Anthropic caught scientists trying to use Claude to develop bioweapons
The AI company blocked at least five attempts this year by researchers to extract information that could help build biological weapons, including users from countries it bans outright.

Key points
- Anthropic blocked at least five separate attempts in 2025 by actors seeking to use its AI models for biological weapons research.
- Some attempts came from users in countries Anthropic prohibits from accessing its technology, including Russia and Iran.
- Anthropic published the cases publicly, calling on the AI industry and governments to address biological risks together.
- In each case, users either found ways around safety controls or tried to hide the true purpose of their requests.
The company behind Claude, the AI chatbot and large language model (software trained on vast amounts of text that can answer questions, write code and carry out research tasks), says it blocked multiple attempts this year by people trying to use its technology to help develop biological weapons.
Anthropologic published five specific cases in a report on malicious use of its models. In each one, the actors either circumvented controls, meaning they found workarounds to bypass built-in safety rules, or tried to disguise what their research was actually about. Some of those users were in countries Anthropic already bans from accessing Claude entirely: Russia, China, and Iran.
What did these researchers actually ask?
Anthropologic has not published transcripts, so the precise requests are not known. What the company confirmed is that the attempts were serious enough to document and share publicly, and that users deliberately tried to hide their intent from the system's safeguards.
This matters because Claude, like rival chatbots from OpenAI and Google, is designed to refuse requests that could help create weapons or cause mass harm. Getting around those refusals takes deliberate effort. These weren't accidental queries.
Should ordinary people be worried?
The immediate risk sits far from most people's daily lives. You can't accidentally stumble into bioweapons research on a chatbot. What the Anthropic report really flags is a structural problem: AI systems powerful enough to assist with legitimate science are also powerful enough to assist with dangerous science, and the line between the two isn't always easy for software to spot.
Anthropologic said it published the cases specifically to start a conversation with governments and the broader AI industry. The message is that voluntary safety controls at one company aren't enough. It's asking for coordinated rules.
We covered the broader landscape of Anthropic's threat reporting on 10 September 2026, when the company released a 154-page account of who is trying to misuse its AI, naming everyone from missile designers to propagandists. These five bioweapons cases sit inside that larger picture.
First reported by Ars Technica AI, this comes as AI companies face growing pressure from regulators in the US and Europe to demonstrate that their systems cannot be turned into tools for mass harm.
What happens next?
Anthropologic's report is a call for outside help, not a declaration that the problem is solved. The company is inviting policy makers to build frameworks that go beyond what any single AI lab can enforce alone.
The honest read: the people trying to misuse these systems are creative and motivated. One company's safety team is not a permanent ceiling on what determined bad actors will attempt. Governments that want to influence this need to move before something goes wrong, not after.



