Virology
Anthropic Admits Its AI Can No Longer Rule Out Bioweapon Help
Anthropic's September 2026 threat report reveals Claude was used in five bioweapons-adjacent research attempts, including a chikungunya gain-of-function request. Here's why virologists and AI safety experts are both worried.
For years, AI companies had a reassuring line about biosecurity: their chatbots simply weren't smart enough to meaningfully help anyone build a bioweapon. On 10 September 2026, Anthropic said that line no longer holds for its newest models, in its own threat intelligence report. Buried in it is a detail that matters well beyond the AI industry: a scientist affiliated with a military research institute reportedly asked Claude to help draft a grant application for gain-of-function research on chikungunya virus, aimed at making the pathogen more transmissible and better at dodging the immune system. Anthropic blocked the request. What it can no longer promise is that its models will always catch the next one.
Anthropic's report, titled Detecting and Countering Misuse of AI: September 2026, covers activity the company disrupted between December 2025 and August 2026 across seven categories of harm, from cyberattacks to influence operations (Anthropic, 2026). One section, on "biological misuse," describes five cases in which people used Claude in ways that could have supported the development of biological weapons, as reported by Axios and Interesting Engineering.
The most striking case, dated May 2026, involved a researcher connected to a military institute who asked Claude for help drafting a grant proposal for gain-of-function work on chikungunya, a mosquito-borne virus that causes severe fever and long-lasting joint pain, for which no licensed antiviral treatment exists. The proposed method, repeatedly passing the virus through live animals to select for greater transmissibility and immune evasion, is a recognised virology technique and also exactly the kind of dual-use research that keeps biosecurity specialists up at night, as Tech Times reported. Anthropic says it blocked the request and referred the case to law enforcement.
A second case involved weeks of Claude use for research into highly pathogenic avian influenza, specifically the mutations that might let it adapt to mammals and spread through the air. Anthropic's safety systems flagged the pattern and restricted that user to weaker model tiers, cutting off access to its most capable systems. Three further cases involved orthopoxviruses (the family that includes smallpox and mpox), venom-derived compounds, and other toxins. In every one of the five cases, Anthropic says it could not determine whether the person intended harm. The requests looked like ordinary, if sensitive, scientific work.
The company's own wording is the real headline here: "Older models were well below the threshold where they could meaningfully assist in bioweapons development. This is no longer a certainty with newer models," as quoted by Tech Times. As far as the public record shows, that's the first time a major AI developer has said this outright.
Background: how virus science and chatbots ended up in the same sentence#
This warning didn't come out of nowhere. On 6 August 2026, a Stanford-led team working with the Arc Institute reported in Science that they had used a generative AI model to design the complete genome of a synthetic bacteriophage, a virus that infects bacteria rather than people, that doesn't exist in nature. The new virus went on to kill E. coli successfully in the lab. It was the first documented case of AI designing a working organism from scratch. The result has real medical promise: phages like these are being explored as alternatives to antibiotics against drug-resistant bacteria. But it also proved a point biosecurity researchers had been raising for a while. If an AI model can design a working genome for a bacteriophage, the same underlying techniques might, in principle, be pushed toward more dangerous pathogens.
That concern was spelled out a month later in a Science paper by researchers from Johns Hopkins, Stanford, Oxford, Columbia, NYU and Fordham, cataloguing specific ways AI tools can lower the technical bar for dangerous biology: designing new protein shells to package a virus's genetic material, forecasting how a pathogen might evolve, generating DNA or RNA sequences built to slip past the screening software gene-synthesis companies use to catch dangerous orders, and designing viral genomes suited to working once assembled in a lab (Bloomfield et al., Science, 2026). That's the technical backdrop Anthropic's disclosure landed on. Not a standalone incident, but the latest point on a line biosecurity experts had already been tracking.
It also connects to an older argument. Gain-of-function research, deliberately altering a pathogen's properties to study how it might behave, became a flashpoint after Ron Fouchier and Yoshihiro Kawaoka showed H5N1 bird flu could be made to spread between ferrets, the standard stand-in for human transmission, as CIDRAP has documented. That fight led to a US moratorium on certain gain-of-function studies from 2014 to 2017, and afterwards to the P3CO oversight framework for pandemic-pathogen research. The chikungunya case sits squarely inside that decade-old grey zone. Except now the question isn't just whether a lab should do the work; it's whether a chatbot should help plan it.
Why this matters#
For virology and public health, the stakes are fairly simple. The tools that let scientists study how viruses evolve naturally are the same tools that could, in the wrong hands, help engineer something worse on purpose. Anthropic's report suggests an AI assistant can now narrow the gap between a trained virologist with lab access and someone with a laptop and a subscription, at least for parts of the planning and analysis work. That doesn't mean anyone can build a pandemic pathogen with a chatbot tomorrow. The physical work of synthesising and testing a virus still needs specialised equipment, materials and expertise. But research planning, literature synthesis and experimental design were bottlenecks too, once, and this report suggests they're wearing thin.
For the AI industry, this is a genuine break from the previous "not yet, but someday" pattern of reassurance. It forces every frontier lab to ask whether its own systems have quietly crossed a similar line, and it hands ammunition to the roughly 70% of national security experts who, in a recent survey by the Institute for Security and Technology, said AI already meaningfully raises bioweapon risk, or will within two to three years (ISI survey, 2026).
For pandemic preparedness, the timing is uncomfortable. The Democratic Republic of the Congo is currently battling one of the largest Ebola epidemics on record, caused by the Bundibugyo strain, with confirmed deaths above 3,000 as of early September 2026, according to WHO outbreak reporting. A naturally occurring virus is still capable of overwhelming health systems this badly. That's worth sitting with: engineered threats are a risk layered on top of a very real, ongoing one, and money spent guarding against speculative AI-enabled bioweapons is money not spent on vaccines, surveillance or outbreak response for the pathogens already circulating.
Critical analysis#
Anthropic deserves some credit here. Publishing detailed, self-incriminating case studies isn't something companies do lightly, and this disclosure is more candid than most competitors' public statements on the subject. The company caught all five cases, banned the accounts involved, tightened safeguards for Claude Fable 5 and later models, and referred at least one case to law enforcement.
The report still has real limits that Anthropic doesn't fully resolve. It can only describe what its own monitoring caught, not what slipped through, what happened on rival platforms, or what determined actors managed by other means entirely. Anthropic is also the only party currently positioned to audit Anthropic's threat intelligence. No independent body reviews its methodology or checks that its safeguards are adequate, a gap outside commentary has already flagged.
There's also real ambiguity in the underlying science. Chikungunya, avian influenza and orthopoxvirus research are all legitimate, actively funded fields. The serial-passage technique used in the blocked case is a standard tool for studying viral evolution, not inherently a weapons programme. Anthropic itself admits it couldn't establish malicious intent in any of the five cases, and that's precisely what makes this hard: dual-use research doesn't announce itself, and a policy that blocks too aggressively risks slowing the very pandemic-preparedness science that makes outbreaks like the current Ebola epidemic survivable at all.
Don't expect quick fixes. Mandatory gene-synthesis screening, standards for how AI models handle biological data, and some form of independent audit for AI safety claims are all under discussion in Washington and elsewhere, but none has become binding law yet. Even RAND's own proposed "layered defence" is explicitly framed as a multi-year build, not an immediate patch (Guerra, RAND, 2026).
Expert perspective#
Jacob Klein, Anthropic's head of threat intelligence, told the New York Times that these situations rarely arrive with an obvious declaration of malicious intent. Researchers can present entirely plausible scientific goals while pursuing methods that carry serious dual-use risk, as reported by Interesting Engineering. Susan Monarez, a microbiologist and former US public health official who reviewed the report before publication, told the same outlet that advanced models could help bad actors hide dangerous research behind legitimate-looking scientific cover.
Steph Guerra, a molecular biologist at the RAND Corporation, has argued that the August Science paper on AI-designed bacteriophages and Anthropic's disclosure are two sides of the same problem. Even though the Stanford and Arc Institute virus only infects bacteria, the underlying design capability, combined with the kind of research assistance Anthropic just documented, is narrowing the distance between what only elite, well-funded labs could once do and what a smaller, less careful group might attempt (Guerra, Bulletin of the Atomic Scientists, 2026). What sets this moment apart from earlier biosecurity scares, in her view, isn't that the science itself is new. Gain-of-function research and dual-use biology have existed for decades. It's that AI compresses the time and expertise needed to attempt it, faster than regulators have managed to keep up.
Key takeaways#
Anthropic disclosed, for the first time publicly by a major AI company, that its newest models can't be assumed to sit safely below the threshold for meaningful bioweapons assistance. The company blocked five cases of Claude being used for biology research carrying weapons-relevant risk, including a chikungunya gain-of-function grant request tied to a military institute. This builds directly on an August 2026 Science paper showing AI can already design working synthetic virus genomes, albeit ones that only infect bacteria so far. None of the five disrupted cases had provable malicious intent, which shows how badly dual-use research resists simple screening. And all of this is unfolding while a real, naturally occurring Ebola epidemic in Central Africa is a blunt reminder that engineered-pathogen risk is still hypothetical, while gaps in outbreak-response funding are not.
Frequently Asked Questions#
Did Anthropic's AI actually help someone build a bioweapon? No. Anthropic says it detected and blocked all five documented cases before any dangerous outcome, and none involved a completed weapon. The concern is about the assistance the AI could have given, not a realised attack.
What is gain-of-function research, in plain terms? It's laboratory work that deliberately changes a pathogen's properties, for example making it spread more easily or evade the immune system, usually to understand how it might evolve naturally and prepare countermeasures in advance. The same methods could, in principle, be misused to make a pathogen more dangerous on purpose.
Is chikungunya virus dangerous? Chikungunya causes fever and severe, sometimes long-lasting joint pain. It's rarely fatal but can be seriously debilitating, and there's no licensed antiviral treatment, only supportive care and, in some countries, preventive vaccines.
Did the Stanford and Arc Institute AI-designed virus infect humans? No. The synthetic viruses described in the August 2026 Science paper were bacteriophages, engineered to infect and kill E. coli bacteria, not human cells.
What is Anthropic actually doing to prevent misuse? The company says it has added stricter safeguards to Claude Fable 5 and later models, specifically restricting a wide range of dual-use biological research queries, and that it shares intelligence on disrupted cases with law enforcement and industry partners.
Can regulators actually stop this kind of misuse? Not fully, and not yet. Proposals like mandatory gene-synthesis order screening and formal government review of frontier AI models exist mostly as draft legislation or voluntary industry commitments so far, not enforced law.
Does this mean AI companies should stop building biological research tools altogether? Most experts cited in this reporting argue against that. Tools like AlphaFold have delivered real benefits in medicine and biology. The challenge is telling beneficial dual-use research apart from misuse, not blocking biological AI outright.
Why does this matter if I'm not a scientist or AI researcher? Biosecurity policy shapes how quickly future vaccines and treatments get developed, how much oversight AI companies face, and, in a worst case, how ready health systems are to respond to an engineered outbreak. It's a public-interest question, not just an industry one.
Glossary#
Gain-of-function research: Laboratory work that alters a pathogen to give it new or enhanced properties, such as greater transmissibility, usually to study how it might evolve.
Dual-use research of concern (DURC): Legitimate scientific research that could also be readily misused to cause significant harm, such as work that could make a pathogen more dangerous.
Bacteriophage: A virus that infects and replicates inside bacteria, harmless to humans and other animals.
Orthopoxvirus: A genus of viruses that includes smallpox and mpox, notable for its potential to cause severe disease and its history in bioweapons concerns.
P3CO Framework: The US government's "Potential Pandemic Pathogen Care and Oversight" policy, which governs federally funded research that could create pathogens capable of causing a pandemic.
Serial passage: A laboratory technique in which a pathogen is repeatedly transferred between hosts, such as live animals, to select for particular traits, including increased transmissibility.
Threat intelligence report: A structured disclosure, published periodically by AI companies like Anthropic, detailing detected attempts to misuse their systems and the countermeasures deployed.
Frontier model: Industry shorthand for the most advanced, highest-capability AI systems a company has released, as distinct from older or smaller models.
References#
- Anthropic. "Detecting and Countering Misuse of AI: September 2026." Published 10 September 2026. anthropic.com/threat-intelligence-report-september-2026 (primary source)
- Bettelheim, A. and Owens, C. "How AI makes biological research more dangerous." Axios, 11 September 2026. axios.com/2026/09/11/ai-warnings-biological-research-dangerous
- Khollam, A. "Anthropic says scientists exploited Claude for bioweapons research." Interesting Engineering, 10 September 2026. interestingengineering.com/ai-robotics/anthropic-scientists-claude-lethal-bioweapons-research
- Culbertson, D. "Anthropic Threat Report: AI Models Near Bioweapons Threshold as Drone Kill Software Emerges." Tech Times, 11 September 2026. techtimes.com/articles/327308
- Bettelheim, A. "Stanford team designs first AI-generated virus." Axios, 6 August 2026. axios.com/2026/08/06/ai-virus-designed-bacteria-viruses
- Bloomfield, D. et al. "Strengthening nucleic acid biosecurity screening against generative protein design tools." Science 391, 558-561 (2026). doi.org/10.1126/science.aeb2689 (peer-reviewed)
- Guerra, S. "Newly created viruses are a warning. We still have a window to stop AI-enabled bioweapons." Bulletin of the Atomic Scientists, 4 September 2026. thebulletin.org/2026/09/newly-created-viruses-are-a-warning
- Guerra, S. "AI Can Now Design Viruses. We Need Biosecurity Guardrails Now." RAND Corporation Commentary, 4 September 2026. rand.org/pubs/commentary/2026/09/ai-can-now-design-viruses
- Callaway, E. "AI can design viruses, toxins and other bioweapons. How worried should we be?" Nature 653, 344-347 (2026). nature.com/articles/d41586-026-01476-x
- CIDRAP. "Fears about mutant H5N1 hinge on ferrets as flu model." University of Minnesota. cidrap.umn.edu
- Institute for Security and Technology. "AI and the Future of National Security" survey, September 2026. securityandtechnology.org
- World Health Organization. "Ebola disease caused by Bundibugyo virus, Democratic Republic of the Congo." Disease Outbreak News, 2026. who.int/emergencies/disease-outbreak-news/item/2026-DON617