Anthropic blocks AI misuse for cyberattacks, surveillance, and bioweapons research

Anthropic blocked attempts to use its AI for cyberattacks, surveillance, and bioweapons research between December 2025 and August 2026, including a grant proposal for gain-of-function chikungunya virus work.

Categorized in: AI News Science and Research
Published on: Sep 13, 2026
Anthropic blocks AI misuse for cyberattacks, surveillance, and bioweapons research

Anthropic said Thursday it has blocked attempts by bad actors to use its artificial intelligence models for cyberattacks, surveillance, and research that could have led to biological weapons. The disclosure, published in the company's third AI misuse report since March 2025, comes as AI models grow capable enough that even lone individuals can create threats that would not have been possible a year ago.

Between December 2025 and August 2026, Anthropic researchers found misuse by actors ranging from spyware vendors and politically motivated individuals to state-sponsored groups spreading propaganda. The report includes snippets of malicious code and AI prompts the company said it identified, along with a call for governments and AI competitors to detect and prevent similar abuse.

"We're publishing this work because we believe we have a responsibility to disclose malicious misuse of our services," the company said. "As models become increasingly capable, their risks will increase, unless AI developers and society's defenders act to make them safer."

Biological research requests raise alarms

Among the findings are unnamed actors attempting to use Anthropic's models for research that could have led to biological weapons. In one instance, the company said its systems blocked a request for Claude's assistance in writing a grant application for gain-of-function research on the chikungunya virus, a mosquito-borne pathogen that causes severe pain and fever.

The proposal sought to enhance mutations to make the virus progressively more harmful. Anthropic acknowledged such research could "certainly" support vaccine and treatment development, but said "it could also be used to make the pathogen more dangerous."

Anthropic's older models, such as Claude Opus 4 and Claude Sonnet 4.5 from 2025, were "well below the threshold where they could meaningfully assist a sophisticated user in carrying out dangerous biological research." The company said safeguards on those models were less stringent, directed mostly at preventing access to content that might help novices recreate known bioweapons.

For today's models, which can assist with complex scientific research tasks, "the evidence is no longer certain, and we cannot make that same assurance." Anthropic has applied stronger safeguards restricting access to dual-use biological research queries in its more recent models, such as Claude Fable 5. Professionals working with Claude AI Courses may encounter these restrictions when exploring scientific applications of the models.

Influence operations and model theft

The report also documents groups that created hundreds of social media accounts designed to look like ordinary people, then posted material amplifying the same political view over the course of a week. Anthropic outlined nine such cases originating in Russia, Iran, Turkey, and across the Persian Gulf, South Asia, Africa, and Europe.

While social media companies can detect influence operations once posts are circulating, Anthropic said "we may see it on Claude while the operation is still being built." The company also identified one illicit distillation case it described as "an industrial-scale, covert campaign to extract a model's capabilities and replicate them in another model without authorization."

The report was published two days after Anthropic researcher Jacob Coxon announced his resignation over concerns that the company and its chief rival OpenAI "are racing straight to self-improving superintelligence and gambling with our lives." Coxon's post warned that some colleagues now believe AI could threaten human life by the end of the decade.

Why this matters for science and research professionals

For researchers working with AI models, the distinction between legitimate scientific inquiry and dual-use research is becoming a compliance issue. Anthropic's decision to restrict a wider range of biological research queries in newer models means researchers should expect more friction when using commercial AI tools for virology, microbiology, and related fields - even for work with clear public health benefits. Understanding where these guardrails sit, and documenting the legitimate purpose of research requests, will become part of responsible AI use in the lab. Those following developments in AI for Science & Research should track how safety policies evolve across different model versions.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)