Anthropic just dropped a detailed look under the hood of how people are trying to push its Claude AI into some seriously sensitive scientific territory.
In its September 2026 threat intelligence report, released around September 10, the company laid out five separate cases where working scientists turned to Claude for help with research that could also support biological weapons development. The activity stretched from late 2025 into mid-2026. Anthropic is clear it didn’t catch anyone openly declaring evil intentions. The queries looked a lot like standard scientific work — grant applications, study planning, data analysis. Still, the dual-use risk was high enough that the company stepped in, banned the accounts, and tightened its filters.
The report calls biological misuse “one of the most serious risks of frontier AI models.” The same information that can help create a vaccine or better treatment can, in the wrong hands or the wrong context, make a pathogen more dangerous. Anthropic says it chose caution.
Here’s what the company found:
One case involved a researcher asking Claude to help write a full grant application for gain-of-function work on the chikungunya virus — the kind of research that deliberately enhances a pathogen’s transmissibility or immune-evasion abilities. The planned work was linked to a military research institute, which raised extra red flags. The request came through a reseller platform designed to dodge regional blocks. When Claude refused, the system sometimes bounced the prompt to other, less restricted models. Anthropic shut it down.
In another, a researcher outside the U.S. spent weeks using Claude to plan experiments on highly pathogenic avian influenza (bird flu), focusing on how the virus adapts to mammals. Safeguards kept the conversations limited to weaker versions of the model. The account was still banned.
A third case saw Claude draft an entire grant application in about an hour for orthopoxvirus research (the family that includes smallpox and mpox) focused on immune-evasion mechanisms. It came through a reseller serving multiple customers.
The last two involved work on venom peptides and toxins. Researchers used Claude to map toxin structures and generate optimized versions, framing the goals as therapeutic — new painkillers and the like. But the compounds sit in that classic dual-use zone where the same molecules can be helpful or harmful. Both accounts were banned for accessing the models from restricted regions and, in one instance, deliberately keeping toxin identities vague in progress reports.
Across all five cases, Anthropic banned the accounts, shared findings with authorities and other AI companies, and used the incidents to strengthen safeguards on newer models. The company is careful not to name people, labs, or countries, noting that the individuals appear to be working scientists and that identifying them could create its own problems.
This biological section is only one part of a much larger report that also covers cyber operations, surveillance, influence campaigns, and conventional weapons software. But the bio cases stand out because they sit right at the messy intersection of legitimate science and catastrophic risk.
Anthropic’s message is straightforward: today’s frontier models are capable enough that the old assumption — that they couldn’t meaningfully help with dangerous biological work — no longer holds. The company is adjusting its defenses accordingly and wants the rest of the industry and governments paying attention.
The report doesn’t claim Claude helped anyone actually build a bioweapon. It does show that sophisticated dual-use research is already finding its way to these systems, often by people who know how to route around the guardrails. For an industry racing ahead on capability, that’s a clear signal that safety work has to keep pace.


