In May 2026, someone opened a conversation with Claude and asked the chatbot to help write a grant application. The proposal was for gain-of-function research on chikungunya — a mosquito-borne virus that causes searing joint pain and fever and has no licensed cure — and the stated aim was to engineer the pathogen to spread more easily and slip past the human immune system. The work, the request indicated, would be carried out at a military research institute, in a part of the world where Anthropic normally blocks access to Claude entirely.
Anthropic’s systems flagged the request and refused it. Then the company did something no AI firm had done before: it told the public.
In what it calls its most detailed threat report to date, published on 10 September, Anthropic disclosed five separate cases in which people tried to steer Claude toward biological research that could feed a weapons programme. It is, the company says, the first time any AI developer has publicly acknowledged catching its own models being pointed at a potential bioweapon.
More unsettling than any single case was a single admission about the technology itself. Anthropic’s 2025 models, the report says, sat well below the level where they could meaningfully help a skilled actor with dangerous biological work. Its newest, more capable models are a different story. For those, the report concedes, “we cannot make that same assurance.”
5
bio-research cases that could aid weapons work
1st
public disclosure of AI steered toward a bioweapon
7
harm areas, from cyber to conventional weapons
0
countries named in the biology section of the report
Anatomy of the request Anthropic blocked
What was asked
Help drafting a scientific grant application for gain-of-function work — engineering a virus to become more transmissible and better at evading immunity.
The pathogen
Chikungunya, a mosquito-borne virus with debilitating symptoms and no licensed treatment.
Where
Intended for a military research institute, in a region where Claude is normally blocked from use.
Outcome
✕ Flagged and refused. One of five bio cases disrupted between December 2025 and August 2026.
The hardest part, Anthropic’s threat-intelligence chief Jacob Klein told The New York Times, is that malicious intent rarely announces itself.
“
You are not seeing someone in a comic-book kind of way say, ‘I want to build a biological weapon.’
— Jacob Klein, head of threat intelligence, Anthropic
That is the dual-use trap at the centre of the report. The same techniques that push a vaccine breakthrough can also make a pathogen deadlier, and the company says it often could not tell which was which. It blocked the chikungunya request anyway — not because it had proof of ill intent, but because the downside was too catastrophic to gamble on. It banned the accounts and shared its findings with authorities and other AI companies.
Beyond biology. A machine for lowering the bar
The bioweapon cases are the report’s most severe, but they sit inside a far broader catalogue of misuse — spanning cyberattacks, propaganda, surveillance and, most concretely, the building of physical weapons.
The missile cell that ran Claude like an engineering team
Among the report’s most striking findings is a cell of operatives based in northern Yemen pursuing three weapons programmes at once: a guided rocket built around a cheap, phone-grade flight computer; a multi-stage ballistic missile with a stated range goal beyond 2,000 kilometres; and a set of missile variants — labelled “R2000” — that included a hypersonic glide vehicle.
Rather than hire software engineers, the group used Claude Code to write the guidance, navigation and control software that keeps a flying weapon on course. In one instance it had the AI graft an open-source autopilot onto the phone-class computer, write the control and position-estimation code, tune the settings, run the build pipeline and simulate a flight. And it did not rely on a single chatbot: the operators ran several Claude instances in parallel and handed each a job — delegating exactly as a team lead would.
One cell, several Claudes, delegated like staff
The operators assigned each AI instance a role and let them work in parallel.
Anthropic says its safeguards refused many of the requests, but not all. The operators hid what they were building and spread their work across sessions so that no single conversation gave away the goal. The company found no evidence the weapons were ever fielded — but the cell did test-fire a guided rocket. The launch appears to have failed. Within hours, the operators were back with Claude, asking it to help work out why.
Sophisticated attacks, unsophisticated attackers
The blunt topline on the cyber side: AI has erased the gap that used to separate elite, state-backed hacking teams from lone opportunists. For investigators, the report says, the sophistication of an attack has stopped being a reliable clue to who is behind it.
Break-ins that once demanded a skilled crew and weeks of effort now take one person a few hours, with the AI scanning for weak points, writing the intrusion code and sorting the stolen data on its own. In one operation linked to Russian espionage, AI even acted as a watchman over the attackers’ own malware — quietly rewriting it whenever antivirus software caught on, until it went invisible again.
One operator, many victims
Organisations hit in single AI-assisted campaigns run by tiny teams — or one person.
In parallel, Anthropic disrupted nine influence operations — fake-news networks and armies of bot accounts run from Russia, Iran, Turkey and beyond, several of them timed to national elections — that used Claude as an automated newsroom, churning out and laundering propaganda so state narratives could pass as independent local reporting.
The timing. A warning from inside the safety lab
The report did not arrive in a vacuum. It landed two days after one of Anthropic’s own researchers walked out — and it comes as the company moves toward a stock-market debut expected this autumn.
On 8 September, Jacob Coxon, a 27-year-old who says he spent three years training AI models at both OpenAI and Anthropic, resigned and left the industry. In a thread on X viewed tens of millions of times, he accused both companies of “gambling with our lives” by racing toward AI that can improve itself, and called for a coordinated slowdown across the labs.
What turned a resignation into a reckoning was the reply from inside the company’s own safety team. Evan Hubinger, an alignment research lead at Anthropic, publicly agreed with him.
“
We really do earnestly believe AI could kill all humans.
— Evan Hubinger, alignment research lead, Anthropic, replying to Coxon on X
>10%
Hubinger’s personal estimate of the chance AI causes human extinction within the decade. He added that Anthropic has no plan yet to keep a future superintelligence aligned — and is not clearly on track to find one.
Hubinger was careful to separate today from tomorrow. He considers current models low-risk; his fear is future systems that grow far more capable by repeatedly improving themselves. But that distinction is exactly what makes this report land harder. The misuse it documents is still human-directed — yet it already shows AI acting with unsettling independence: malware that rewrites itself, agent “swarms” that run break-ins for days unsupervised, collection fleets that harvest data on a schedule with no human in the loop.
A worry Anthropic has never hidden
The company’s own words, tracked over time, point one direction.
Anthropic does not dispute the uncertainty. Its own risk assessment judged the danger from current models to be low — but leaned partly on those models simply not being capable enough to slip their oversight, and admitted the judgement’s weaknesses. It is precisely that reasoning that would offer thinner comfort for a more capable successor.
For now, a human at Anthropic saw the request to make a virus deadlier, understood what it meant, and said no. The warning buried in the company’s own report is that this may be the easy part.
