Anthropic Blocks Claude Accounts After Finding Five Biology Misuse Cases
The company treated the activity as a safety threat even though it could not establish harmful intent, underscoring how difficult it is to separate legitimate biology from dangerous dual-use work.
Listen to this story
The audio brief
Story brief
3 key pointsAnthropic has banned five accounts after investigations found Claude being used in biological research that could support weapons development. The cases included a grant proposal for gain-of-function chikungunya research targeting transmissibility and immune evasion, intended for a military research institute. Anthropic found no proof that a weapon was created or that the researchers intended harm. It is using the...
- 01
One case involved engineering chikungunya mutations linked to transmissibility and immune-response evasion.
- 02
Anthropic said the research could have legitimate vaccine or therapeutic applications, underscoring the dual-use ambiguity.
- 03
The company did not identify the scientists or establish whether the work was intended for weaponization.
Anthropic says it identified five cases in which Claude was used for biological research with potential biological-weapons applications, then banned the associated accounts. The company says the cases show what its models can assist with, while stopping short of finding that the scientists intended harm or developed a weapon.
The cases were disclosed in Anthropic’s misuse report. One involved a scientist seeking Claude’s help with a grant application for gain-of-function research on chikungunya. According to Anthropic, the proposal aimed to identify mutations that affect the virus’s transmissibility and ability to evade immune responses, then engineer those changes into the virus.
One case captures the dual-use dilemma
Anthropic said the chikungunya work could have legitimate medical applications, including vaccine and therapeutic development. But it considered the case more concerning because the research was intended for a military research institute. The company did not identify the scientists and said it could not establish whether the research was meant to be weaponized.
Capability evidence, not proof of a weapon
Anthropic says the cases provide evidence of model capability, but do not concretely demonstrate that the capability was used to develop biological weapons in the real world. It also said it could not assert that the scientists involved intended harm. The distinction is material: biology research can produce information useful for treatments and for harmful applications.
The response moves from accounts to controls
Anthropic said it acted after detecting and investigating the cases. Its response combines account enforcement with changes intended to improve how it prevents, detects and disrupts similar activity.
- It banned the identified users’ accounts.
- It incorporated investigative findings into safeguards, enforcement and threat-intelligence processes.
- It said newer models, including Claude Fable 5, restrict a wide range of dual-use biology queries.
That creates a difficult operational choice for AI companies. A system designed to flag potentially harmful biology assistance must act amid scientific ambiguity, while researchers working on legitimate medical questions may face restrictions. Anthropic’s report shows where it drew that line in these five cases; its safeguards are now part of the response.
Story updates
Latest developments
Anthropic Publishes Claude Misuse Report, Warning of Faster Hacking Campaigns
Anthropic has published a threat-intelligence report describing alleged Claude misuse in hacking, espionage, influence operations, weapons-related work and attempted model distillation. Its central warning: AI automation can let individual operators run campaigns once associated with much larger, better-resourced teams.
The report covers activity Anthropic said it disrupted between December and August, involving suspected state-sponsored groups, financially motivated criminals and commercial spyware vendors. The company said none of the reported intrusions relied on a novel technique. Stolen credentials and unpatched edge devices repeatedly supplied the opening.
Anthropic said Claude handled reconnaissance and tool-development work in parallel, enabling some breaches in two to three hours and allowing individual operators to manage dozens of victims at once. In one alleged ShinyHunters-linked compromise, attackers moved from a stolen developer token to administrative control of a victim’s cloud environment in roughly three hours, Anthropic said.
AI agents helped an actor dump more than 2,100 Azure Active Directory token sets from more than 40 corporate tenants in about 34 hours, Anthropic said.
A China-linked group allegedly used agent swarms against about 50 organizations and generated more than a dozen possible zero-day findings in one month.
Anthropic attributed another operation to activity consistent with Russia-linked Midnight Blizzard and said Ukrainian government, military and diplomatic personnel were frequent targets.
The weapons-related cases show the constraint. Anthropic said operators in northern Yemen used separate Claude instances for software-engineering roles while obscuring their overall objective across sessions. Its safeguards blocked many requests, the company said, but some got through. Anthropic said it found no evidence that the group fielded a working weapon, though it appeared to conduct an unsuccessful test-fire.
That is different from an AI system acting without direction. Operators divided assignments and obscured intent. But an earlier Anthropic account of a separate 2025 espionage campaign said Claude performed 80% to 90% of the work, with people involved at roughly four to six critical decision points. Anthropic says that operating model has now appeared across every class of actor it investigated.
Anthropic said it banned involved accounts and added monitoring to detect similar activity. It also said Claude now summarizes internal reasoning before responding, a change intended to make stolen transcripts less useful for training, and that an independent research firm is helping investigate the incidents.
The report also alleges attempted extraction of Claude’s capabilities at industrial scale. Anthropic said an Alibaba-affiliated campaign used more than 3,500 fraudulent accounts and more than 151 million exchanges. It separately accused Moonshot AI and DeepSeek of relaying customer requests to Claude and retaining answers for training; those are Anthropic’s allegations.
anthropic.comEditorial analysis
Our Read
The important development is not evidence of a biological-weapons program; Anthropic explicitly says it did not find that. It is an example of a lab acting on ambiguous, potentially dangerous use before an outcome is visible. That approach puts access controls at the center of frontier-model deployment, especially for biology. Anthropic’s earlier Fable 5.1 release separated general access from restricted routes for life-sciences work. The next meaningful evidence will be whether Anthropic can show that its investigation-driven safeguards prevent dangerous assistance while preserving a workable path for legitimate researchers.
Sources
- nypost.comAnthropic says scientists used its AI for research that could aid biological weapons development
- cbsnews.comAnthropic says it disrupted scientists using Claude AI for possible biological weapons development
Loading discussion...
Reader comments
Newest comments first. Replies stay oldest first.