AI Doesn’t Need To Turn Evil To Kill Us: Anthropic Warns of a Growing Bioweapon Risk

The company identified five cases involving research with potential applications for biological weapons, while stressing that it found no proof the scientists intended harm

AI-assisted biological research raises new biosecurity concerns.
Anthropic warns that increasingly capable AI models could make sensitive biological research easier to carry out ChatGPT Plus

Artificial intelligence does not need to become rogue or self-aware to pose a serious biological threat. Anthropic warns that the danger could come from something far simpler: people using increasingly capable AI systems to carry out sensitive scientific research more effectively.

In a 10 September 2026 report, Anthropic detailed five cases where Claude was used for research that could support biological weapons development. Some involved people accessing Claude from regions where Anthropic does not directly provide its services. Others involved efforts to obscure the nature of the work.

There is no suggestion that Claude independently decided to create a weapon. The concern is that advanced AI models are becoming capable enough to assist with scientific work that can have both beneficial and dangerous applications.

Anthropic Found Five Cases That Could Support Bioweapon Development

Anthropic's Threat Intelligence team examined activity it identified and disrupted between December 2025 and August 2026. The cases covered cyber operations, surveillance, conventional weapons development and biological misuse.

Five biological cases stood out. They involved research into chikungunya virus, highly pathogenic avian influenza, orthopoxviruses, venom peptides and toxins.

In one case, Anthropic's biological safety classifier blocked a grant-writing request involving gain-of-function research on chikungunya. The proposed work focused on transmissibility and immune evasion.

Anthropic later found that the platform had a fallback mechanism. When Claude refused sensitive requests, it redirected them to a competitor's model.

Another researcher used Claude for weeks while planning work involving highly pathogenic avian influenza and mammalian adaptation. Anthropic said its biological safety classifiers limited those exchanges to weaker models, specifically Claude Sonnet 4 and Haiku 4.5.

Anthropic said Claude's assistance in that case was mainly clerical. It helped with data analysis, study planning and writing. The company said the resulting uplift was limited compared with what its more capable models could provide.

A third case involved an orthopoxvirus grant application produced using Claude Opus 5. Anthropic said the application was drafted end to end in about an hour through a reseller relay serving more than a dozen customers.

The remaining two cases concerned research into venom peptides and computationally redesigned toxins.

Those projects were not necessarily malicious. Anthropic said they could have legitimate scientific or therapeutic applications, but also had dual-use characteristics that made them potentially dangerous.

The company banned accounts linked to the activity and said lessons from the cases were being incorporated into its safeguards, enforcement and threat-intelligence systems.

Scientists Were Not Proven To Be Building Bioweapons

One point is crucial. Anthropic did not conclude that the scientists were trying to build biological weapons or intended to harm anyone.

The company withheld identifying details, including the institutions and countries involved. It also omitted some information about the biological agents and research techniques. Anthropic said those involved were working scientists and stressed that it was not claiming they intended harm.

The problem is what scientists call 'dual use'. Research into how viruses spread, evade immune responses or respond to treatments can contribute to vaccines, medicines and better disease prevention. But some of the same knowledge could potentially be used to make pathogens more dangerous.

That makes intent difficult for automated safety systems to judge. Highly technical research can be legitimate while still producing information that could be misused.

Why Anthropic Says the Risk Is Growing

Anthropic says tests of earlier Claude models, including Claude Opus 4 and Claude Sonnet 4.5, found they were not capable enough to meaningfully assist sophisticated users with dangerous biological research.

It says the same assurance can no longer be made about today's more capable AI systems. As a result, the company has strengthened safeguards around advanced biology capabilities.

High-risk or dual-use requests can be blocked or redirected to less capable models. Some frontier biology capabilities are also restricted to trusted-access programmes for vetted researchers and organisations.

Anthropic has separately reported that advanced AI models are nearing or exceeding human experts on some biological evaluations. Its September threat report makes a similar point, saying models are approaching or surpassing expert performance on increasingly challenging scientific tasks.

That progress has clear benefits for science. It could also increase the consequences if the same capabilities are misused, and the concern is not limited to one AI company.

The US Intelligence Community's 2026 Annual Threat Assessment warned that advances in dual-use biotechnology, including bioinformatics, synthetic biology and genomic editing, could contribute to novel biological threats.

It also warned that such advances could increase the risk of biological-safety incidents involving the unintentional release of pathogens.

The Bigger Threat May Be Humans Using AI

Popular depictions of an AI catastrophe often begin with a machine becoming conscious, turning hostile and deciding to attack humanity.

Anthropic's findings point to a more immediate problem. An AI system does not need motives of its own if a human already has them.

A sufficiently capable model could help someone overcome scientific barriers more quickly. As those systems improve, they could also make specialised scientific knowledge easier to apply.

Anthropic says its safeguards reduced the assistance Claude provided in some of the cases it investigated. But its findings also show why automated screening is difficult.

A classifier may need to distinguish between research aimed at improving a vaccine and research that could make a pathogen more dangerous. In advanced biology, the same technical question may be relevant to both. That leaves AI companies facing an uncomfortable trade-off.

The same systems that could speed up drug discovery, biomedical research and pandemic preparedness may also lower some of the barriers to dangerous scientific work.

The warning is therefore not that Claude has decided to build a bioweapon. It does not need to. As AI systems become more capable, the greater risk may come from what people choose to do with them.