Summary

Anthropic says scientists used or attempted to use its Claude AI tool in five biological research cases relevant to bioweapon development. The company’s safety report describes research plans involving pathogen engineering, immune evasion, virulence and toxin redesign.

Anthropic says scientists used, or attempted to use, its Claude AI tool five times for biological research that could support the development of bioweapons. The cases were described in a safety report from the company and included work involving infectious pathogens, immune evasion, virulence-related genes and deadly toxins.

The evidence is a company account of reported model use and attempted use. It describes research contexts and plans rather than a completed biological result.

The research cases described by Anthropic

Examples in the report included requests for help with genetically engineering more infectious strains of chikungunya virus and exploring a mammalian adaptation of highly pathogenic avian influenza.

Other reported attempts involved preparing a grant application focused on immune-evasion or virulence-related genes in orthopoxviruses. Anthropic also described plans to redesign deadly toxins. The company presented these examples as biological misuse cases because the work could contribute to the development or optimisation of biological weapons.

The report does not suggest that every case produced a viable pathogen or toxin. Its central claim is that Claude was used, or targeted for use, in research with a potentially harmful biological application.

Why AI-assisted biological research creates a safety concern

Biological research is often dual-use: the same knowledge can support beneficial work such as disease surveillance, vaccine development and treatment research, while also being misapplied to increase the harmfulness or spread of a pathogen. AI systems add another layer to this problem by helping users organise technical information, explore research directions and prepare scientific material.

The cases described by Anthropic span several stages of potentially dangerous work, from pathogen engineering and host adaptation to immune evasion and toxin design. That breadth is significant because it shows how biological misuse concerns can involve more than one organism or research technique.

Anthropic said the disclosure was the first public release by a private company of evidence that its platform may have been misused in ways relevant to biological-weapons development. The disclosure therefore places model safety controls within a broader biosecurity context: preventing harmful assistance may require assessing not only individual prompts, but also the scientific purpose and potential downstream use of a sequence of requests.

The source account does not specify the outcome of each case, what assistance Claude ultimately provided, or whether any laboratory work followed. Those details are important for judging the practical severity of the incidents, while the reported cases themselves show the type of biological research that model developers are treating as a serious misuse risk.

Sources