Anthropic published a report on Thursday describing five cases in which researchers in countries where it restricts access to its models got around those restrictions and used Claude for biological work the company judged dangerous enough to cut off. In the episode it details most fully, from May, a user asked Claude to help write a government grant application for a project to engineer more dangerous mutations of chikungunya, a mosquito-borne virus that causes fever and severe joint pain. Anthropic believes the work may have been running inside a military research institute. Every account tied to the five episodes has been banned. What the company cannot say is whether any of it was an attempt to build a weapon.
That last part is the report, not a gap in it. Anthropic states plainly that it could not reliably determine whether the requests belonged to legitimate science or to a bioweapons effort, and says it chose to act with maximum caution despite the uncertainty. Jacob Klein, who runs threat intelligence at the company, told The New York Times that Anthropic does not know whether the results were meant for military use, but that gain-of-function research inside a military facility is cause for concern. Gain-of-function work is research whose purpose is to strengthen or add biological properties to organisms and pathogens. Klein also said these situations rarely arrive as an open declaration of intent to build a weapon for mass killing; they are deeply ambiguous, and user intent is hard to pin down.
The mechanism of the failure matters more than the tally of cases. According to Anthropic, the users concealed the real purpose of their research specifically so that Claude's protections would not fire. By the company's own account, those protections did not hold. Whatever the report says about foreign researchers, it is also a document in which a frontier lab states that its published safeguards can be walked around by anyone willing to describe their project in different words — and that the same route remains open to whoever tries next.
The timing sits awkwardly. The report landed in the middle of a fresh argument about AI safety, with a former Anthropic employee accusing the company of irresponsibly developing powerful systems while knowing what they could destroy. Anthropic's answer, in effect, is that it is the one catching the abuse. Dario Amodei has made the bioweapons case for years, including in a long essay published earlier this year, where he wrote that the company keeps improving its defenses so its models do not assist biological weapons research, and that legislation and international cooperation are needed to bring the risk down.
Here is my reading. A report like this does two jobs at once, and only one of them is safety. It documents a control failure, which is genuinely useful. It also demonstrates that the product is powerful enough to be worth misusing — a claim Anthropic has been accused of inflating about its own technology for marketing reasons. Both things can be true, and the report does not help a reader separate them, because the load-bearing question goes unanswered: did Claude actually supply capability the researchers did not already have? Drafting a grant application is writing. Nothing in the report says the model contributed virology that a state laboratory could not obtain on its own. Until a disclosure like this one addresses that directly, the severity of the finding rests on an assumption rather than evidence, and "we blocked accounts that might have been dangerous" is not the same claim as "we prevented a weapon."
Not everyone reads it that cautiously. Andrew Weber, a senior fellow at the Council on Strategic Risks who saw the report before publication, told The New York Times that its findings show alarming examples of state-backed bioweapons developers beginning to use the fast-growing capabilities of advanced AI models.
The uncomfortable part of the episode is structural. The detection here was done by the vendor, on its own logs, and disclosed on a schedule of its own choosing. There is no equivalent report from anyone else, which tells a reader nothing about whether the same attempts are landing elsewhere. And a banned account ends a customer relationship, not a research program: if the work Anthropic describes was real, it is still being done — just without the log file.