Artificial intelligence company Anthropic has disclosed five cases in which researchers attempted to use its Claude models for sensitive biological work involving viruses, toxins and other dual-use scientific fields.
The company did not accuse the researchers of intending to create biological weapons. Instead, it said the cases demonstrate how advanced AI systems can assist legitimate scientific research while potentially accelerating projects that could cause serious harm if misused.
Anthropic described biological misuse as one of the most significant risks associated with increasingly capable AI models. Its report offers a rare public account of how researchers have tried to apply frontier AI tools to complex bioscience tasks and how the company’s safety systems responded.
Claude request involving chikungunya research was blockedOne case involved a request connected to a grant application for research on the chikungunya virus, a mosquito-borne infection that can cause fever and severe joint pain.
According to Anthropic, the proposed work examined changes related to the virus’s transmissibility and its ability to evade immune responses. The company classified the request as involving gain-of-function research and said its safeguards blocked it.
The application was reportedly linked to a military research institute, although it indicated that civilian researchers were involved. Anthropic acknowledged that such studies could support vaccine or therapeutic development, but warned that similar methods might also increase a pathogen’s harmful characteristics. This ambiguity illustrates the central challenge of dual-use science: the same technical knowledge may contribute to disease prevention or be redirected towards dangerous objectives.
Avian flu and orthopoxvirus cases raise safety concernsAnthropic also identified a researcher who used Claude while studying highly pathogenic avian influenza and its adaptation to mammals. The work focused on mutations associated with mammalian adaptation and transmission in animal models.
The researcher reportedly used the AI system over several weeks for study planning, data analysis and interpretation. Anthropic said access to its more capable models was restricted, limiting the assistance primarily to administrative and general research-planning functions. Another case involved an application related to orthopoxvirus research at a state-associated infectious disease laboratory. Orthopoxviruses belong to the viral family that includes smallpox and mpox.
Claude was reportedly used to help draft a grant proposal covering the scientific hypothesis, experimental design and other planning elements. The disclosure raises questions about how much assistance AI systems should provide when a project involves pathogens with serious public-health or security implications.
Researchers also sought help with toxins and venom compoundsThe remaining cases involved venom-derived compounds and computationally redesigned toxins. Anthropic said one researcher used Claude to help develop a database of venom toxin peptides and a system for optimising their properties. The stated purpose was to explore potential painkillers and other therapeutic products. However, the company said the same research could potentially be adapted to produce harmful or incapacitating compounds.
In another case, a researcher used Claude for projects involving redesigned toxins connected to a national research programme. Anthropic alleged that the user asked the model to keep descriptions of certain biological agents deliberately vague in progress reports. That request appeared to raise concerns beyond the scientific subject itself because it suggested an effort to obscure important information. Anthropic said it banned accounts linked to the cases and strengthened its safeguards following the investigations.
Dual-use science creates a difficult AI safety testOlder AI systems were generally considered unlikely to provide substantial assistance to sophisticated biological weapons programmes. Newer frontier models, however, can support more complex scientific reasoning, data interpretation and research planning.
This progress makes it harder for safety systems to distinguish between legitimate biomedical work and activity that could be harmful. Research into viruses, immune evasion or toxins may have valuable applications in vaccines, treatments and public-health preparedness while also carrying misuse risks.
Anthropic warned that sophisticated users might conceal dangerous goals behind apparently legitimate scientific requests. Effective safeguards may therefore need to consider not only what a user asks, but also the broader research context, the user’s identity and how advanced scientific capabilities are being applied. The disclosures do not establish that Claude was used to create a weaponised pathogen. They instead show that AI companies are encountering real-world requests near the boundary between beneficial research and potentially catastrophic misuse.