Monitoring Biological Misuse in AI

Anthropic blocked multiple accounts during a thirty-day review period after identifying attempts to use its artificial intelligence models for the development of biological weapons. The company, which produces the Claude line of models, categorized biological misuse as a top-tier risk in its recent threat intelligence report. Analysts examined thirty-five specific research efforts that triggered internal safety flags. These investigations centered on gain-of-function research involving infectious diseases such as bird flu and the development of novel toxins.

While the company confirmed these activities involved professional researchers, it could not determine whether the intent behind the queries was malicious or scientific. The actors involved employed various tactics to hide their research goals, including circumventing regional access blocks. Anthropic notes that the ability of modern AI to perform complex scientific tasks has effectively lowered the barrier for individuals to engage in work that previously required the resources of a nation-state. This shift represents a move toward the democratization of sophisticated, and potentially dangerous, scientific knowledge.

Specific Risks and Research Tactics

One case study highlighted in the report involved a user attempting to write a grant application for gain-of-function research on the chikungunya virus. The user requested assistance regarding immune evasion and transmissibility. Another instance involved a researcher outside the United States focusing on bird flu adaptation to mammals. These activities occurred alongside queries into orthopoxviruses, a category that includes the virus responsible for smallpox.

Anthropic asserts that while its models are designed for legitimate scientific breakthroughs in medicine and drug discovery, the dual-use nature of this technology presents a permanent tension. The same code that predicts protein structures to treat cancer also provides a roadmap for synthesizing hazardous pathogens. The company acknowledged that as its models reach or exceed expert performance levels, the gap between beneficial outcomes and destructive use will continue to shrink. This risk profile forces the company to monitor real-world usage patterns that frequently fall outside the current visibility of government intelligence agencies.

Geopolitical Surveillance and Weaponization

Beyond biological concerns, the report details how AI platforms were redirected to assist in conventional weapon development and state-sponsored surveillance. Users linked to groups in Yemen, believed to be Houthi rebels, attempted to use Claude to write guidance software for missile systems. Meanwhile, the report identified operators connected to the Chinese government who used AI to track and target religious minorities, including Uyghurs and various Christian communities across Asia. Some of these attempts involved complex redirection, where users on domestic Chinese platforms like Kimi or DeepSeek had their queries rerouted to Anthropic’s models without their knowledge.

These findings emerge as internal debate regarding AI safety reaches a boiling point. Former employees have started speaking publicly about the potential for advanced models to assist in critical infrastructure attacks or the creation of extinction-level biological agents. Jacob Coxon, an AI researcher who recently resigned, stated that the pace of development currently outstrips the ability of firms to maintain control over their own creations. Despite these warnings, the regulatory environment remains stagnant. With no unified federal mandate, companies currently operate as their own primary regulators, creating a patchwork of safety standards across the industry.