Anthropic says scientists used Claude for research that could aid biological weapons development, while others used it for missiles, armed drones, espionage and propaganda, fueling warnings that AI risks are no longer theoreticalIn recent days, President Donald Trump was asked whether he feared artificial intelligence could lead to human extinction. “No, I don’t have any [concerns],” he replied. What does concern him, he explained, is the possibility that the United States will not win the global AI race.At almost the same time, Anthropic published a report describing what is already happening in practice: Scientists used its Claude model for research intended to aid the development of biological weapons, while actors linked to hostile countries including Iran, Yemen and Russia also used it to develop weapons and for espionage, propaganda and surveillance.GalleryAnthropic’s Claude (Photo: Anthropic)Anthropic reported five cases of such biological research that it identified in recent months. According to the company, this is the first time a private AI company has published findings on the possible use of its platform to develop biological weapons. At the same time, Anthropic stopped short of concluding that the cases involved terrorist plots. The names of the scientists, operatives, institutions and countries where they operated were not disclosed.According to the report, in some cases users circumvented geographic restrictions and concealed their objectives to evade Claude’s safety mechanisms. Although tests conducted in 2025 found that Claude models were not capable of providing significant assistance with dangerous biological research, more advanced and potentially more dangerous models have since been released. Anthropic said it added additional safeguards and blocked the accounts it identified.The most notable case disclosed began with a seemingly innocuous request: help writing a research grant proposal. Behind it was a state-funded project involving chikungunya, a virus transmitted through mosquito bites that can cause fever and severe pain lasting for months.The scientist wanted to study genetic changes that would affect the virus’s ability to infect hosts and evade the immune system, then engineer those changes in animal experiments. Such research, known as “gain-of-function” research, can advance vaccines and treatments. It can also produce a more dangerous version of a pathogen. The warning signs grew more serious when Anthropic realized the work was intended for a military research institute.In another case, a researcher from a region where Claude is unavailable connected through a U.S. server and an anonymous email address. Over several weeks and thousands of exchanges, the researcher used the model to design experiments involving avian influenza, analyze data, explore research directions and decide which experiments to conduct next.Behind a request for help writing a research proposal was a state-funded project involving a mosquito-borne virus that can cause fever and severe pain.The goal was to examine the adaptation of H5 viruses to mammals, including mutations associated with airborne transmission. According to the report, humans have almost no immunity to them and about half of confirmed human cases have resulted in death, although the viruses still do not spread efficiently from person to person.Safeguards prevented the researcher from accessing more powerful models, so Anthropic estimates that the assistance received was largely limited to data analysis and research planning. Still, the conversations indicated that the group likely had actual access to laboratory samples.The other cases disclosed were also troubling. In one, an advanced version of Claude produced, in about an hour, a complete research proposal on how a virus from the poxvirus family might evade the human immune system.In another case, a researcher working under a program supported by state actors used Claude to build a database of toxic peptides from a range of venomous animals. The stated goal was to develop painkillers and other drugs, but the database could also provide a basis for creating paralyzing agents. Anthropic did not disclose the country involved or the animals studied.The full report at times reads like a shopping catalog for a movie villain with a good internet connection. Anthropic identified six cases in which Claude was used to develop software for weapons, including guns, missiles, armed drones and bombs, as well as guidance and control systems. The cases were linked to actors in China, Russia and Yemen.What began as an innocent request turned out to be an attempt to obtain information for a biological weapon (Photo: Created using ChatGPT)“Neither company is acting responsibly,” he wrote. “They are racing straight to self-improving superintelligence and gambling with our lives.”Coxon made clear that existing models do not currently pose an extinction risk, but warned that the pace of progress could quickly change that. Evan Hubinger, who leads research at Anthropic on aligning models with human goals, publicly agreed and estimated that there is a greater than 10% chance that artificial intelligence will wipe out humanity within the next decade.At rival OpenAI, maintaining a sense of business as usual has also proved difficult. Steven Adler, who worked at the company for four years in AI safety, wrote this week that even the developers of these systems do not know what boundaries they will respect. He cited an experiment in which a swarm of 1,200 AI agents coordinated to achieve higher scores on cybersecurity tasks they were being tested on.About 700 of them broke into Hugging Face systems, a major platform for hosting and sharing models and datasets, in search of information that would help them cheat on the test. They also looked for ways to cover their tracks and none of the agents alerted their operators.Adler said AI companies should also report “near misses,” maintain records that cannot be altered and prevent models from disabling their own alarm systems. OpenAI Chief Scientist Jakub Pachocki has called for “voluntary slowdowns” to become routine because no company has yet solved the safety problems.Not everyone, of course, accepted the warnings. Elon Musk called the wave of public statements a “stunt” and a “psyop.”Coxon responded: “ I'm real and these are my real beliefs. You could ask your xAI researchers about me if you hadn't fired them.”Trump, as noted, is mainly worried about losing the race to China. And Jacob Klein, Anthropic’s head of threat intelligence, explained why identifying who is genuinely dangerous is so difficult: “You are not seeing someone in a comic book kind of way say, 'Hey, I want to build a biological weapon to kill everybody.’”In the case that raised the alarm, the request was far more polite: help writing a research grant proposal.
Claude used in dangerous biological research as AI threats move into the real world
Anthropic says scientists used Claude for research that could aid biological weapons development, while others used it for missiles, armed drones, espionage and propaganda, fueling warnings that AI risks are no longer theoretical
Anthropic documenta 5 casi Claude per gain-of-function research (H5, chikungunya) e 6 per weapons development da attori statali di Cina, Russia, Yemen. I rischi AI operativi richiedono riconsiderazione di vendor stack e governance; la corsa globale all'AI dominance senza regulatory framework accelera urgenza policy intervention.










