AI
Claude can design proteins, but it can't help you study viruses
Anthropic published a wet-lab-validated protein binder result on 18 August 2026, then disclosed an 11-month biosecurity classifier gap. The two stories together explain why the world's most capable protein designer is also the one most locked out of virology.
Anthropic released two findings this week that pull in opposite directions. The first is a remarkable capability result: Claude, a general-purpose AI assistant, designed functional protein binders against 14 of 15 disease targets in a single run, validated independently in a wet lab, with hit rates nearly double the field's standard. The second is a remarkable admission about governance: for almost a year, the biological-content classifiers meant to keep Claude from helping to build bioweapons were silently disabled across roughly 133 million contractor conversations, and no one noticed. Both facts landed in the same week. They tell the global scientific community something it has been arguing about for years: AI is now a real laboratory tool, and it cannot be governed by classifier signals alone.
What happened?#
On 18 August 2026, Anthropic published results from a protein binder design campaign run by Claude Mythos Preview and Claude Opus 4.8. The two models were given a 30,000-token prompt, access to a corpus of papers, the open-source protein-design toolchain talready used in the field and up to 12,500 hours of compute on NVIDIA H100 GPUs. They produced 1,320 candidate protein sequences across 15 disease targets. Independent contract research organisations Adaptyv Bio and Twist Bioscience then synthesised every design and tested whether it actually bound. 354 of the 1,320 designs bound, a 26.8% hit rate across the multi-target campaign and 35.1% in single-target mode. The typical protein-design campaign today runs at 10 to 15%, according to the Anthropic write-up. Against one target, RBX1, the model's top design bound with a 3.9 nM affinity, beating the 45 nM winning entry of an open competition where only 9 of 245 designs bound at all.
In a second experiment, Claude Opus 5, the company's generally available model, was given raw NMR and LC-MS instrument files from a contract lab, with no documentation, and a two-sentence prompt. It returned chemical-shift analysis, hydrogen counts, and a purity estimate of 96.4%, within a tenth of a percent of the lab's own analyst, in 19 to 23 minutes. The whole workflow, prompts, structure predictions, and binding data for all 1,320 designs, is now public under a CC-BY-4.0 licence.
The same post is also where Anthropic confirmed what many had suspected: life-science research tasks, including the protein design capability itself, remain blocked in Claude Fable 5, the company's most capable model. Anthropic said the block is part of a "trusted access" program for credentialed scientists that the company called one of its highest priorities but has not yet launched. Until then, Opus 5 remains the most capable generally available Claude for life-science work.
Background: protein binders, agents, and the new laboratory#
A protein binder is a small engineered protein that latches onto a target protein, such as a receptor on a cell surface, with high affinity. Most modern drugs are binders, or use them. Designing one from scratch, what the field calls de novo design, has been the bottleneck of early-stage drug discovery for two decades. It requires choosing a target, identifying where on the target the binder should attach (an "epitope"), generating a candidate structure, optimising its sequence for stability and binding, screening for expressibility, and validating experimentally. Each step used to demand a different specialist.
In the last four years, machine-learning models such as AlphaProteo from Google DeepMind, RFdiffusion from the Baker lab, and Chroma have turned the design step itself into a near-routine computation. They still, however, demand days or weeks of orchestration by a computational biologist who knows which tool to use when, and a wet lab to make and test what comes out.
An "AI agent" is a model given a goal, a toolbox, and permission to plan and execute multi-step work without a human in the loop. Claude was given that role here. The novelty is not the model or the underlying design tools. The novelty is that a general agent orchestrated the entire campaign, from target research through wet-lab submission, in roughly the time it would take a human to read the first paper.
Why this matters#
For drug discovery, the implications are immediate. A campaign that used to take a small team months of compute and screening was completed by one Claude instance in 24 to 48 hours, with no human steering after the initial prompt. The 29-page technical report makes clear the model is not yet an autonomous scientist. It is, however, an autonomous lab technician, and the bottleneck it compresses is the one that limits how many candidate drugs a biotech can afford to make in a quarter.
For virology and pandemic preparedness, the story is more complicated. The same general capability that makes Claude a good antibody engineer would also make it a useful assistant for someone trying to engineer a viral protein. Anthropic itself lists virology, toxicology, and molecular design as dual-use domains where its strongest model still falls back to the less capable Opus 5, a routing decision made on a per-query basis. On 7 August the company said it had reduced false-positive "fallbacks" in Fable 5 by about 85%, but the underlying restrictions remain.
That decision became easier after an unusual disclosure in the same week's August 2026 Risk Report. Anthropic revealed that from May 2025 to April 2026, a flag intended only for internal debugging turned off the blocking biological classifiers for every external contractor using Claude for human-feedback data collection. Roughly 50,000 contractors and 133 million conversations went unfiltered. A retrospective review of every retained transcript using Claude Sonnet 5 surfaced 1,197 high-risk conversations, of which 62 were not from sanctioned red-teaming; humans reviewed all 62 and found no clear evidence of bioweapon uplift, according to the report. Anthropic nonetheless raised its internal catastrophic-harm rating for non-novel bioweapons from "very low" to "low" and acknowledged the discovery means it is "less confident" that other gaps do not exist.
The combination matters for pandemic preparedness because it is exactly the case the field has been warning about. The most useful model in the world for protein engineering is also the most useful for viral protein engineering. The same week it was shown to design real binders, it was shown to have spent a year with one of its main guardrails off, by accident, on the traffic of contractors who had not been screened for the kind of expertise that would make misuse plausible.
Critical analysis#
The protein-design result is real but has clear limits. The campaign failed outright on one target, maltose-binding protein, where none of the 90 designs bound. On a synthetic protein not found in nature, BBF-14, performance was modest. The model was also never asked to demonstrate biological activity, only binding. A binder is the first step of a drug, not the drug. None of the 354 binders was tested for any therapeutic effect, and no protein-target complex was structurally solved.
The hit-rate comparison is also Anthropic's own, against a "10 to 15% typical" figure the company chose to highlight. As the analysis from fourweekmba.com puts it, the framing, the chosen baselines, and the chosen comparison targets all belong to Anthropic. The independent wet-lab validation is the strong part of the story; the marketing around it is not.
The biosecurity disclosure has limits of its own. Anthropic disclosed the gap itself, in a public document, which is a higher standard than its peers publish. The 1,197-conversation review, however, was done by Claude Sonnet 5, a system trained by Anthropic, not an independent auditor. The "no clear evidence of misuse" finding has not been independently verified. Critics at the Belfer Center at Harvard have argued that voluntary self-reporting by frontier labs is structurally inadequate for an industry whose products can plausibly enable catastrophic harm, and the August disclosure is, in a sense, the case for that argument.
For the timeline to real-world impact, expect two distinct clocks. On the protein-design side, the public dataset, the 12,500 H100-hour recipe, and the fact that every model Claude orchestrated is open-source mean any academic lab with a GPU cluster can reproduce a similar campaign within weeks. The bottleneck is the contract lab fee for synthesis and binding assays, not the AI. On the safeguards side, the trusted access program has no announced launch date. Until it does, the strongest protein designer in commercial deployment cannot help credentialed virologists design antiviral candidates, even though it is freely available for the same task in a different disease area.
Expert perspective#
The closest published comparison is AlphaProteo, from Google DeepMind, which reports sub-nanomolar binding affinities and 9 to 88% success rates on seven therapeutic targets, with a single round of medium-throughput screening. However, making a head-to-head comparison of AlphaProteo and Claude is WRONG because AlphaProteo was built specifically for binder design. Claude was not. It is a general agent that happens to be very good at one specialist task because it can plan and orchestrate a toolchain better than any single tool can.
What is genuinely new is the level of autonomy. Earlier protein-design agents needed an expert to choose the epitope, swap tools when one stalled, and decide which result deserved wet-lab validation. Claude made those decisions for itself across 15 targets at once, with the only intervention being approvals for infrastructure access. The technical report notes that expert-led campaigns using active feedback would almost certainly score higher, which is the right caveat.
Anthropic is notorious for restricting its highly capable models from being used for virus research and pandemic preparedness. Even if they produce the best binder design automation workflow, it may not be of any use for high-value research with current safeguards in place.
Key takeaways#
- Claude designed working protein binders for 14 of 15 disease targets in a fully autonomous, independently validated run, with hit rates roughly double the field's typical range.
- The same week, Anthropic disclosed that its biological-content classifiers were silently disabled for nearly a year on 133 million contractor conversations, the largest single biosecurity gap yet disclosed by a frontier lab.
- Virology, toxicology, and molecular design remain explicitly routed away from Claude Fable 5, the company's most capable model, regardless of who is asking.
- The "trusted access" program for credentialed life-science researchers, the one place where virologists could use the strongest Claude for antiviral work, has no announced launch date.
- Every model Claude used is open-source, so the result is reproducible today; the wet-lab bill, not the AI, is the new bottleneck.
Frequently asked questions#
Did Claude really discover new science? No. Claude orchestrated existing open-source protein-design tools faster and more systematically than a typical human workflow. The novelty is in the orchestration, not in the underlying science.
Why are virology queries still restricted on Claude Fable 5? Because the same general capability that makes Claude a good antibody engineer would also make it a useful assistant for someone trying to engineer a viral protein. Anthropic lists virology, toxicology, and molecular design as the dual-use domains where it still falls back to the less capable Opus 5.
Was the 11-month classifier outage a hack? No. It was a configuration bug. An internal flag intended for debugging turned off both the blocking action of the biological classifiers and the logging that would have caught the gap. Anthropic's August 2026 Risk Report calls it a feature-flag mistake.
Can I run this campaign myself? If you have GPU access, yes. The prompts, structure predictions, and binding data are public on Hugging Face under CC-BY-4.0. The expensive part is paying Adaptyv Bio or Twist Bioscience to synthesise and test the designs.
Is the protein design capability available in Claude today? No. The capability used in this research is gated behind a coming trusted-access program for credentialed scientists. For life-science work today, the most capable generally available model is Opus 5.
What does this mean for pandemic preparedness? In the short term, the technology for designing antiviral candidates is now in the hands of any academic lab. In the medium term, the labs that can do this work without losing their best tools to classifier restrictions will be the ones with formal access agreements, which today are very few.
Glossary#
De novo protein design: engineering a new protein from scratch, without using an existing natural protein as a starting template.
Hit rate: the fraction of computational designs that, when synthesised and tested in a wet lab, actually bind their target.
Affinity (KD): a measure of how tightly a binder attaches to its target. Lower numbers mean tighter binding; nanomolar and picomolar affinities are typical of effective drugs.
Dual-use research of concern (DURC): life-science research whose findings could be used for both beneficial and harmful purposes, such as viral protein engineering.
Classifier (in this context): an automated system that reads prompts and outputs to flag or block potentially dangerous biological content before a model is allowed to respond.
Fallback routing: when a high-capability model is asked a question in a restricted domain, sending the query to a less capable model with different guardrails instead of answering it directly.
Agent: an AI system given a goal and a toolbox, with permission to plan and execute multi-step work without a human in the loop.
References#
- Anthropic, "How Claude is accelerating protein design and analytical chemistry," 18 August 2026. https://www.anthropic.com/research/Claude-accelerates-protein-design
- Amir Shanehsazzadeh et al., "Autonomous De Novo Protein Binder Design with Claude," alphaXiv preprint, 18 August 2026. Preprint (not peer-reviewed). https://www.alphaxiv.org/abs/2608.claude-de-novo
- Anthropic, Risk Report: August 2026, 14 August 2026. https://www.anthropic.com/aug-2026-risk-report
- Anthropic, Responsible Scaling Policy, version 3.4, last updated 14 August 2026. https://www.anthropic.com/responsible-scaling-policy
- "Anthropic releases dataset behind Claude's 14/15 binder run," AIWeekly, 18 August 2026. https://aiweekly.co/alerts/anthropic-releases-dataset-behind-claudes-1415-binder-run
- "Anthropic says Claude can now design proteins and analyse lab data," India Today, 19 August 2026. https://www.indiatoday.in/technology/story/anthropic-claude-protein-design-raw-lab-data-chemistry-research-2974779-2026-08-19
- "Anthropic tests Claude to design protein binders for drug research, here's how it turned out," CNBCTV18, 19 August 2026. https://www.cnbctv18.com/technology/anthropic-tests-claude-to-design-protein-binders-for-drug-research-heres-how-it-turned-out-19972582.htm
- "Twist Bioscience Assists Anthropic in Testing Whether Claude Can Accelerate Drug-Design Process," MarketWatch, 18 August 2026. https://www.marketwatch.com/story/twist-bioscience-assists-anthropic-in-testing-whether-claude-can-accelerate-drug-design-process-c8ecb923
- "Anthropic's Claude Orchestrated Existing Protein-Design Tools," fourweekmba, 19 August 2026. https://fourweekmba.com/ai-anthropic-claude-protein-design-minibinders-automated-resear/
- "Anthropic acknowledges biosecurity lapse across 133 million AI interactions," ForkLog, 16 August 2026. https://forklog.com/en/anthropic-acknowledges-biosecurity-lapse-across-133-million-ai-interactions/
- "Anthropic ran 133 million contractor chats with its bioweapon filters off," The Next Web, 16 August 2026. https://thenextweb.com/news/anthropic-risk-report-bio-classifiers-human-feedback-gap
- "Anthropic's Safety Report Details Its Own Process Failures," SERVOLA, 16 August 2026. https://servola.de/journal/anthropic-safety-report-lists-its-own-failures/
- "Anthropic Raises Misalignment Risk to Low and Shelves Internal Model 2," Unite.AI, 16 August 2026. https://www.unite.ai/anthropic-raises-misalignment-risk-to-low-and-shelves-internal-model-2/
- "Anthropic Loosens Fable 5's Biology Leash," AI-360, 7 August 2026. https://www.ai-360.online/anthropic-loosens-fable-5s-biology-leash/
- "Anthropic's bio-weapons filter was offline for nearly a year," AI Navigate, 17 August 2026. https://ai-navigate.net/en/updates/2026-08-17/anthropic-s-bio-weapons-filter-was-offline-for-nearly-a-year
- "Anthropic explains why its latest AI models remain a low catastrophic risk despite rising uncertainty," News18, 15 August 2026. https://www.news18.com/tech/anthropic-explains-why-its-latest-ai-models-remain-a-low-catastrophic-risk-despite-rising-uncertainty-ws-l-10274592.html
- "Anthropic Risk Report Aug 2026: Risk Raised to 'Low'," explainX, 15 August 2026. https://explainx.ai/blog/anthropic-august-2026-risk-report
- "Claude Protein Design: 14/15 Targets, Beats Field Hit Rate," explainX, 19 August 2026. https://explainx.ai/blog/claude-protein-design-analytical-chemistry-august-2026
- "The Dual-Use Frontier of AI-Enabled Biotechnology," Belfer Center, August 2026. https://www.belfercenter.org/research-analysis/dual-use-frontier-ai-enabled-biotechnology-civilian-opportunities-national
- "De novo design of high-affinity protein binders with AlphaProteo," Google DeepMind, 12 September 2024. https://www.alphaxiv.org/abs/2409.08022
- Nathan C. Frey, X post announcing the protein design update, 18 August 2026. https://x.com/nc_frey/status/2089849837399195939
- Adaptyv Bio, BenchBB. https://www.adaptyvbio.com/blog/benchbb
- Anthropic, "claude-protein-binder-design" dataset on Hugging Face, CC-BY-4.0. https://huggingface.co/datasets/Anthropic/claude-protein-binder-design
- Anthropic, technical report PDF accompanying the protein design post. https://www-cdn.anthropic.com/30bf50e22a01388bb29bf077ee3f244531594b7a.pdf
- "Anthropic says 354 Claude protein designs bound in lab tests," RuntimeWire, 18 August 2026. https://runtimewire.com/article/anthropic-claude-autonomous-protein-binder-design