Anthropic, the company behind Claude AI, has identified five cases in which its artificial intelligence models were used for research activities that could potentially support the development of biological weapons.
The company disclosed the cases in its latest threat intelligence report, which examined malicious or potentially harmful activities detected and disrupted on its platform between December 2025 and August 2026.
According to Anthropic, the flagged cases involved research related to chikungunya virus, highly pathogenic avian influenza, orthopoxviruses, venom peptides and toxins.
The company said it had banned the accounts involved and incorporated lessons from its investigations into its safety safeguards, enforcement measures and threat intelligence systems.
Anthropic stressed that identifying the cases did not mean the researchers involved intended to cause harm.
The company said it would not disclose the names of the research institutions, countries or specific biological agents and techniques involved, noting that revealing such information could expose the researchers or their laboratories to harm.
Anthropic said the incidents highlighted the difficulty of separating legitimate scientific research from activities that could potentially be adapted for harmful purposes.
The company described biological misuse as one of the most serious risks associated with increasingly capable AI systems, warning that artificial intelligence could potentially be used to make existing pathogens more dangerous or contribute to the creation of new ones.
At the same time, Anthropic noted that the same scientific information that could be misused in biological weapons research could also contribute to beneficial work, including vaccine and disease-treatment development.
In the first case, Anthropic’s biological safety classifier blocked a request involving the preparation of a grant application for gain-of-function research on chikungunya virus.
The company’s subsequent investigation found that a reseller platform had been providing access to Claude to researchers in regions where Anthropic does not offer its services.
Anthropic said the platform also routed requests rejected by Claude to other AI models with less restrictive safeguards.
Following the investigation, Anthropic said it banned the accounts involved, worked with partners to shut down the relay networks and shared its findings with other AI companies and government authorities.
In another case, Anthropic said a researcher outside the United States used Claude over several weeks while planning research involving highly pathogenic avian influenza and its adaptation to mammals.
The researcher reportedly used the AI system for study planning, data analysis, interpretation and prioritisation of experiments, as well as editorial assistance.
Anthropic said its safeguards restricted the researcher to weaker Claude models, meaning the AI’s contribution was largely limited to clerical assistance, research ideation and study design.
Nevertheless, the company said the case provided evidence of active research programmes involving pathogens with enhanced pandemic potential.
A third case involved a grant application for orthopoxvirus research at a state-associated infectious disease laboratory.
Anthropic said a reseller relay serving more than a dozen customers had used Claude to help draft the application.
The application reportedly focused on research into how orthopoxviruses interact with the immune system and was produced using Claude Opus 5 in about an hour.
The fourth and fifth cases involved research into venoms and toxins.
Anthropic said one researcher used Claude to develop an atlas of venom toxin peptides and a generative system designed to optimise toxin characteristics. The stated objective was to develop therapeutic molecules.
In another case, a researcher used Claude in projects involving the computational redesign of toxins under a national public research programme.
Anthropic said the researcher deliberately concealed the identities of some toxins and viral proteins in progress reports.
The company said both accounts were banned in May 2026 for violating its Supported Regions Policy.
Despite the cases, Anthropic cautioned against interpreting its findings as evidence that Claude is currently enabling an imminent biological threat.
The company said the incidents should instead be viewed as evidence that significant dual-use research efforts are associated with state actors of concern.
The report is part of Anthropic’s broader investigation into the misuse of its AI systems.
The company said that during the eight-month period covered by its investigations, it also uncovered activities involving cyber operations, surveillance, influence operations, scams and fraud, conventional weapons development and attempts to illicitly distil its AI models.
The findings come amid wider debate over how governments and AI companies should manage increasingly capable artificial intelligence systems whose capabilities can be applied to both legitimate scientific research and potentially harmful activities.


