Connect with us

AI

Anthropic Maps How States Used Claude for Dual-Use Biology

Anthropic’s September 2026 threat report details five dual-use biology cases on Claude, plus missile software and industrial distillation.

Published

on

Anthropic on September 10, 2026 released five case studies of scientists using Claude on biological work that could support weapons. The company banned the accounts and told authorities. It still will not say those scientists meant to build a weapon.

The file is larger than that scare. It is a threat-intelligence product from a company that sells a chatbot, complete with internal group codes, missile software, and industrial copying of Claude by Chinese labs.

A Private Intel Shop Inside Anthropic

The September 2026 threat intelligence report covers activity the company says it disrupted between December 2025 and August 2026, a window it calls eight months. Jacob Klein, who leads the Threat Intelligence team, and his investigators track actors under Generative Threat Group labels, the same habit a government shop uses for case files.

Prior public papers arrived in March 2025, August 2025, and November 2025. Those earlier files focused on influence-for-hire, scams, and a suspected Chinese state-sponsored campaign that used Claude Code with high autonomy against about 30 targets. This one adds biological misuse and conventional weapons as named harm areas, and it says no private company has previously published evidence of potential biological-weapons misuse of its own platform.

Claude Haiku, Sonnet, and Opus models appear in the cases. None of the misuse sat on Claude Fable or Mythos-class models, except one illicit distillation case. Anthropic says it banned the accounts, tightened safeguards, and shared intelligence with authorities and other AI companies where it judged that useful.

SEVEN HARM AREAS IN THE REPORT

  • Cyber operations: State-linked and criminal groups used Claude to run reconnaissance, phishing, malware rebuilds, and data theft, including an actor Anthropic links to Midnight Blizzard that targeted more than 20 organizations.
  • Influence operations: Networks used Claude to staff fake media, election content, and state-aligned messaging in several regions.
  • Surveillance: Government-aligned users built dossiers, tracked diaspora groups, and engineered monitoring tools.
  • Scams and fraud: Criminals used Claude to industrialize fraud stacks, including fake access resellers that stole customer credentials.
  • Biological misuse: Five case studies of working scientists on dual-use pathogen and toxin work.
  • Conventional weapons: Six cases of software for rockets, drones, and related systems, three in China, two in Russia, and one in Yemen.
  • Illicit distillation: Unauthorized labs copied Claude’s capabilities through proxy farms and stolen accounts.

That mix is the sleeper in the paper. A product-safety blog does not assign GTG numbers to a Yemen guidance cell or to Alibaba. A threat service does.

Five Scientists and No Proven Weapons Plot

The bio section is five case studies, not a courtroom brief. Anthropic is withholding names, countries, and the precise agents and techniques. The people in the file are working scientists. The company says it does not assert that they intended harm, and that naming them or their labs could put them at risk.

Actors in these examples got around regional blocks on unsupported countries and hid the point of the work. Klein’s team banned the accounts after each investigation and fed the findings into classifiers and enforcement.

THE FIVE BIOLOGICAL CASE STUDIES

Case The work Claude’s role What Anthropic did
1 Chikungunya gain-of-function grant, military institute Grant text, later editorial help on research outputs Blocked by the bio classifier in May 2026, then a full investigation and account bans
2 Mammal-adapted highly pathogenic avian influenza Weeks of planning, data analysis, and write-up, thousands of messages Classifiers kept the work on the weakest model class
3 Orthopoxvirus immune-evasion grant Opus 5 drafted the full application in about an hour The traffic sat on a reseller relay serving more than a dozen customers
4 Venom peptide atlas aimed at paralytic and analgesic targets A generative optimization pipeline State-supported program; account banned in May 2026 for region evasion
5 Computational redesign of toxins for a national program Molecule work plus deliberately vague progress reports Targets included a bacterial toxin subunit and a hemorrhagic-fever virus protein on the WHO R&D Blueprint

Case 1 is the one the wires grabbed. In May 2026 the biological safety classifier blocked a request for help writing a grant on gain-of-function research, meaning work that genetically alters an organism to add or enhance a property, on the chikungunya virus. The grant wanted mutations that change transmissibility and immune evasion, then selection in live animals so the virus would become more harmful round by round.

Chikungunya is mosquito-borne, causes severe pain and fever that can last weeks or months, and has no licensed therapeutic for the virus. Because it already circulates, Anthropic notes a deliberate release would be hard to tell from a natural outbreak. The civilian language in the paperwork was less calming than the planned site: a military research institute.

The request had been tunneled through an LLM platform that served dozens of life-sciences researchers. The countries involved are in regions Anthropic does not serve, so the platform pushed traffic through US infrastructure, used a zero-data-retention channel to hide content, and treated blocked biology prompts as a product bug. After the May 2026 takedown, the operator was back within days.

Why a Vaccine Lab and a Weapons Lab Look the Same

Anthropic has spent a year arguing why the company treats LLM biorisk seriously, including ASL-3 deployment controls first switched on with Claude Opus 4. The new report is blunter about the practical limit of those controls. Older models such as Claude Opus 4 and Claude Sonnet 4.5, from 2025, sat well below the line where they could meaningfully help a skilled user run dangerous biological research, the company says. It will not give that assurance for current models.

Beneficial work and prohibited work share techniques. The same literature review, clone design, and animal-study plan can support a vaccine or a worse pathogen. Sophisticated users know the monitors are watching, so they keep a therapeutic story in the prompt. Anthropic even flags a historical rhyme: most scientists in the Soviet Biopreparat program thought they were doing basic or defensive research because nobody told them the offensive goal.

You are not seeing someone in a comic book kind of way say, ‘Hey, I want to build a biological weapon to kill everybody.’

Jacob Klein, Head of Threat Intelligence, Anthropic

Klein also said the situation is nuanced, and that the team does not know whether the research was meant to be weaponized. A military institute running gain-of-function work is concerning, he said. Andrew Weber, a senior fellow at the Council on Strategic Risks who reviewed the report before release, went further and described the findings as chilling examples of state-sponsored biological weapons developers using leading models.

WHERE EXPERTS DISAGREE

  • Klein’s line: The scientists look like working researchers, the work is dual-use, and Anthropic cannot say it was meant to be weaponized.
  • Weber’s line: The same file is evidence of state-sponsored biological weapons developers tapping frontier models.

That split is why “plots” is a bad headline. The company erred on the side of shutting the work down because a miss would be costly. It is not claiming it caught a finished weapons program. Case 2 makes the same bind concrete: a researcher outside the US spent several weeks, and thousands of messages, planning mammal-adaptation experiments on highly pathogenic avian influenza. Anthropic says related H5 viruses kill roughly half of confirmed human cases and do not yet spread well person to person, so a mammal-adapted strain would be a pandemic-class problem. The same genetic map could also help spot a natural spillover. Classifiers kept those chats on the weakest model class.

A Yemen Cell Put Claude Code on a Rocket

If the bio cases are ambiguous science, the weapons chapter is not. Over the past year the threat team investigated actors who used Claude to write software for weapons, or to handle the intelligence and procurement those programs need. The report details six cases: three in China, two in Russia, and one in Yemen. “Disrupted” here means every linked account was banned. Where the same people worked on other platforms, Anthropic says it told those companies too.

The Guided Rocket That Failed a Field Test

GTG-87001 is a cell in northern Yemen that Anthropic says ran three programs at once: a guided rocket on a phone-class flight computer with final-phase homing; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant set, called R2000 in the file, that included a hypersonic glide vehicle. The operators used Claude Code in place of human software engineers for guidance, navigation, and control software. They assigned separate Claude instances to write, research, and review, like a tiny engineering team.

Safeguards blocked many requests and missed others. The cell hid the end product and split the work across sessions so no single chat showed the whole program. Anthropic does not have evidence they fielded an operational weapon. They did test-fire a guided rocket. The field test appears to have failed. Within hours they were back in Claude doing failure analysis.

China, Russia, and the New Weapons Classifiers

The other development cases include anti-torpedo design work, drone-swarm software tested in simulation and loaded onto real boards, and targeting software for electronic warfare and air-defense suppression. Two further cases used Claude for procurement and open-source collection, including a China-based actor gathering material on directed-energy weapons. Anthropic says it has now launched classifiers aimed at high-yield explosives and weapons-development traffic, a category that did not sit in the earlier cyber-focused papers.

The through line is labor. These actors already had hardware knowledge and access. Claude supplied software staff, simulation, and write-ups, which is a different problem from a novice asking how a bomb works.

Chinese Labs Harvested Claude at Industrial Scale

On September 8, 2026, the National Security Agency, the FBI, and the Cybersecurity and Infrastructure Security Agency issued a joint statement accusing DeepSeek, Moonshot, Alibaba, MiniMax, StepFun, and Z.AI of industrial-scale distillation of US models. Anthropic’s paper, two days later, puts company-level counts on that warning for Claude.

Since February 2026 the company says it has detected and disrupted unauthorized distillation campaigns it attributes with high confidence to seven labs based in China, aimed at Opus-class models. Distillation is a normal training method, a big teacher model generating answers that a smaller student copies. Anthropic’s charge is illicit distillation: covert, industrial copying, usually through fake accounts, stolen cards, and stolen API keys, routed via proxy “transfer stations.”

THE DISTILLATION COUNTS IN THE FILE

  • Alibaba (Qwen / Tongyi Lab): The largest campaign Anthropic has measured, more than 151 million exchanges against Opus 4.6 and 4.7 between May and July 2026.
  • DeepSeek: More than 12.1 million exchanges over 14 days in July 2026.
  • Moonshot: Silently forwarded customer requests to Claude while users thought they were talking to Kimi, then harvested the transcripts.
  • The privacy cost: Some relayed sessions carried names, emails, and company data from users in the United States and Europe, in at least a dozen languages.

A model distilled from Claude does not inherit Claude’s refusal layer. Anthropic’s own distillation research found that a student model can pick up dangerous biological or cyber skills even when the stolen chats barely mention those topics. That is the bridge between the copying chapter and the bio chapter, and it is why the bio headline is incomplete on its own.

The “they paid for tokens, so it is not an attack” objection misses the fraud layer in the file. The campaigns Anthropic is describing run on stolen credentials and synthetic identities, not on a lab’s ordinary invoice.

The Relays That Returned Within Days

The bio classifier did its job on the chikungunya grant. The business around that grant is the part that should worry people who think a filter is a policy. The platform’s developers used gray-market resellers and synthetic accounts, taught the system to send refused biology prompts to a competitor’s model, and presented that fallback to Claude as over-refusal mitigation. Claude wrote much of the routing code. After Anthropic banned the cluster in May 2026 and worked with partners to take down the relays, the operator rebuilt access within days and, within weeks, was running platform work off consumer subscriptions tied to fresh identities. End users were still reaching Claude through zero-data-retention partners. Klein’s team says it is still banning accounts in that cluster.

Case 3 is the same hole at higher speed. A reseller relay serving more than a dozen unrelated customers exchanged tens of thousands of messages with Claude in a matter of days. One customer’s run sat entirely on Opus 5. In about an hour the model drafted an orthopoxvirus immune-evasion grant from hypothesis through dosing and contingency plans.

A separate, earlier paper, Anthropic’s August 2026 risk report, described a different failure. From May 2025 until April 2026, blocking biological classifiers were off on all human-feedback vendor traffic. That pool was about 50,000 people, vetted by outside vendors, and it produced around 133 million exchanges. A later sweep flagged 1,197 transcripts as high risk for biological harm. Anthropic said a manual review found no clearly concerning chemical or biological misuse that would have given a threat actor meaningful help, and that the gap is now closed. It also said the discovery made similar unknown gaps more likely.

ANTHROPIC’S PUBLIC THREAT PAPERS

  1. April 23, 2025: Posts the March 2025 report on influence-as-a-service, credential scraping, recruitment fraud, and novice malware, and bans the accounts.
  2. August 2025: Issues a follow-up threat paper as misuse shifts from one-off chats toward orchestrated campaigns.
  3. November 2025: Discloses a suspected Chinese state-sponsored campaign, GTG-1002, that used Claude Code across roughly 30 targets with high autonomy.
  4. September 10, 2026: Publishes the seven-area file, including the first public bio-misuse case studies from a private company, plus weapons software and the distillation counts.

The company already runs voluntary testing with the US Center for AI Standards and Innovation and the UK AI Security Institute. Those partnerships do not solve the dual-use judgement, and they do not keep a reseller from standing the pipe back up. The chikungunya grant still moved from a blocked prompt to live research outputs. The Yemen cell still got a rocket to a field test. The scientists in the file still have no names, and Anthropic still will not call their work a weapons plot.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending