Politics

Bioweapon threat exposed as Anthropic sounds alarm on foreign actors plotting virus experiments

Researchers outside the United States used frontier AI models to plan experiments involving highly pathogenic bird flu, chikungunya and other biological agents with potential weapons applications, according to a new threat report from Anthropic.

The researchers used AI to study viruses’ transmissibility and immune evasion, investigate orthopoxvirus immune-response genes and help design novel toxins — at times while taking steps to evade safeguards meant to restrict access to dangerous biological capabilities.

Anthropic detailed five cases in the report published Thursday but withheld the countries, institutions and specific biological agents involved. The company stressed that it is not claiming the researchers intended to develop biological weapons.

AI KILL SWITCH BILL COULD SHUT DOWN ROGUE MODELS

The findings offer a concrete glimpse at a threat that has largely been discussed in hypothetical terms: Scientists who already possess biological expertise, materials and laboratory access are using increasingly powerful AI systems to accelerate sensitive dual-use research.

They also land amid a renewed debate over catastrophic AI risks. Jacob Coxon, a former Anthropic and OpenAI researcher, recently resigned while accusing the companies of “racing straight to self-improving superintelligence and gambling with our lives.” His warning drew more than 100 million views on X.

SEN. BERNIE SANDERS: YES, WE MUST HIT THE PAUSE BUTTON ON AI BEFORE IT IS TOO LATE

Evan Hubinger, Anthropic’s alignment science lead, separately said he personally believed there was a greater than 10% chance AI could kill all humans within the next decade.

But Anthropic’s report points to a threat that is already taking shape: researchers using frontier AI for potentially dangerous biological work, circumventing geographic restrictions and adapting when the models’ safeguards get in their way.

In one case, Anthropic blocked a grant application for chikungunya gain-of-function research at a military research institute. The proposed work focused on identifying mutations that could increase the virus’ transmissibility and ability to evade the immune system.

The researchers planned to engineer those mutations into infectious clones and repeatedly pass the virus through live animals, selecting for variants that caused the most severe disease.

That work could help scientists develop better vaccines and treatments for chikungunya. It could also produce a more dangerous pathogen that would be difficult to distinguish from a naturally occurring outbreak, Anthropic said.

The researchers accessed Claude through a life-sciences platform that tunneled traffic through U.S. infrastructure to evade Anthropic’s regional restrictions. When Claude refused to answer sensitive prompts, the platform routed those requests to another model with more permissive safeguards.

Anthropic said the research continued after the company banned accounts connected to the activity. The platform operator re-established access within days using new identities, while Claude continued to provide editorial assistance on research materials.

In another case, a researcher spent weeks using Claude to plan experiments involving mammalian adaptation and airborne transmission in highly pathogenic avian influenza.

FDA APPROVES FIRST-EVER MRNA FLU VACCINE FOR MILLIONS OF OLDER AMERICANS

The researcher was studying viral traits that could allow bird flu to spread more effectively among mammals and cause severe disease outside the respiratory system. A version capable of efficient human-to-human transmission would pose a significant pandemic threat, according to the report.

Anthropic said the researcher appeared to have access to virus isolates and animal-model facilities. The company confined the work to weaker models, limiting the assistance primarily to study design, data analysis and editorial support.

The company said the case provided evidence of an active research program developing the knowledge and biological materials needed to create pathogens with enhanced pandemic potential. The researcher also took steps to hide his identity while accessing the models from an unsupported region.

A separate user connected to a state-associated infectious-disease laboratory used Claude to draft an orthopoxvirus research grant from start to finish in about an hour.

Orthopoxviruses include variola, the virus that causes smallpox, as well as mpox. The grant application proposed studying viral genes that disable the human immune response and included the central hypothesis, experimental design, dosing, statistical plans and contingency strategies.

Because the work was framed around weakening the virus, Claude’s safeguards did not block the assistance. But Anthropic said the same knowledge could also help a researcher preserve or enhance the virus’ immune-evasion capabilities.

The final two cases involved venom peptides and toxins.

One researcher used Claude to build an atlas of toxin peptides from multiple venomous animal lineages and then created a generative pipeline to optimize their characteristics.

The stated goal was to develop new painkillers, antidepressants and other treatments. But the atlas also included structures associated with paralytic toxins that could potentially be used as incapacitating agents. Anthropic said the work was part of a state-supported research program.

In the other case, a researcher used Claude to computationally redesign several toxins, including a bacterial toxin and a protein from a hemorrhagic-fever virus identified by the World Health Organization as a priority disease threat.

The researcher used Claude to help prepare progress reports but instructed the model to keep the identities of the toxins deliberately vague.

The cases illustrate why biological misuse can be difficult to prevent through automated filters alone. Anthropic’s safeguards blocked the clearest attempts involving enhanced pandemic pathogens, but they were less effective when users framed their work as medical, defensive or therapeutic research.

“Biological capabilities are dual use,” Anthropic said in the report. “The same information that can be used to develop a biological weapon could also be used to develop, for example, a vaccine or a cure for a disease.”

The company said it recently reviewed 30 days of activity associated with adversarial state institutions and found roughly 35 distinct biological research efforts. Most involved ordinary civilian science, but some had “notable dual-use potential.”

Anthropic said the findings do not show that Claude has enabled an imminent biological attack.

They do show, the company said, that researchers tied to state-associated programs are attempting to evade access controls and use frontier AI models in biological research that could have weapons applications.

The company said future safeguards will likely require more than content filters, including identity verification, institutional vetting and closer monitoring of users seeking access to advanced biological capabilities.