On September 10, 2026, Anthropic published a security report on detecting and countering the misuse of AI. This report is notably different from previous public statements with respect to biology and includes unusually detailed cases of how models were used in ways that could support the development of biological weapons.
This report names specific viruses and methods of safeguard evasion. It is clear that these are presented as case studies, and not as the totality of concerning inquiries nor even the most concerning inquiries they have received.
The five cases they have selected were all dual-use, meaning that they could be interpreted to either enable better medical treatments or the development of bioweapons. As Anthropic points out in their report, this has historical precedent. The Soviet Biopreparat program employed over 30,000 people towards dual-use research with the goal of developing the world’s most sophisticated and deadly biological weapons. Many of the employees were completely unaware that they were supporting this military effort and were under the impression that they were doing basic or defensive research. Hiding work under dual-use inquiries is the type of behavior we would therefore expect from the most sophisticated threat actors.
In this post I will present cases 1, 2, 3, and 5, which I found most concerning, including what the actors did to evade safeguards. Because pathogens are self-replicating, they pose a threat as weapons of mass destruction. The first three cases in the report concern pathogens, and the last two are focused on venoms and toxins. In the fifth case study, one of the toxins and a protein being examined are relevant to transmissible pathogens.
Anthropic has two main layers of safeguards –– blocks on who can use the model, and classifiers that deny or downgrade high-risk biological inquiries to weaker models. In these cases, the second layer mostly held and the first layer failed repeatedly.
Case 1: Chikungunya virus work through an evasion platform for military-civilian research
Pathogen: Chikungunya virus
Research: The inquiries were concerning how to make Chikungunya virus, a mosquito-borne virus with no licensed therapeutic treatment, more transmissible and immune evasive. The inquiries also considered infecting live animals and then selecting for increased virulence. This was presumably presented as research with the intent to then develop better vaccines and therapeutics.
Actor: Unknown/undisclosed researcher(s) outside the US, connected to a military research institute.
Evasion: These researchers were in a country that Claude does not offer service to, so they accessed Claude through a platform used by multiple virologists with both military and civilian affiliation, designed to both hide location and route blocked requests to less restrictive models. They also used a zero data retention (ZDR) service to hide content. Claude itself wrote much of the code that allowed this platform to accomplish goals like routing blocked requests to less restrictive models. It was presented to Claude as work to combat over-refusals. In the development of the platform, Claude was accessed through gray market resellers.
Note on Concern: Though Anthropic banned associated accounts and will continue to do so, it appears this research is ongoing. I am most concerned in this case by the military affiliation and the usage of the evasion platform.
Case 2: Highly-pathogenic mammal-adapted avian influenza
Pathogen: Avian influenza
Research: Research was planned to both identify and introduce mutations in avian influenza that are associated with mammalian adaptation and airborne transmission. Anthropic notes that the research appears to involve access to both animal models and live viral samples.
Actor: Unknown/undisclosed researcher(s) outside the US, working in what Anthropic describes as a credible institutional context.
Evasion: Like Case 1, the researcher accessed Claude from an unsupported region. They used a US virtual private server, and a privacy-prioritizing email provider with an autogenerated username. A classifier successfully blocked or rerouted the inquiries to Anthropic’s weakest models.
Note on Concern: I find this case extremely concerning because of the nature of the pathogen involved, the focus on traits explicitly associated with enhancing pandemic potential, and the researchers’ apparent access to live viral samples and animal models.
Case 3: Covert frontier model access for orthopoxvirus research
Pathogen: Orthopoxvirus
Research: Claude was used to author a grant application for orthopoxvirus research. Like case 2, the researchers seemed to have access to both live virus and high-containment facilities. The research concerned identifying an immune-evasion gene, with the stated goal of deleting it to attenuate the virus. Identification of this gene could also enable gain-of-function work.
Actor: An unknown/undisclosed researcher at a state-associated infectious disease laboratory.
Evasion: The account used an autogenerated email address and anonymizing services. Likely because the work was framed as attenuating the virus, biological classifiers failed and Opus 5 wrote the entire grant application end-to-end for the researcher. The account used a reseller platform with many other customers.
Note on Concern: This is concerning because unlike in cases 1 and 2, Claude did not refuse the work or redirect it to a less capable model. This means that it is, or, at the time was, possible to fool the biological classifiers designed by Anthropic. Orthopoxvirus is a member of the viral family that includes smallpox –– one of the highest concern pandemic-class pathogens. Though this research may have been legitimately focused on attenuating the virus, it is exactly the type of research that would enable you to increase the immune evasion capabilities of a pandemic-class pathogen.
Case 5: Computational redesign of toxins and proteins relevant to pandemic-class pathogens
Pathogen: Bacterial toxin subunit, protein from hemorrhagic-fever virus (on the World Health Organization’s priority list of diseases with the greatest epidemic and pandemic threat)
Research: This work was focused on computationally redesigning a diverse set of toxins. The research was described as state priority research.
Actor: Unknown/undisclosed researcher working under a national public research program in an unsupported area.
Evasion: The report notes that the research was framed in a largely therapeutic context, and that the “identity of the bacterial toxin and viral proteins were intentionally obscured.”
Note on Concern: This case is concerning to me because the work involved computational redesign of a protein belonging to a pandemic-class pathogen. I was also concerned by the researcher deliberately obscuring the identities of the toxins and proteins, as well as the fact that Anthropic’s classifiers seemed not to refuse the work as much as one would hope.
Table Summary
Below is a table summary of some of the important characteristics:
Concluding Notes
It is unlikely that we will get a clear picture of the most concerning inquiries due to wariness of information hazards, and this is a good thing. We should also remember that Anthropic likely gets the least concerning inquiries of a major frontier lab because of the known strictness of their biological classifiers.
From my perspective, the important takeaways here are:
Covert gain-of-function research is likely ongoing internationally.
Foreign actors, likely including adversarial states, will go to lengths to maintain access to US frontier models and evade classifiers.
Not offering support in regions is very easily circumventable and current classifiers are not quite good enough to consistently refuse all concerning inquiries.
Overall, this report is both reassuring and troubling.
I am glad that Anthropic’s various safeguards appear to be preventing the models from providing substantial assistance to potential threat actors. Anthropic’s conclusion that more KYC-style safeguards are needed is correct –– intent is not discernible from just the content of a request. Biosecurity policy should also reflect this.
It is alarming that there are so many cases of researchers engaged in extensive evasive techniques to pursue dual-use research with the help of Anthropic’s models, especially given that these models are known to have particularly strict classifiers. It leaves me wondering what inquiries are being routed to other frontier labs.
Disclaimer: This piece represents my personal views and my personal views only. It does not represent the opinion of any organization I work for or with.


