The alarming version of Anthropic’s latest threat report fits neatly into a headline: scientists tried to use Claude to help make biological weapons. The 154-page document is more complicated, and in several ways more consequential, than that. Anthropic describes five biological research cases that crossed into territory capable of supporting weapons development, but it also says it cannot establish that the scientists involved intended harm. In two cases, its safety systems did what they were supposed to do and pushed the researchers onto weaker Claude models, sharply limiting the assistance available. In another, a powerful model helped draft a dual-use research proposal because the work was framed around reducing a virus’s harmful properties, a legitimate scientific goal that can sit uncomfortably close to the knowledge needed to do the opposite.The recurring failure was not simply a chatbot answering a forbidden question. It was an access system being worked around: regional blocks bypassed through US infrastructure, reseller relays serving multiple researchers, zero-data-retention channels reducing visibility, fresh identities appearing after bans, and refused prompts being diverted to another company’s model. That makes the report less a story about one dangerous answer and more a preview of how AI safety changes when the user is an expert, the science is dual use and the model ecosystem has multiple doors.About The AuthorAt heart, I am a storyteller drawn to the watershed moments that bend the technology landscape. I braid narrative with data, humanise statistics, and trace the arc from first spark to world-changing impact. My reportage, features and reviews are witty, sardonic, visual and vivid, using anecdote to illuminate rather than eviscerate.