For years, the threat of AI-assisted bioweapons development was largely a thought experiment debated in policy papers and congressional hearings. Anthropic’s new threat-intelligence report changes that framing, as AI Is Making state-linked attacks increasingly easier to execute.
The company says it has disrupted several attempts this year by scientists who used Claude to conduct research that could plausibly assist biological weapons development. Anthropic banned associated accounts and dismantled relay networks used to circumvent regional access controls.
Released September 10, 2026, the report covers roughly eight months of misuse data. It also documents state-linked actors using Claude for propaganda, dissident surveillance, and conventional weapons development in cases tied to Russia, China, Iran, and Yemen.
A Virus, a Grant Application, and a Military Lab
The most concrete case in the report involves reported gain-of-function research on a painful mosquito-borne virus, intended for a military institution.
In May, a scientist asked Claude to help draft a grant application for research designed to engineer mutations that would make chikungunya more harmful and capable of repeatedly infecting live animals. Chikungunya is a mosquito-borne virus that causes prolonged and severe joint pain.
What prompted Anthropic to flag the request: the work was intended to be carried out at a military research institute. Gain-of-function research, which involves modifying pathogens to study how they might evolve, has legitimate scientific applications, but that combination of context and setting was enough to act.
Jacob Klein, Anthropic’s head of threat intelligence, explained the detection difficulty plainly. “You are not seeing someone in a comic book kind of way say, ‘Hey, I want to build a biological weapon to kill everybody,’” he told the New York Times. “It’s an incredibly nuanced situation.”
Anthropic says it cannot definitively determine whether blocked research is legitimate dual-use work or weapons development. Faced with that uncertainty, the company says it erred toward blocking.
Older Models Were Limited. Current Ones Are Not.
Anthropic’s own evaluations show a meaningful capability gap between earlier Claude models and the more powerful systems now in use.
Older Claude models could not meaningfully assist in dangerous biological research. Current, more capable models can complete complex scientific tasks, a shift the company says changes the risk calculus significantly.
That gap also helps explain an earlier operational stumble. Bio-risk filters were disabled on contractor traffic from May 2025 to April 2026, covering approximately 133 million exchanges with around 50,000 contractors. A retrospective review flagged 1,197 high-risk transcripts, though Anthropic found no confirmed evidence of actual bioweapons uplift from that gap.
Russia, China, Iran, Yemen
Beyond biological threats, the report catalogs state-linked misuse spanning propaganda, dissident targeting, and conventional weapons software.
The report documents Russian state media using Claude to craft propaganda framed as independent reporting, including fabricated claims about a Moldovan election. Suspected Chinese and Iranian government-linked actors used the models to target dissident surveillance and diaspora communities, according to the report.
Anthropic also details six cases involving software relevant to conventional weapons design. Three are linked to China, two to Russia, and one to Yemen, implicitly referencing the Iran-backed Houthi militia.
“Chilling Examples”
Outside reviewers who read the report before publication are calling the findings serious and urging strict access restrictions on powerful AI models.
Andrew Weber, a senior fellow at the Council on Strategic Risks and former U.S. Assistant Secretary of Defense for nuclear, chemical, and biological defense programs, reviewed the report before publication. He called some findings “chilling examples of state-sponsored biological weapons developers tapping into the rapidly advancing capabilities” of leading AI models, according to the New York Times.
“The fact that Russia, China and North Korea continue to develop prohibited biological weapons makes it imperative that we deny their researchers access to these extraordinarily capable models,” Weber said, according to the Washington Examiner.
Susan Monarez, a microbiologist and former acting CDC director who also reviewed the report, warned that the same AI capabilities advancing vaccine research could let bad actors “hide in plain sight, using seemingly legitimate research to create pathogens we may not see coming.”
Anthropic CEO Dario Amodei has publicly called bioweapons assistance a hard constraint Claude should never cross and has supported stronger regulatory controls on AI-enabled bioengineering. The report’s disclosures are likely to add weight to those calls, particularly for binding safety standards tied to existing biological weapons treaties and export control regimes.




























