Anthropic said Thursday it disrupted multiple attempts this year by state-linked actors and researchers to use its artificial intelligence models for work that could contribute to biological weapons and advanced conventional weapons systems.
In a report covering roughly the past eight months, the company described cases in which scientists tied to foreign governments tried to exploit its Claude models. Anthropic said it could not always determine whether the biological research at issue was legitimate science or something more dangerous, but it banned the accounts involved in every case. The company did not name the researchers, their institutions or their countries, nor did it specify which biological agents were involved.
According to the report, some scientists evaded Anthropic’s geographic access restrictions and worked to obscure the purpose of their research to get around the company’s safety systems.
Jacob Klein, Anthropic’s head of threat intelligence, said the flagged cases were rarely clear-cut. “You are not seeing someone in a comic book kind of way say, ‘Hey, I want to build a biological weapon to kill everybody.’ It’s an incredibly nuanced situation,” Klein said.
Gain-of-Function Request Tied to Military Institute
One case from May involved a scientist who asked Claude for help drafting a grant application for research on chikungunya, a mosquito-borne virus that can cause months of severe joint pain. The request appeared aimed at engineering mutations that would make the virus more harmful through repeated infection of live animals — a method known as gain-of-function research. Anthropic said the work appeared linked to a military research institute.
“What we don’t know is if the research was meant to be weaponized. But a military institution doing gain-of-function research is concerning,” Klein said.
The report also described government-linked actors from China and Iran using Claude to help surveil dissident and diaspora communities. Separately, Anthropic said it had found evidence that Russian state media used the model to produce online propaganda disguised as independent journalism, including fabricated claims connected to an election in Moldova.
New Category: Conventional Weapons Development
Anthropic identified what it called a new category of misuse: attempts to use Claude to help design conventional weapons, including firearms, missiles, armed drones and bombs. The report documented six such cases — three in China, two in Russia and one in Yemen. Anthropic did not name the group involved in the Yemen case, though the surrounding context in the report points to the Iran-backed Houthi militia.
The Yemen-based group’s activity touched multiple missile programs, the report said, including a multi-stage ballistic missile with a stated range of more than 2,000 kilometers and a system called the “R2000,” which had a hypersonic glide vehicle variant. Anthropic said the actors used Claude Code “in place of human software engineers” to write guidance, navigation and control software, and to integrate an open-source autopilot with a phone-class flight computer. The work included control and position-estimation software, tuning control settings, running firmware builds and conducting flight simulations.
To speed up the work, the group reportedly ran multiple instances of Claude simultaneously — one to write code, one to conduct research, and a third to review the first instance’s output.
Anthropic said it found no evidence that an operational weapon was ever successfully fielded. The group did carry out a test launch of a guided rocket that appeared to fail, and returned to Claude within hours seeking help investigating what went wrong. Anthropic noted the group had already built its own offline simulation toolkit, independent of Claude or standard engineering software such as MATLAB, before turning to the AI model for assistance.
The Yemen case was one of four conventional-weapons operations detailed in the report. The others involved software tied to a drone swarm, a torpedo-interception system, and targeting software for electronic warfare and suppression of air defenses.
Anthropic said its AI models released last year were not capable enough to meaningfully assist with dangerous biological research, and that the increasing sophistication of newer models has pushed it to tighten safeguards around dual-use biological queries.
You must be logged in to post a comment Login