Anthropic said it stopped multiple attempts by scientists this year to use Claude for research that could support the development of biological weapons, publishing five case studies in which users circumvented its safety controls. The disclosures, released September 11, 2026, name users from regions Anthropic prohibits from accessing its models, including Russia, China, and Iran. In each case, Anthropic said it banned the accounts and restricted the sensitive work to its weakest models.
The company framed the report as an early warning to the rest of the industry. One case involved a researcher from an unsupported region who spent weeks planning avian influenza experiments with Claude, working around Anthropic's regional access rules before the system's filters kicked in. Anthropic said it could not confirm whether the scientists intended harm, noting that the same information required to design a biological weapon can also be used to design a vaccine.
Anthropic said in the report that it wants the disclosures to prompt a broader response.
“We hope that by sharing these examples, we spark a conversation within the AI industry and with governments about emerging biological risks and how best to counter them.”— Anthropic, Company statement
Key facts
- 01Anthropic disclosed five cases this year in which users circumvented controls on Claude to pursue biological research the company deemed dangerous.
- 02Flagged users were based in regions Anthropic prohibits from accessing its models, including Russia, China, and Iran.
- 03One researcher from an unsupported region spent weeks planning avian influenza experiments with Claude before safety filters restricted the work to weaker models.
- 04Anthropic also named seven China-based labs, including Moonshot and DeepSeek, that attempted to replicate Claude through distillation.
- 05The disclosure lands days after researcher Jacob Coxon resigned from Anthropic warning that AI 'could kill us all by the end of the decade.'
The company withheld the names of the institutions and countries involved, citing operational sensitivity. It framed the five examples as a representative slice rather than a complete accounting, arguing that AI-assisted biology now warrants the same scrutiny as AI-assisted cybersecurity.
The report lands during a tense stretch for the AI safety debate. Earlier this week, Anthropic researcher Jacob Coxon resigned, warning publicly that employees inside frontier labs are increasingly convinced the technology poses an existential threat. His departure has amplified an argument that has been building all year, following the release of advanced models including Anthropic's Mythos and an OpenAI disclosure in July that its models had autonomously hacked into AI group Hugging Face.
Coxon's warning has become a rallying point for safety advocates.
“earnestly believe it [AI] could kill us all by the end of the decade.”— Jacob Coxon, Former Anthropic researcher
Beyond biology, Anthropic's report catalogued other misuse patterns, including a network of fake dating apps designed to defraud users and surveillance systems built to identify and monitor dissidents. The company said the range of abuse cases has widened as its models have become more capable, and that its detection tooling has had to keep pace with users who deliberately obfuscate the purpose of their requests.
The report also expanded Anthropic's earlier claims that Chinese labs are attempting to copy its models. It named seven China-based labs, including Moonshot and DeepSeek, that tried to replicate Claude through distillation, a process in which one model is trained to imitate the outputs of another. Anthropic said it had detected 'increasingly sophisticated methods to circumvent our defenses and harvest the capabilities of US frontier models.'
The practical bar for turning AI-assisted research into an actual weapon remains high. Designing a pathogen on paper is not the same as producing one, and physical synthesis still requires laboratory access, reagents, containment, and expertise that a chatbot cannot supply. That gap is the strongest current argument against panic, and Anthropic acknowledged it, but the company's position is that the trajectory of model capability is closing the design half of the problem faster than policy is closing the synthesis half.
Anthropic's decision to publish this level of detail is a strategic move as much as a safety one. The company has spent the past year positioning itself as the frontier lab most willing to disclose misuse, and the timing — days after Coxon's resignation and weeks into a broader industry argument about whether labs should slow down — puts pressure on competitors to publish comparable reports. If OpenAI, Google, and Meta stay quiet while Anthropic keeps releasing case studies, the regulatory conversation in Washington and Brussels will be shaped almost entirely by Anthropic's framing, which is exactly the outcome Anthropic wants.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




