And what if an AI renowned for its safeguards quietly served as the right-hand to research on viruses capable of killing? That chilling question is raised by Anthropic’s latest report, the company behind the Claude model. For several months, five researchers reportedly used this AI for work involving dangerous pathogens, while the company struggled to decide between legitimate scientific curiosity and a real threat. An affair that challenges the notion that the safeguards of cutting-edge AIs are truly impermeable.
- Anthropic identified five cases, between December 2025 and last August, where researchers allegedly used Claude for work related to dangerous pathogens (Chikungunya, avian influenza, orthopoxviruses, venoms and toxins), without being able to determine with certainty whether it was legitimate research or malicious attempts.
- A resale platform was discovered redirecting biological queries refused by Claude to other AIs with weaker protections, revealing that a single vulnerable link in the ecosystem can render safeguards bypassable.
- Anthropic banned the accounts involved and alerted authorities and other AI companies, while acknowledging that the increasing capabilities of newer models heighten this dual-use risk between medicine and bioterrorism.
- The dual-use trap: when healing and killing share the same playbook
- Chikungunya, avian influenza, orthopoxviruses: a deep dive into the five files that alarmed Anthropic
- Outsmarting AI: the flaw no one anticipated
- What this case truly reveals about the future of AI and bioterrorism
The dual-use trap: when healing and killing use the same playbook
The heart of the problem rests on a reality biosafety experts know well: biology is a dual-use science. The methods that enable developing a vaccine against an emerging virus are, for the most part, the same as those that could be used to make it more dangerous. A request for help to understand a pathogen’s structure, analyze sequencing data, or plan an experimental study can originate just as well from a public health researcher as from a malicious actor masquerading as a scientist.
It is precisely this ambiguity that has complicated Anthropic’s task. The company itself acknowledges that it cannot determine with certainty whether the five identified cases represented traditional academic research or attempts to circumvent safeguards for purposes of biological arms. Faced with this uncertainty, the decision was to err on the side of caution, starting from the assumption that a missed incident could have far graver consequences than an excess of caution.
Chikungunya, avian influenza, orthopoxviruses: a deep dive into the five cases that alarmed Anthropic
These cases span from December 2025 through last August. The first concerns the Chikungunya virus: a grant application for so-called “gain-of-function” research intended for a military-oriented institute was blocked by Anthropic. Notably, the researchers did not abandon their project; they simply switched channels, which greatly worried the company about its real ability to prevent such use.
The second case touches on highly pathogenic avian influenza. A researcher used Claude for several weeks to plan a study and analyze data, but only via less capable versions of the model, which limited the scope of the assistance obtained. Three other cases involve orthopoxviruses, venom-related compounds, and toxins. Anthropic did not disclose the identities, locations, or precise biological details of these files.
Outsmarting AI: The flaw no one anticipated
What makes this affair particularly troubling is not only the nature of the research at issue but the way safeguards could be bypassed. Anthropic indeed identified a resale platform that redirected initially refused biological queries to other AI models with far weaker protections. In other words, even when Claude refused to respond, there existed a backdoor to obtain elsewhere what had been blocked here.
Anthropic responded by banning the implicated accounts and sharing its findings with the competent authorities as well as with other AI-focused companies. Yet the episode illustrates a structural limitation: a safeguard, even a robust one, is only as strong as the rest of the AI ecosystem’s vigilance. A single weaker link is enough to make the entire system bypassable.
What this case truly reveals about the future of AI and bioterrorism
This case highlights a risk still relatively under-discussed compared with other AI-related threats, such as large-scale cyberattacks or the misalignment of autonomous agents. Until now, cases where AI facilitated the development of dangerous pathogens were documented in real-world research contexts, without confirmed progression to production or use as a biological weapon. This affair marks a turning point: it shows that the boundary between laboratory work and a real threat is becoming increasingly porous as models gain power.
Anthropic itself notes that older versions of Claude would probably not have allowed going as far in this type of research. It is precisely the expanded capabilities of recent models that are worrying: the more capable an AI becomes in biology, the more useful it is for medicine and, potentially, for misuse. A paradox that places AI companies in an unprecedented responsibility, to arbitrate—often in the gray area—between encouraging scientific innovation and preventing catastrophic scenarios.
This case serves as a reminder, at a time when artificial intelligence is increasingly taking root in our daily lives, that the race between technological progress and collective security is far from over. Safeguards exist, but they increasingly resemble seawalls facing a rising tide. It remains to be seen whether the AI industry will mend the breaches before a single incident escalates into a far more dramatic scenario.