What we know so far: Anthropic, the San Francisco-based AI company led by Dario Amodei, claims to have identified possible attempts by suspected state-sponsored researchers to exploit its Claude AI model to develop biological weapons. The company added that the users were blocked after repeated attempts triggered Claude's built-in safety protocols.
Anthropic recently detailed at least five cases where suspected rogue actors "circumvented controls" specifically designed to prevent users in certain parts of the world from accessing Claude's extensive knowledge base regarding infectious diseases, such as bird flu, and lethal venoms and toxins, like botulinum toxin.
However, the total number of attempts is much larger, with the company claiming to have identified about 35 distinct efforts between November 2025 and September 2026 by possible state-funded bioweapons developers to "obfuscate the purpose of their research to evade our safeguards."
One of the suspected cases involved gain-of-function research into the transmission and immune evasion of the chikungunya virus. Another account was flagged for researching how the bird flu virus can be adapted to cause severe illness in mammals. Researchers were also banned for queries about orthopoxviruses – a genus of DNA viruses that includes variola, which causes smallpox, and mpox.
Anthropic acknowledged that it is difficult to determine whether research on toxins, poisons, and related substances is intended to aid the manufacture of bioweapons or to develop antidotes, vaccines, and other medical or therapeutic solutions. However, what caused the system to flag the aforementioned attempts was the use of various anonymizing techniques to evade Anthropic's regional blocking.
In the aftermath of the bioweapons scare, Anthropic says it has upgraded its safety protocols to prevent threat actors from exploiting its AI models for nefarious purposes. "Out of an abundance of caution, we have launched recent models (most notably Claude Fable 5) with stronger safeguards that restrict access to a wide range of dual-use biological research queries," the company stated.
Anthropic did not identify the regions from which these queries are believed to have originated, but the company is widely known to block users in China, Russia, Iran, North Korea, and several other countries from accessing Claude. However, it says it blocked all suspect accounts by May 2026 for violating its Supported Regions Policy.
According to Anthropic, misusing AI to create bioweapons is one of the "most serious risks" facing AI models. The company added that it incorporated the guardrails precisely to avoid situations like these, in which rogue nation-states could exploit AI to prepare deadly bioweapons and use them to wage biological warfare against their own people or Western democracies.
