Anthropic blocked at least 35 state-sponsored attempts to exploit Claude AI for bioweapons research between November 2025 and September 2026. The attempts involved gain-of-function research on bird flu and chikungunya, studies on orthopoxviruses, and cataloging lethal toxins. Users from blocked regions used anonymizing techniques to evade safeguards, prompting Anthropic to strengthen Claude Fable 5's safety protocols.

Anthropic Identifies State-Sponsored Attempts to Exploit Claude for Bioweapons Research

Anthropic, the San Francisco-based AI company led by Dario Amodei, has revealed it blocked approximately 35 distinct state-sponsored attempts to use Claude AI for bioweapons research between November 2025 and September 2026

1

. The company detailed five specific cases in a new misuse report where suspected rogue actors circumvented controls designed to prevent users in certain regions from accessing Claude's extensive knowledge base regarding infectious diseases and lethal toxins

2

.

Source: Gizmodo

Source: Gizmodo

Specific Cases Reveal Sophisticated Evasion Tactics

One flagged case involved gain-of-function research aimed at making the chikungunya virus more transmissible and dangerous to humans. Users attempting this research tunneled traffic through U.S. infrastructure to evade regional blocks and used zero data retention services to hide content

2

. What alarmed Anthropic most was that the queries sought help drafting a grant application for research intended at a military institute, prompting an internal investigation even after Claude rejected the requests.

Another account was banned for researching how the bird flu virus could be adapted to cause severe illness in mammals

1

. Additional cases involved queries about orthopoxviruses—a genus including variola, which causes smallpox—and attempts to catalog venom peptides capable of inducing paralysis

2

. While venom research has legitimate applications in pain relief and cancer treatment, the specific focus on paralysis-inducing compounds raised red flags.

Dual-Use Dilemma Complicates Detection

Anthropic acknowledged the challenge of distinguishing between legitimate research and misuse of AI. Jacob Klein, Anthropic's head of threat intelligence, explained that detecting harmful intent isn't straightforward: "You are not seeing someone in a comic book kind of way say, 'Hey, I want to build a biological weapon to kill everybody'"

2

. The dual-use biological research problem means projects intended to develop vaccines or antidotes can easily be inverted into creating biological weapons themselves.

Source: TechSpot

Source: TechSpot

What triggered Claude's safety protocols in these cases wasn't just the content of queries but the use of anonymizing techniques to evade Anthropic's regional blocking. The company blocks users in China, Russia, Iran, North Korea, and several other countries from accessing Claude, and all suspect accounts were blocked by May 2026 for violating its Supported Regions Policy

1

.

Strengthened Safeguards in Claude Fable 5

In response to these biological risks, Anthropic upgraded AI safety protocols when launching Claude Fable 5. The company stated it released the model "with stronger safeguards that restrict access to a wide range of dual-use biological research queries"

1

. Anthropic also strengthened Fable 5's ability to recognize when bad-faith actors attempt to copy its capabilities through distillation attacks—a technique where a more capable "teacher" AI's work product is extracted to train a smaller "student" AI

2

.

The company has foiled seven illicit distillation attacks targeting Claude from labs based in China since making the issue public in February 2026

2

. However, it remains unclear whether these attacks overlapped with the bioweapons cases, as Anthropic chose not to name the parties responsible.

Expert Assessment Calls Findings "Chilling"

Andrew Weber, former Pentagon assistant secretary of defense for nuclear, chemical, and biological defense programs, reviewed the report before publication and called the findings "chilling examples of state-sponsored biological weapons developers tapping into the rapidly advancing capabilities" of advanced AI models

2

. Weber, now with the Council on Strategic Risks, emphasized the serious nature of these attempts.

Why This Matters for AI Governance

Anthropic describes misuse of AI to create bioweapons as one of the "most serious risks" facing AI models

1

. The company published the report hoping to "spark a conversation within the AI industry, and with governments, about emerging biological risks and how best to counter them"

2

.

Researchers have warned that stronger chatbots could lower the knowledge barrier for biological threats, though lab access, materials, tacit know-how, and safe handling still present significant hurdles

3

. Jennifer Doudna has stated that models by themselves aren't enough to create bioweapons. However, a 2025 White House order leaves oversight scattered as AI capabilities advance beyond coding and search applications

3

.

Watch for how this incident influences industry-wide standards for AI guardrails and whether governments accelerate regulatory frameworks around dual-use AI research. The tension between enabling legitimate scientific advancement and preventing the misuse of AI for biological warfare will likely intensify as models become more capable.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved