Anthropic has publicly detailed five cases in which users attempted to employ its generative AI model, Claude, for research with potential biological weapons applications. The disclosure, covered in a Science report, marks the first time a major AI company has acknowledged its product may have been used in attempts related to bioweapons development. The report spans misuse attempts from December 2023 through August 2024 and categorizes them into areas including cyber operations, biological misuse, and conventional weapons development.
The models involved were Claude Haiku, Sonnet, and Opus. Anthropic said it found no identified misuse attempts involving higher-level Claude models, with one exception. The company highlighted patterns where users tried to circumvent Claude's safety mechanisms after being blocked, often using intermediate servers, VPNs, and burner accounts to disguise their locations.
Viral modification and gain-of-function research
Three of the five biological cases involved viral modification research. In May, a user prompted Claude to draft a grant proposal for identifying mutations in the chikungunya virus that increase transmissibility and help it evade the immune system. The user's prompt indicated plans to construct viruses carrying those mutations and conduct animal experiments. Chikungunya rarely causes death but can lead to high fever and severe arthritis.
Another user that month used Claude to plan experiments creating mutations that would help a highly pathogenic avian influenza virus adapt better to mammalian hosts. A third case involved drafting a grant proposal to identify mutations that reduce the virulence of Orthopoxvirus genus viruses in mice - a family that includes smallpox and mpox. Anthropic classified the chikungunya study as gain-of-function research and the avian influenza work as potential pandemic pathogen research, a class of experiments currently banned in the United States. The company blocked assistance in both instances.
Toxin research and dual-use concerns
The remaining two cases centered on toxin research. One user employed Claude to compile a database of toxic substances as part of a drug discovery project. The other relied on the AI to computationally redesign multiple toxins, including bacterial and viral toxins designated as major disease threats. Anthropic judged both as dual-use research - work that seeks therapeutic compounds but could be repurposed for developing toxic agents.
In the fifth toxin-related case, the company observed the user deliberately using vague terminology for toxin names when drafting progress reports. Anthropic blocked some accounts, but noted that users in at least one case continued accessing the service through alternative methods.
Divergent views from virologists and biosecurity experts
The report has split scientific opinion. Some biosecurity experts warn that AI could lower barriers to biochemical weapons development through capability amplification - letting individuals with limited expertise quickly acquire dangerous knowledge. Others argue the interpretation is excessive.
Kristian Andersen, professor of immunology and microbiology at Scripps Research, said "many of the cases Anthropic describes are standard basic research that seeks to reproduce mutations already observed in nature in the laboratory and verify their function." He added that such experiments can be conducted safely using non-replicating pseudoviruses in high-containment facilities. Gregory Koblentz, associate professor of biodefense at George Mason University, pointed out that all the pathogens mentioned "are already circulating in various regions of the world and currently pose public health threats," making them legitimate objects of study.
The dispute now centers on how far AI companies should go in controlling scientific research. Andersen noted that even a question comparing two Ebola virus genome strains is currently blocked by Claude, raising concerns that excessive restrictions could interfere with legitimate work. David Gillum, a senior research scholar in biosecurity at Arizona State University, warned that if big tech companies "are also given the authority to control research, it could affect the production of scientific knowledge itself."
Biosecurity experts Philippa Lentzos of King's College London and Gigi Gronvall of Johns Hopkins University both urged caution against extreme interpretations. Lentzos said, "When interpreting these cases, we should be careful not to lean toward either extreme." Gronvall described some online reactions as "overheated." Both saw value in the report documenting concrete examples of how AI could be misused in biological research, viewing it as a starting point for discussing regulatory frameworks.
Why this matters for science and research professionals
The Anthropic report surfaces a tension that directly affects researchers using AI for Science & Research: the line between standard molecular biology and dual-use concerns is being drawn by AI companies, not by funding bodies or institutional review boards. For scientists who rely on large language models to draft grants, plan experiments, or analyze sequences, the blocking of queries about Ebola strain comparisons signals that safety filters may already be interfering with basic research workflows. Understanding where these boundaries sit - and how they shift - will become part of the practical skill set for labs integrating AI tools, whether through formal training like an AI Learning Path for Research Scientists or through direct experience with model refusals.
Your membership also unlocks: