Anthropic Discloses Multiple Attempts to Weaponise Claude for Missiles and Bioweapons

← Back to the feed

Anthropic Discloses Multiple Attempts to Weaponise Claude for Missiles and Bioweapons

Developed over time first seen 1 day ago

· 1 day ago

Anthropic has disclosed that it detected and blocked several attempts this year by researchers, including some based in Russia, China and Iran, to use its Claude AI models for work that could contribute to biological weapons development. The company said users tried to "circumvent controls" and disguise the true purpose of their research, prompting it to publish case studies in the hope of encouraging wider discussion among AI firms and governments about how to manage such risks as models grow more capable.

Among the five examples given was a researcher from an "unsupported region" who spent weeks using Claude to plan experiments involving avian influenza, though Anthropic's safeguards limited the interaction to its weakest models. The firm acknowledged it could not always determine whether users intended harm, since research that could aid bioweapons often overlaps with legitimate work such as vaccine development, and it declined to name the institutions or countries involved. The report also detailed unrelated abuses, including fake dating apps used for fraud and surveillance tools for monitoring dissidents, as well as claims that seven Chinese AI labs, including Moonshot and DeepSeek, attempted to replicate Anthropic's technology through "distillation".

  • Anthropic blocked several attempts to misuse Claude for bioweapons research
  • Cases involved users in Russia, China and Iran evading safeguards
  • Report also cites fraud, surveillance misuse and Chinese labs copying its models

New here? Start with this

Anthropic makes Claude, one of the leading AI chatbots and language models, competing with products such as ChatGPT and Google's Gemini. Like other AI firms, it builds in safeguards meant to stop its tools being used for serious harm, including help with building weapons. Because these models can process huge amounts of technical and scientific information, companies including Anthropic regularly publish reports on how people have tried to misuse them and what defences caught these attempts.

The company has increasingly framed itself as taking AI safety seriously, and its staff and leadership have spoken publicly about the risks advanced AI could pose. This has included warnings from employees about the technology's long-term dangers, feeding into a wider debate in the industry about whether AI systems are being developed responsibly and quickly enough, or too quickly, given their growing capabilities.

This story matters because it touches on concerns shared across the AI industry: that powerful models could, in principle, be misused to assist with weapons development or other serious harms, and that safeguards intended to prevent this are being actively tested by users around the world. It also reflects broader questions about how AI companies police access to their tools, including restrictions tied to certain countries, and about competition with other AI developers seeking to replicate their technology.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

Those who see this disclosure as alarming argue it offers concrete proof that frontier AI already attracts serious attempts at catastrophic misuse, including from state-linked actors in sanctioned countries seeking help with bioweapons and missile design. They contend that voluntary, company-led safeguards cannot be relied upon indefinitely, especially as models grow more capable and jailbreaking techniques more sophisticated, and that the resignation of a safety-focused employee warning of existential risk should be taken seriously rather than dismissed as alarmism. On this view, incidents like the avian influenza case justify binding external oversight, tighter export and access controls, and industry-wide safety standards rather than leaving containment to individual firms' discretion.

The case against

Others read the same disclosure as evidence that responsible safeguards are working as intended: five attempts were identified, restricted to weaker models, and the accounts banned, with no successful weaponisation reported. They argue that publishing this level of detail is itself a mark of genuine transparency rather than concealment, and that because biological and missile-adjacent research is inherently dual-use, overzealous restriction risks chilling legitimate scientists such as vaccine researchers. They also caution that framing every misuse attempt as near-apocalyptic can fuel disproportionate regulation that entrenches incumbents like Anthropic while doing little to stop determined bad actors, who may simply turn to less safety-conscious rivals such as the China-based labs mentioned in the report.

Coverage

AI Americas Celebrity Entertainment Geopolitics Politics Technology World

Read the full article at the source →