LIVE
All stories ›
AI IN LIFENEWS
Tools & AppsBusiness & DealsAI ModelsSocietyChips & ComputeResearchSafety & SecurityRegulation & PolicyRobotics OpenAIAnthropicGoogle & DeepMindAlibaba / QwenxAIMetaByteDance
HomeAnthropic › SECURITY
SECURITY

Anthropic Says It Blocked Bioweapons Queries to Claude

The company's first big misuse report spans more than 150 pages, from flu research to drone swarms — with Anthropic as the only source for all of it.

Anthropic Says It Blocked Bioweapons Queries to Claude
Symbolic image: behind the airlock window, gloved hands lower a rack of sample vials into a sealed containment cabinet while status lights blink on the monitoring console.

In short

Anthropic says it cut off users who tried to enlist Claude for dangerous-pathogen research and weapons work, though the only account of those cases is the company's own report.

At a glance

  • Report "Detecting and countering misuse of AI": more than 150 pages, eight months of observation, seven categories of misuse.
  • Biology: gain-of-function research requests, plus thousands of messages about flu viruses sent via VPN and an anonymous email address.
  • Weapons: missiles (northern Yemen), anti-torpedo tech (China), autonomous kamikaze drone swarms (suspected freelancers from Russia).
  • Distillation: 23 million interactions from Moonshot (Kimi) from May to July, 12 million via Deepseek within 14 days.
  • Der Standard additionally reports limits on requests coming from geographically high-risk regions.

Anthropic says it shut down accounts that tried to use Claude for work on dangerous pathogens and on weapons systems. The cases come from the company's first broad misuse report, described by German outlet heise online on September 11, 2026. Nobody outside the company has checked them: Anthropic is the sole source for what happened and how often.

One report, seven kinds of abuse

The document is titled "Detecting and countering misuse of AI" and runs to more than 150 pages, covering eight months of observation. It sorts incidents into seven areas: cyber operations, influence operations, surveillance, fraud, biological misuse, conventional weapons and model distillation. That is a far wider frame than the single-incident disclosures Anthropic has published so far.

The biology cases

One attempt used Claude to help draft a funding application for gain-of-function research on a virus. In another, thousands of messages about influenza viruses arrived through a VPN and an anonymous email address. Der Standard adds a plan to study an avian flu variant that could jump to mammals, and reports that requests from geographically high-risk regions were restricted.

The hard part is dual use. From the outside, a question about a pathogen looks much the same whether the goal is a vaccine or a weapon, which is why the report's judgment calls matter as much as its counts.

Missiles, torpedoes, drone swarms

Under conventional weapons, the report describes actors from northern Yemen working on missiles and Chinese efforts around anti-torpedo technology. It also cites what heise online renders as suspected freelance actors from Russia developing autonomous kamikaze drone swarms. Attribution in all three cases is Anthropic's own assessment, not a finding by any authority.

Rivals routing queries into Claude

The distillation section carries the most concrete figures. Anthropic counted 23 million interactions traced to Moonshot (Kimi) between May and July, and 12 million through Deepseek inside 14 days. The allegation is that competitors quietly passed user queries to Claude rather than answering them with their own models.

What is not settled

A third German-language report on the same document could not be opened for this article, so none of its details are used here. Two questions stay open: how Anthropic ties individual accounts to specific actors, and what "blocked" means in practice — a ban, a refusal filter, or a referral to authorities. Until the report is examined independently, it remains one company's account of its own enforcement.

◈ AI-GENERATED REPORT · SOURCES LINKED

FAQ

What is in Anthropic's misuse report?

The report "Detecting and countering misuse of AI" covers eight months across more than 150 pages, according to heise online, and groups cases into seven categories: cyber operations, influence operations, surveillance, fraud, biological misuse, conventional weapons and model distillation.

Did Anthropic actually stop bioweapons research?

That cannot be confirmed from outside. Anthropic describes requests tied to gain-of-function work and to influenza viruses and says it intervened, but no independent audit or official confirmation of those cases has been published.

Why do Moonshot and Deepseek appear in the report?

They show up in the model distillation chapter: Anthropic counted 23 million interactions from Moonshot (Kimi) between May and July and 12 million via Deepseek within 14 days, and accuses the providers of quietly routing queries to Claude.

Sources

More reports