the individuals involved were "working scientists" but did not name the research institutions or countries.
Case studies reveal dual-use risks
One case involved a request for help writing a grant application for gain-of-function research on the chikungunya virus, focusing on transmissibility and immune evasion. Another researcher outside the US used Claude for work on bird flu that examined viral adaptation to mammals and mechanisms of severe illness. Additional cases covered orthopoxviruses - the group that includes variola, which causes smallpox, and mpox - as well as venom toxin research.
Anthropic's report draws a direct line between AI's scientific promise and its potential for misuse. "Sophisticated attacks no longer require sophisticated attackers," the report states. "The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators."
The company said bad actors could exploit AI's beneficial biological applications to "maintain a kind of 'plausible deniability'" about harmful research. Recent models, including Claude Fable 5, now include stronger safeguards that restrict access to a broad range of dual-use biological research queries. For researchers navigating these boundaries, Claude AI Courses & Certifications cover the model's capabilities and safety guardrails in scientific contexts.
Safeguards working but strain showing
Anthropic said there is evidence its safeguards are functioning, but acknowledged that more robust safety systems will be necessary as models become more capable. The company also disrupted efforts to use its models for surveillance operations, scams, and development of conventional weapons including drones and missiles.
"As our models become increasingly capable, approaching or exceeding expert performance at challenging scientific tasks, we expect their impact will only increase, both in beneficial and potentially harmful contexts," the report said. The disclosure arrives amid a series of warnings from AI employees leaving companies over safety concerns.
Jacob Coxon, a former Anthropic employee, told CNN on Wednesday that advanced AI systems "could cause extreme havoc." In a resignation post on X this week, the 27-year-old researcher wrote that "the people building AI earnestly believe that it could kill us all by the end of the decade." He said AI could hack critical infrastructure or build "extinction-level bioweapons."
Industry self-policing amid regulatory vacuum
Nearly 1,400 AI company employees signed an open letter in July urging the US government to regulate the technology. OpenAI Chief Scientist Jakub Pachocki warned this week that AI capabilities are advancing faster than researchers' ability to monitor and control them. Congress has so far declined to rein in the technology, and the Trump administration has moved to undermine state AI regulations.
Anthropic said Wednesday that "the world would benefit from the industry adopting a lawful, verifiable way to work together to pace how we release powerful models." For now, AI companies are largely policing themselves. Researchers working at the intersection of AI and biology can explore AI Research Tools Training to understand current safety protocols and responsible use frameworks.
Why this matters for science and research professionals
The report underscores a tension that working scientists now face daily: the same AI tools accelerating drug discovery and materials science can be redirected toward harmful ends by actors exploiting plausible deniability. Researchers should expect heightened scrutiny of queries involving pathogens, toxins, or gain-of-function experiments when using commercial AI platforms. Documenting legitimate research purposes and institutional affiliations upfront may become standard practice as providers tighten automated flagging systems. The gap between what models can do and what regulators oversee continues to widen, leaving individual researchers and their institutions to navigate biosecurity questions that lack clear legal guardrails.
Your membership also unlocks: