As frontier artificial intelligence models grow increasingly capable of assisting complex scientific workflows, the boundary between legitimate healthcare research and dangerous biological synthesis has become an urgent national security frontier. In a comprehensive threat intelligence briefing published by Anthropic, the AI safety lab revealed it disrupted multiple attempts to harness its Claude models for high-risk biological research between late 2025 and mid-2026. The documented incidents, which involved working scientists and state-backed entities attempting to bypass model safeguards, underscore the emerging dual-use challenge facing frontier AI developers as foundational models acquire the capacity to accelerate pathogen engineering and conventional arms software.
We're publishing our most detailed threat intelligence report to date.
It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them.
We disrupted every operation in the report,…
Dual-Use ambiguity and pathogen studies
According to Anthropic's report, biological misuse represents one of the most severe threat categories confronting frontier model developers. The lab documented five specific case studies where users sought assistance that could support biological weapons pipelines:
Gain-of-Function Grant Drafting: In one case, a scientist linked to a military research facility sought Claude's help drafting a grant proposal for gain-of-function research on the mosquito-borne chikungunya virus, aiming to engineer mutations that increased transmission in live animal hosts.
Orthopoxvirus Immune Evasion: Another user utilized third-party API reseller relays to draft an orthopoxvirus immune-evasion proposal on Claude Opus in approximately one hour.
Avian Influenza and Toxin Redesign: Additional cases involved mammalian-adaptation experiments on avian influenza, as well as state-linked attempts to optimize biological venoms and toxins.
Anthropic emphasized that while the activities posed severe safety risks, establishing definitive malicious intent is difficult because the biochemical queries used to model vaccine targets directly mirror those used to engineer dangerous pathogens.
🚨 THE AI THREAT EVERYONE FEARED IS ALREADY HAPPENING
Anthropic just released a major threat intelligence report revealing how state-linked groups, hackers and criminals are weaponizing AI.
The report covers malicious activity disrupted between December 2025 and August 2026.… pic.twitter.com/TApfOpLIwA
Evasion tactics and safety interventions
Threat actors utilized multiple circumvention techniques, including routing requests through third-party API relays, operating from embargoed jurisdictions, and chaining automated fallbacks to competitor models when Claude refused prompts.
In response, Anthropic banned the offending accounts and deployed layered mitigations, including hard refusals via specialized biological safety classifiers, automated model downgrades to less capable tiers, and proactive institutional sweeps.
Anthropic’s public disclosure signals that passive keyword filtering is no longer enough to manage frontier model risks. As autonomous AI agents lower the technical barrier for biochemical experimentation, AI developers must transition toward verified access credentials and continuous behavioral telemetry to prevent foundational models from accelerating biological proliferation.
(Feature image credits to Andrey Rudakov/Bloomberg via Getty Images)
Read More: iPhone 18 Pro Max vs. iPhone 17 Pro Max: Everything Apple changed