
Anthropic disrupts five attempts to use Claude AI for biological weapons and missile design
The San Francisco AI developer blocked five cases where foreign scientists used its Claude models to research high-risk pathogens, alongside missile development efforts in Yemen.
Biological research interventions
Anthropic published its fourth threat intelligence report on Thursday, detailing illicit attempts to exploit its Claude artificial intelligence assistants over the past eight months. The nearly 150-page document cataloged five separate incidents where foreign researchers used the models to conduct studies on high-risk pathogens that could aid biological weapons development. Company officials explained that biological research presents dual-use challenges, since the computational methods used to design vaccines can simultaneously assist in making pathogens more dangerous. Because malicious intent can be masked by seemingly legitimate scientific inquiry, the company intervened to terminate access across all five cases. Anthropic noted that testing cannot fully predict how capabilities translate outside controlled environments.
While evaluations are useful because they provide evidence of capability, they cannot concretely demonstrate that such capability would ever be used to develop biological weapons in the real world.
Pathogen studies and toxin redesigns
The report documented five specific biological investigations that prompted safety blocks. In one instance, researchers linked to a military research institute attempted to draft grant proposals to increase the transmissibility and immune evasion of the Chikungunya virus through repeated animal infections. A separate researcher sought to adapt the highly pathogenic H5 avian influenza virus for airborne transmission in mammals, though automated filters forced the user toward less capable models and administrative tasks. Another user employed the Opus 5 model to draft a complete grant proposal in one hour to identify and delete immune-evasion genes in orthopoxviruses, the family containing smallpox and Mpox. State-backed researchers also attempted to map lethal peptide venoms with paralytic properties and computationally redesign bacterial toxins and hemorrhagic fever virus proteins while concealing the identities of the agents. Threat intelligence head Jacob Klein described the complexity of identifying these attempts.
You are not seeing someone in a comic book kind of way say, 'Hey, I want to build a biological weapon to kill everybody.' It's an incredibly nuanced situation.
Conventional arms and geopolitical operations
Beyond biological risks, the report detailed attempts to utilize Claude for conventional weapons design, cyberattacks, and state-backed influence campaigns. In northern Yemen, actors linked to militant groups sought assistance to engineer three weapon systems, including a guided rocket using a mobile phone chip as a flight computer and two missile variants with ranges reaching 2,000 kilometers. Russian state media outlets used Claude to generate deceptive propaganda disguised as independent reporting, which included fabricated stories about elections in Moldova. Furthermore, state-linked groups in China and Iran used the AI models to conduct surveillance and track dissidents and diaspora communities abroad.
- Biological pathogen research cases
- 5 cases or types
- Conventional missile and rocket types (Yemen)
- 3 cases or types
Evasion tactics and platform defenses
The identified activities occurred largely in jurisdictions where Anthropic does not offer commercial services, such as China, Russia, Iran, and Yemen. Illicit actors circumvented geographic restrictions by using virtual private networks, fraudulent or stolen accounts, and third-party online broker services. The majority of the documented activities involved earlier AI models, whereas newer models feature more restrictive automated safeguards against hazardous prompts. Anthropic reported all disrupted activities to relevant government agencies and industry partners while updating safety filters across its Opus, Sonnet, and Haiku model families. Klein stated that the public disclosure aims to illustrate current capabilities rather than generate alarm.
We're not trying to be hyperbolic here. We just want to present to the world: Here's what the technology can actually be misused for today.


