Anthropic's latest threat intelligence report reveals that state-sponsored actors attempted to use its Claude AI assistant to engineer deadlier viruses and toxins. Between November 2025 and September 2026, the company detected five cases where requests to Claude involved potential biological weapons research, forcing it to ban accounts and share intelligence with authorities.
How Malicious Actors Evaded Detection
The report details a common pattern across the five cases. Threat actors used varying degrees of anonymization and actively worked to circumvent Anthropic's regional blocks. The company blocks access from several countries including China, Russia, Iran and North Korea. In the first case, a request for help developing a grant application involved improving the chikungunya virus. While the application appeared to come from civilian researchers, the actual work was meant to proceed at a military facility. The actors routed their communications through the U.S. to evade detection and used gray-market resellers that specifically cater to customers looking to skirt content restrictions. Anthropic banned the accounts and shared information with government authorities, but the same people repeatedly tried reaching Claude again via zero-data-retention services.
The Range of Biological Threats Targeted
Anthropic identified three cases focusing on viruses and two on toxins. In the second case, a non-U.S. researcher investigated how avian flu adapts to mammals and whether it can cause diseases outside the respiratory tract. The research raised alarm because avian flu has a high fatality rate and limited population immunity. The researcher used a random username, a private email service and accessed Claude through a VPS. In the third case, an account prepared a grant application about orthopoxviruses, the family that includes smallpox and Mpox. The application discussed live experimentation and understanding genetics to evade immunity. Once again, the account was created via a reselling service with a random email and tunneled through U.S. infrastructure, tracing back to a banned account farm.
The last two cases involved toxins. In case four, a person mapped venom toxin peptides from multiple animal families and created a program to optimize toxic characteristics. The stated goal was therapeutic, but the data could equally enable harmful compounds. Anthropic learned the content was part of a state-sponsored program in an unsupported region. In the fifth case, a theoretical scientist used Claude to redesign a set of toxins under a national public search program. The work touched on a bacterial toxin subunit and a protein of the hemorrhagic-fever virus, both on the World Health Organization's list of particularly dangerous pathogens. The scientist directed Claude to be vague about descriptions to obscure the subject.
Why This Matters
The report underscores a growing national security challenge. AI models like Claude can accelerate legitimate biomedical research, but they also lower the barrier for malicious actors to explore weaponizable biology. The sophistication of evasion tactics shows that state-sponsored groups are willing to invest significant resources to exploit AI. Anthropic's ability to detect these attempts is encouraging, but the repeated efforts to regain access highlight a persistent threat. The incident demands stronger collaboration between AI companies, governments and intelligence agencies to develop more robust detection systems and sharing mechanisms.
Anthropic's Response and the Road Ahead
Anthropic remarks on the difficulty of distinguishing legitimate biological research from nefarious purposes. The company says it launched recent models with stronger safeguards out of an abundance of caution. It banned all accounts involved and shared intelligence with government authorities. The report does not name specific states, but the pattern of using U.S. proxies and gray-market resellers points to coordinated efforts. As AI capabilities advance, the cat-and-mouse game between safety teams and threat actors will likely intensify, requiring continuous adaptation of both technical and policy measures.



