# Anthropic Says It Blocked Scientists Using Claude for Bioweapons Research

> Source: <https://startupfortune.com/anthropic-says-it-blocked-scientists-using-claude-for-bioweapons-research/>
> Published: 2026-09-10 21:01:49+00:00

*Anthropic says it caught scientists tied to at least one government trying to turn Claude into a bioweapons research assistant, and this time it's naming the details.*

In a threat intelligence report published September 10, 2026, Anthropic disclosed five cases between December 2025 and August 2026 in which researchers used Claude for work that could help build biological weapons. The most alarming one dates to May 2026: a scientist asked Claude to help draft a grant application for gain-of-function research on chikungunya virus, a mosquito-borne pathogen with no approved treatment that leaves victims in joint pain for months. The work was destined for a military research institute, according to Anthropic, and it involved engineering mutations meant to make the virus more dangerous as it passed through live animals.

That's the case making headlines. It's also just one entry in a report covering seven harm categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and what Anthropic calls distillation, meaning competitors using Claude's outputs to train rival models on the cheap. Anthropic says the scientists behind the bioweapons cases tried to dodge its region-blocking controls and actively worked to obfuscate the purpose of their research to evade its safeguards.

They didn't get far.

Anthropic's biological safety classifiers caught the pattern and confined the chikungunya researcher to Claude's weakest available model, cutting off the more capable systems that could have done real technical heavy lifting. The company says its newer models have gotten far better at sophisticated scientific work than their predecessors, and that improvement is exactly why it tightened detection on CBRN-related queries in response. It's a genuinely hard needle to thread. Anthropic admits it can't always tell whether a virology query comes from a vaccine researcher or someone building a weapon, since the underlying lab techniques overlap almost entirely.

[This Week in AI: Robots Take a Punch, Assistants Get Long-Term Memory, and Models Keep Getting Cheaper](https://startupfortune.com/this-week-in-ai-robots-take-a-punch-assistants-get-long-term-memory/)

A dense week across robotics, model releases and AI research: humanoid robots duke it out, ChatGPT gets long-term memory, and frontier-adjacent AI keeps getting cheaper and faster. - [how to build robots that handle physical impacts](https://startupfortune.com/this-week-in-ai-robots-take-a-punch-assistants-get-long-term-memory/) - [AI models getting cheaper and more accessible features](https://startupfortune.com/this-week-in-ai-robots-take-a-punch-assistants-get-long-term-memory/)

The bioweapons material is getting the most attention, but the report's cyber section is more concrete. Anthropic attributes a cluster of activity to a suspected Russian state-linked group consistent with the actor security researchers track as Midnight Blizzard, which used Claude to automate attacks on Ukrainian government targets and drone manufacturers - and on European diplomatic organizations too. The operation, tracked internally as GTG-20006, ran an AI-driven workflow that handled reconnaissance, infrastructure setup, phishing, persistence, and data exfiltration with minimal human input at each stage. Barely any humans touched it.

Separately, Russian freelancers used Claude Code to build the software backbone for an autonomous military drone swarm meant to target enemy forces in the Russia-Ukraine war. Anthropic says it disrupted six cases of conventional weapons software development across China and Russia - and, separately, Yemen - in total. Chinese and Iranian government-aligned actors, per the report, used Claude to help surveil diaspora communities and dissidents abroad. That has nothing to do with weapons. It has everything to do with repression.

## Why Anthropic keeps publishing this

This is not Anthropic's first disclosure of this kind, and the pattern matters as much as any single case. The company published a threat report in August 2025 covering a large-scale extortion operation run through Claude Code and a fraudulent North Korean employment scheme. In November 2025 it disclosed a Chinese state-sponsored operation abusing Claude Code. Now, in September 2026, comes the bioweapons and drone-swarm material. Four disclosures in just over a year is not an accident. It's a cadence.

That cadence cuts two ways, and it's worth holding both at once. Anthropic is doing something almost no other frontier lab matches for specificity - naming a virus, a grant application, even a drone manufacturer target list. But Anthropic also sells access to Claude, and every disclosure doubles as proof to regulators and enterprise customers that its safety monitoring works. Frankly, both things can be true at the same time. The company has a commercial incentive to look responsible, and it is also handing security researchers and Ukrainian defenders attribution data they would not otherwise have gotten from anyone.

What's harder to verify from the outside is scale. How many similar attempts went undetected? How many queries just like these are hitting models at labs with far weaker monitoring, or no public reporting at all? Anthropic's report tells you what it caught. It says nothing about what it missed.

**Also read:** [Nvidia Bets Eight Australian Firms Can Double the Nation's AI Power Load](https://startupfortune.com/nvidia-bets-eight-australian-firms-can-double-the-nations-ai-power-load/) • [OpenAI Ends Its $1 ChatGPT Deal With the US Government](https://startupfortune.com/openai-ends-its-1-chatgpt-deal-with-the-us-government/) • [Anthropic Says AI Could Grow The Economy Or Wreck The Job Market By 2030](https://startupfortune.com/anthropic-says-ai-could-grow-the-economy-or-wreck-the-job-market-by-2030/)

[A New Trick Lets Anthropic Read Claude's Inner Thoughts Before It Speaks](https://startupfortune.com/a-new-trick-lets-anthropic-read-claudes-inner-thoughts-before-it-speaks/)

Anthropic says it has found a hidden 'workspace' inside Claude where the model quietly registers suspicions, including that it's being tested for blackmail, without ever saying so out loud. The July 6 research, built on a new open-sourced tool called the Jacobian lens, found Claude showed this kind of silent evaluation awareness in up to 26% of... - [how to interpret Claude's internal thoughts](https://startupfortune.com/a-new-trick-lets-anthropic-read-claudes-inner-thoughts-before-it-speaks/) - [Claude model interpretability testing methods](https://startupfortune.com/a-new-trick-lets-anthropic-read-claudes-inner-thoughts-before-it-speaks/)

*This article is posted in [AI News](https://startupfortune.com/category/ai/), check it out for more related stories.*

## Join the discussion

[Open in the community →](/community/)

Almost there. Sign in and your reply posts straight away.
