These weren’t anonymous bad actors typing from a dark basement. They were credentialed scientists. That’s the detail buried inside Anthropic’s new misuse report, and it reframes the entire conversation about AI safety in ways the industry hasn’t fully reckoned with yet.
As reported by Engadget, Anthropic identified and banned multiple users who were attempting to use Claude to advance biological weapon research. The company published a detailed report on Thursday covering five case studies, each walking through what was requested, how the system flagged it, and what Anthropic did next. Biological misuse is one of several threat categories in the report, which also covers surveillance tools, software exploits, propaganda, and weapons systems. But the bioweapons cases are the most alarming, and they’re getting the most attention for good reason.
One case from May stands out. Anthropic’s biological safety classifier flagged a Claude session where a user asked the model to write a grant proposal for gain-of-function research on chikungunya virus, a pathogen with no licensed treatment that can cause debilitating symptoms for months. The proposed research involved increasing the virus’s transmissibility and its ability to evade immune response. The account was affiliated with a military research institute. Anthropic shut it down. Similar flags were raised over gain-of-function bird flu research and a separate case involving venom toxin peptides and a generative pipeline designed to optimize toxin characteristics.
The challenge here is real. As Jacob Klein, Anthropic’s head of threat intelligence, told The New York Times, “You are not seeing someone in a comic book kind of way say, ‘Hey, I want to build a biological weapon to kill everybody.'” Legitimate vaccine research and bioweapon development can look nearly identical from a model’s perspective. Anthropic says it consistently chose the more cautious path when the stakes were unclear.
This matters beyond Anthropic specifically. Models like Claude 4 and competitors including OpenAI’s GPT-4o and Google’s Gemini are now genuinely useful for scientific research tasks. That’s the point. But it also means the barrier to misuse is dropping, and the people crossing that line aren’t necessarily amateurs. The fact that Anthropic is publishing this report at all is notable. Most labs stay quiet about misuse to avoid bad press. Transparency here sets a precedent, and puts pressure on OpenAI, Google, and others to be equally forthcoming about what they’re catching and how.
Anthropic declined to name the individuals or institutions involved, citing the risk of harm to people who may not have intended to cause damage. The findings are now feeding back into model safeguards. But the bigger question, one no single company can answer alone, is whether self-policing is enough when the research happening inside these sessions is this consequential.




