Anthropic said Thursday it disrupted multiple attempts by state-linked researchers and other actors to use its Claude models for dual-use biological work that could support weapons development — and that the company often could not tell whether the research was legitimate science or something darker.

The disclosure comes in Anthropic’s September 2026 threat intelligence report, covering misuse the company says it identified and shut down between December 2025 and August 2026 across seven harm areas, including cyber operations, influence campaigns, surveillance, scams, biological misuse, conventional weapons, and illicit model distillation. NBC News and the New York Times highlighted the biological cases.

According to Anthropic’s report and NBC’s account, researchers tied to state institutions in regions where Anthropic blocks service repeatedly evaded those geographic restrictions — often through reseller platforms — to put Claude to work on pathogen-related research the company treats as dual-use. Anthropic described five notable biological-misuse case studies. In one, a reseller routed virologists working on a state-sponsored grant involving chikungunya gain-of-function work around regional blocks. In others, actors sought help planning avian-influenza mammalian-adaptation experiments, drafting an orthopoxvirus immune-evasion grant application, building toxin-related computational pipelines, or keeping agent identities vague in progress reports for a national program.

Anthropic said it banned the linked accounts, tightened classifiers that restrict dual-use biological queries on newer models (including Claude Fable 5), and shared intelligence with authorities and industry partners where appropriate. The company stressed a core problem for private AI labs: the same biological knowledge that produces vaccines can also help engineer dangerous pathogens, so intent is hard to prove from prompts alone. “We could not determine whether the research served a legitimate or nefarious purpose,” the Times summarized Anthropic as saying — leading the company to shut the work down out of caution.

The same report catalogs cyber and surveillance misuse that should worry anyone who distrusts concentrated state power. Anthropic says suspected state-nexus operators used Claude to automate phishing, credential theft, and data exfiltration; commercial spyware vendors and propaganda shops showed up in other chapters. Influence-as-a-service networks used the models to mass-produce fake news sites and sockpuppet accounts aimed at elections from Malaysia to Africa. In short: governments and criminals are treating frontier models as cheap labor for coercion and espionage.

That is the double bind for AI policy. Anthropic is asking the public to trust a private lab’s threat team — and increasingly, lawmakers — to police queries that blur into scientific research. OpenAI, in a separate Wednesday post, is pushing Congress for mandatory national AI safety rules. Voluntary corporate bans can be gamed by resellers; federal mandates risk locking in incumbents and chilling legitimate science. What Thursday’s report actually proves is narrower and uglier: when states want dual-use biology help or domestic surveillance tooling, they will route around the terms of service. The safeguard that matters most is still who holds power — and who gets to define “misuse.”

Sources