Anthropic said Thursday that it had shut down access for scientists who used its Claude AI models “in ways that could support biological weapons development.”
The disclosure appeared in a detailed report that also described other forms of harmful activity tied to surveillance, scams, conventional weapons research and propaganda operations. Anthropic said the incidents highlighted in the report represent some of “the most notable and novel threat activity” the company has identified to date. According to the report, the threat actors included criminals, suspected state-backed groups, spyware vendors and state propaganda organizations.
Anthropic outlined five cases in which activity on its AI systems had the potential to assist biological weapons development. The company described biological misuse as “one of the most serious risks of frontier AI models.”
At the same time, Anthropic said the cases it uncovered “provide evidence of capability” in the AI models, while cautioning that they “cannot concretely demonstrate that such capability would ever be used to develop biological weapons in the real world.”
The users connected to those cases were working scientists, Anthropic said, though the company did not name them. It also said it could not “assert that they intended harm.”
“When we detected and investigated these cases, we banned the users’ accounts and incorporated our investigative findings into our frontier model safeguards, enforcement, and threat intelligence processes to better prevent, detect, and disrupt these activities in the future,” the report says.
Anthropic said newer and more advanced models, including Claude Fable 5, have stronger safeguards than earlier versions and limit access to “a wide range of dual-use biological research queries.” The report noted that AI’s biological capabilities can serve both beneficial and dangerous purposes.
“The same information that can be used to develop a biological weapon could also be used to develop, for example, a vaccine or a cure for a disease,” the company said.
Propaganda and surveillance
Anthropic also said that it identified and removed accounts using Claude for influence operations campaigns to shape public opinion, including three Iranian state-aligned accounts.
In these cases, each operation was run by an actor working within or on behalf of an Iranian state propaganda institution, the company said. Claude was used to build content, make posts seem like they were from independent news sources and to proliferate content across social media platforms like X, Instagram and TikTok.
One Iran-nexus threat actor used Claude to develop targeting recommendations against U.S. naval forces in the region, Anthropic said. The same account designed software for a domestic mass-surveillance platform for Iranian state systems.
Claude was also used to build and run surveillance operations by actors in China and West Africa, and in some cases, to identify targets. Anthropic said it identified cases where AI was being used in place of an engineering workforce.
In China, three accounts aligned with the PRC municipal security service used Claude for surveillance and transnational repression, including a municipal bureau that profiles overseas activists and organizations.