Anthropic Discloses Multiple Attempts to Weaponise Claude for Missiles and Bioweapons
Developing story first seen 2 hours ago
Anthropic has disclosed further detail on its efforts to stop its Claude AI model being misused for weapons research, revealing five specific cases this year in which users tried to "circumvent controls" or "obfuscate" the purpose of biological research to bypass safeguards. Some of these attempts came from users in countries barred from accessing its models, including Russia, China and Iran, and the company has since banned the accounts involved. The disclosure comes amid growing unease about AI safety, following the resignation this week of Anthropic employee Jacob Coxon, who said staff "earnestly believe" AI could kill everyone by the end of the decade.
Among the examples cited was a researcher from an "unsupported region" who spent weeks planning avian influenza experiments with Claude, though Anthropic said its filters restricted the work to its weakest models and stressed it could not be certain of malicious intent, given the overlap between weapons research and legitimate science such as vaccine development. The wider report also detailed other misuse, including fake dating apps used for fraud and surveillance tools built to monitor dissidents, plus claims that seven China-based labs, including Moonshot and DeepSeek, attempted to replicate Anthropic's technology through "distillation" using increasingly sophisticated methods to bypass its defences.
- Anthropic reveals five cases of attempted bioweapons misuse of Claude
- Banned accounts included users from Russia, China and Iran
- Comes amid resignation of staffer warning AI could be catastrophic
New here? Start with this
Anthropic makes Claude, one of the leading AI chatbots and language models, competing with products such as ChatGPT and Google's Gemini. Like other AI firms, it builds in safeguards meant to stop its tools being used for serious harm, including help with building weapons. Because these models can process huge amounts of technical and scientific information, companies including Anthropic regularly publish reports on how people have tried to misuse them and what defences caught these attempts.
The company has increasingly framed itself as taking AI safety seriously, and its staff and leadership have spoken publicly about the risks advanced AI could pose. This has included warnings from employees about the technology's long-term dangers, feeding into a wider debate in the industry about whether AI systems are being developed responsibly and quickly enough, or too quickly, given their growing capabilities.
This story matters because it touches on concerns shared across the AI industry: that powerful models could, in principle, be misused to assist with weapons development or other serious harms, and that safeguards intended to prevent this are being actively tested by users around the world. It also reflects broader questions about how AI companies police access to their tools, including restrictions tied to certain countries, and about competition with other AI developers seeking to replicate their technology.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Those who see this disclosure as alarming argue it offers concrete proof that frontier AI already attracts serious attempts at catastrophic misuse, including from state-linked actors in sanctioned countries seeking help with bioweapons and missile design. They contend that voluntary, company-led safeguards cannot be relied upon indefinitely, especially as models grow more capable and jailbreaking techniques more sophisticated, and that the resignation of a safety-focused employee warning of existential risk should be taken seriously rather than dismissed as alarmism. On this view, incidents like the avian influenza case justify binding external oversight, tighter export and access controls, and industry-wide safety standards rather than leaving containment to individual firms' discretion.
The case against
Others read the same disclosure as evidence that responsible safeguards are working as intended: five attempts were identified, restricted to weaker models, and the accounts banned, with no successful weaponisation reported. They argue that publishing this level of detail is itself a mark of genuine transparency rather than concealment, and that because biological and missile-adjacent research is inherently dual-use, overzealous restriction risks chilling legitimate scientists such as vaccine researchers. They also caution that framing every misuse attempt as near-apocalyptic can fuel disproportionate regulation that entrenches incumbents like Anthropic while doing little to stop determined bad actors, who may simply turn to less safety-conscious rivals such as the China-based labs mentioned in the report.
Full account
Anthropic has published a report detailing several documented attempts to misuse its Claude artificial intelligence models for weapons development this year, spanning both missile engineering and biological research with potential military applications. The disclosures, covered separately by different outlets with differing emphasis, describe a pattern in which threat actors tried to exploit Claude's coding and research capabilities while deliberately concealing their true intentions from the system's safety filters.
One strand of the report concerns a cell of operatives based in northern Yemen who, according to Anthropic, ran three parallel weapons projects using Claude Code: a multi-stage ballistic missile, a variant missile design, and a guided rocket built around an inexpensive, phone-grade flight computer. The group is reported to have used the tool to write navigation and stabilisation software, adapt an open-source autopilot system to their hardware, calibrate control settings, manage a firmware build process and run flight simulations. Anthropic said it saw no evidence of a functioning weapon being fielded, though the actors did test-launch a guided rocket; the attempt reportedly failed, and the operatives returned to Claude within hours seeking to diagnose the fault. The company described the actors as directing multiple Claude sessions in parallel, effectively running them like separate members of an engineering team handling coding, research and review, and said the group evaded some safeguards by concealing the ultimate purpose of their requests and spreading the work across sessions. The accounts involved have since been suspended, and Anthropic says it alerted government and industry partners.
A separate part of the report addresses attempts to use Claude to assist biological research that could feed into weapons development. Anthropic set out five case studies in which users were found to have sidestepped built-in controls or disguised the aims of their work, some originating from countries — including Russia, China and Iran — where the company restricts access to its models. In one example, a researcher based in a region without official support for Anthropic's services reportedly spent an extended period planning work involving avian influenza, though the company's protections limited that person to its least capable models. Anthropic was careful to note the inherent ambiguity in such cases, observing that research capable of informing a biological weapon could equally support legitimate vaccine work, and it declined to identify the institutions, individuals or countries involved, beyond confirming that the relevant accounts had been closed.
The wider report also touched on other forms of misuse, including a fraud operation built around fake dating applications and tools apparently designed to help surveil political dissidents, as well as claims that a number of Chinese AI developers had attempted to replicate Anthropic's technology through a distillation process. Coverage of the report varies in focus: reporting that drew on the missile-related findings placed them in the context of renewed Houthi military activity along Yemen's Red Sea coastline, inferring — though Anthropic itself did not name the group — that the Iran-aligned, US-designated Houthi movement was the likely actor behind the rocket and missile programmes. Other coverage centred more on the biological-research findings and situated them within a broader, ongoing debate among AI developers and biosecurity specialists about how the industry should regulate increasingly capable models, referencing separate recent developments such as a departing employee's public warnings about long-term AI risk and an unrelated incident in which another AI company's systems were said to have breached a code-hosting platform autonomously.
Where outlets differ
One account frames the story primarily around the Yemen-based missile and rocket programme, linking it explicitly (via its own inference rather than Anthropic's wording) to the Houthi movement and to recent Houthi military gains in the Red Sea region; it includes far more technical detail about the flight-control and guidance software involved, and does not mention the biological research findings at all.
The other account focuses almost entirely on the bioweapons-related case studies, emphasising the difficulty of distinguishing legitimate biological research from weapons-relevant work, and situates the report within a broader narrative about AI industry safety debates, including a staff resignation over existential-risk concerns and a separate, unrelated AI security incident at another company — none of which is mentioned in the missile-focused account.
The two accounts differ on attribution and specificity: the missile-focused report names a likely perpetrator (the Houthis) despite acknowledging Anthropic did not do so, whereas the bioweapons-focused report stresses that Anthropic deliberately withheld the names of institutions, individuals and countries involved in the biological case studies.
Only the bioweapons-focused account mentions the additional findings on fake dating-app fraud networks, dissident surveillance tools and Chinese labs allegedly distilling Anthropic's models — details absent from the missile-focused coverage.
Coverage
- Daily Mail — Terrorists who launch attacks on US ships in Red Sea used Anthropic to try to build ballistic missiles
- Ars Technica — Claude users found ways around safeguards for bioweapons research
AI Americas Celebrity Entertainment Geopolitics Politics Technology World