Anthropic Publishes Five Cases of Claude Use That Could Support Biological Weapons Work

September 11, 2026
Anthropic says an actor linked to Russian espionage used Claude to automate phishing, malware modification, infrastructure management and data theft.

Anthropic has published five case studies of people using Claude in ways that could support biological weapons development, in its September threat intelligence report. The company says that to its knowledge no private company has previously shared evidence publicly of its platform being potentially misused for biological weapons work.

The cases are specific. A reseller platform evaded regional blocks to serve virologists pursuing chikungunya gain of function work on a state sponsored grant, then routed refused prompts to models with more permissive safeguards. A researcher in an unsupported region spent weeks planning avian influenza mammalian adaptation experiments, though classifiers confined the work to Anthropic's weakest models. A reseller relay serving a dozen customers had Opus 5 draft a complete orthopoxvirus immune evasion grant application in about an hour. A state supported researcher built a venom peptide atlas and a generative optimisation pipeline aimed at paralytic and analgesic targets. And a researcher computationally redesigned toxins for a national programme, asking Claude to keep the agents' identities deliberately vague in progress reports.

The number circulating from this report deserves its context. Anthropic swept 30 days of activity associated with adversarial state institutions and found roughly 35 distinct research efforts, most of them ordinary civilian science, with some showing notable dual use potential. It is not 35 bioweapons programmes.

The through line across the cases is the intermediary. Resellers and relay services are what let users reach models from regions Anthropic does not serve, and what let a refused prompt be retried against a more permissive provider. The assistance Anthropic describes ranges from document curation to what it calls true research assistance and acceleration, and the company is candid that the evidence in several cases was ambiguous and that it acted out of an abundance of caution.

We hope you enjoyed this article.

Subscribe to Cybersecurity AI Weekly

Weekly newsletter about AI in Cybersecurity.

Whitepaper

Tensordyne Napier: What If One Rack Could Do the Work of Nine?

Tensordyne

This Tensordyne whitepaper presents Napier, an inference-focused AI processor and rack-scale system based on the company’s TDN Math logarithmic number system. It examines infrastructure requirements for large mixture-of-experts and agentic models, compares major inference architecture approaches, and details the TDN AIP processor, TDN72 pod, TDN Link fabric, and Napier Ultra configuration. The paper reports simulation-based performance, cost, and accuracy-validation results, including Tensordyne’s projected comparison of one Napier rack with a nine-rack Nvidia Rubin plus Groq deployment; the chip is reported as taped out and in fabrication.

Read more