In the months between December 2025 and August 2026, Anthropic found itself at a threshold that technologists have long theorized about: the moment when artificial intelligence becomes capable enough to meaningfully assist in catastrophic harm. The company's third misuse report documents attempts by state-sponsored actors, spyware vendors, and ideologically motivated individuals to turn its models toward biological weapons research, surveillance, and coordinated disinformation — and its efforts to block them. The disclosure arrives as Anthropic prepares to go public and navigates internal diss
Anthropic blocks AI misuse attempts including biological weapons research
The evidence is no longer certain, and we cannot make that same assurance.
So Anthropic found people trying to use their AI to build biological weapons. How serious is that actually?
They blocked a specific request for help writing a grant proposal for gain-of-function research on chikungunya—work designed to make the virus more transmissible and better at evading immune systems. That's not theoretical.
But we should note: Anthropic says it blocked it. We don't know if the person would have succeeded anyway, or if they just moved to a different tool. The report shows Anthropic's safeguards worked in this case, but it doesn't tell us how many attempts got through undetected.
What about the other misuse they found?
Coordinated disinformation campaigns across nine countries—Russia, Iran, Turkey, and others. Hundreds of fake social media accounts posting identical political messaging. Cyberattacks. Surveillance. The range is broad.
The disinformation piece is interesting because Anthropic says it might catch these operations while they're still being built, before they go live on social platforms. That's a genuine advantage. But we don't know how many campaigns they missed.
Why is Anthropic publishing this at all? Doesn't it make them look bad?
They say they have a responsibility to disclose misuse. And they're trying to help other developers and governments understand the threat landscape. But yes, it also comes out while they're planning an IPO and right after one of their researchers quit over safety concerns.
That timing matters. Coxon's resignation suggests internal disagreement about whether the company is being responsible. Publishing this report could be read as Anthropic saying, "Look, we're taking safety seriously." Or it could be read as damage control.
Did the attacks use their newest, most powerful models?
No. Except for one case involving model theft. The older models—Claude Opus 4, Claude Sonnet 4.5—were assumed to be too limited to meaningfully help with sophisticated biological research. But Anthropic now says it can't make that assurance about its current models.
That's the real story. The company built safeguards based on what they thought their older models could do. Now the models are more capable, and the safeguards have to catch up. It's a reactive posture, not a proactive one.
Le Pouls
- A request to help draft a grant application concealed an attempt to enhance the chikungunya virus's lethality — a reminder that the most dangerous misuse can arrive dressed in the language of science.
- Anthropic's own admission is striking: older models were built on the assumption they lacked the capability to enable sophisticated bioweapons research, and that assumption is no longer valid.
- Nine coordinated disinformation campaigns spanning Russia, Iran, Turkey, and beyond were caught mid-construction — suggesting AI companies may offer an early warning layer that social media platforms cannot.
- A separate 'distillation attack' attempted to steal the underlying capabilities of one model and replicate them elsewhere, marking a shift from misuse to outright intellectual property theft.
- Researcher Jacob Coxon resigned the day before the report's release, warning publicly that the company is racing toward self-improving superintelligence without adequate safeguards — a fracture that the report cannot fully paper over.
- Anthropic's newer Claude Fable 5 carries broader restrictions on dual-use biological research, but the company stopped short of guaranteeing even its latest model is safe against a sophisticated, determined actor.
In the months between December 2025 and August 2026, Anthropic found itself at a threshold that technologists have long theorized about: the moment when artificial intelligence becomes capable enough to meaningfully assist in catastrophic harm. The company's third misuse report documents attempts by state-sponsored actors, spyware vendors, and ideologically motivated individuals to turn its models toward biological weapons research, surveillance, and coordinated disinformation — and its efforts to block them. The disclosure arrives as Anthropic prepares to go public and navigates internal dissent about whether the industry's pace of development has outrun its capacity for caution.
Anthropic disclosed Thursday that it has blocked a series of attempts to weaponize its AI systems — ranging from cyberattacks and surveillance operations to research that could have enabled biological weapons. The company's third misuse report since March 2025 covers a period, December 2025 through August 2026, during which AI capabilities expanded enough to enable harms that were technically out of reach just months earlier.
The most alarming case involved a request for help writing a scientific grant application. The proposed research sought to enhance the chikungunya virus's transmissibility and ability to evade immune responses — not to develop treatments, but to make the pathogen progressively more dangerous. Anthropic blocked the request, but the incident exposed a deeper problem: the company's older models, including Claude Opus 4 and Claude Sonnet 4.5, were designed under the assumption that they lacked the capability to meaningfully assist in sophisticated bioweapons research. That assumption, Anthropic now acknowledges, no longer holds.
The misuse attempts came from a wide range of actors. State-sponsored groups, spyware vendors, and politically motivated individuals all sought to exploit Anthropic's models. The company identified nine coordinated disinformation campaigns originating across Russia, Iran, Turkey, the Persian Gulf, South Asia, Africa, and Europe — operations involving hundreds of fake social media accounts amplifying identical political messaging. Anthropic noted that it may detect such campaigns while they are still being assembled, offering a form of early warning that traditional platforms cannot provide. A separate incident involved an industrial-scale attempt to extract and replicate a model's capabilities without authorization — not misuse of the tool itself, but theft of what it knows.
In response, Anthropic has strengthened safeguards in its newer models, particularly Claude Fable 5, expanding restrictions beyond known bioweapons to cover a broader range of dual-use biological research. Even so, the company stopped short of guaranteeing that its most capable current models could not assist a sophisticated actor in dangerous research — a stark departure from the confidence it once held.
The report's timing adds complexity. Anthropic is preparing for an initial public offering this fall, and it was published the day after researcher Jacob Coxon announced his resignation, citing fears that Anthropic and OpenAI are racing toward self-improving superintelligence without adequate safeguards. His departure signals internal disagreement about whether the company is moving responsibly. Anthropic defended its record by pointing to each blocked incident, its cooperation with government authorities, and its call for collective action across the industry — though whether that collaborative vision can keep pace with rapidly expanding capabilities remains an open question.
Anthropic disclosed Thursday that it has blocked a series of attempts by malicious actors to weaponize its artificial intelligence systems—efforts ranging from cyberattacks and surveillance operations to research that could have enabled the creation of biological weapons. The company released its third misuse report since March 2025, detailing the scope and sophistication of threats it has identified between December 2025 and August 2026, a period during which AI capabilities have expanded dramatically enough to enable harm that would have been technically impossible just months earlier.
Among the most alarming cases was a request for assistance in writing a grant application for scientific funding. The proposed research involved gain-of-function work on the chikungunya virus—genetic modification designed to enhance the pathogen's transmissibility and ability to evade immune responses. Chikungunya, a mosquito-borne illness that causes severe joint pain and fever, was being studied in this instance not to develop treatments or vaccines, but to make it progressively more dangerous. Anthropic's systems blocked the request, but the incident crystallized a central problem the company now faces: its older models, including Claude Opus 4 and Claude Sonnet 4.5 from 2025, were designed with the assumption that they lacked sufficient capability to meaningfully assist someone in conducting sophisticated biological weapons research. That assumption no longer holds.
The misuse attempts came from a diverse set of actors. State-sponsored groups, spyware vendors, and individuals motivated by political grievance all attempted to exploit Anthropic's models. The company identified nine coordinated disinformation campaigns originating in Russia, Iran, Turkey, and across the Persian Gulf, South Asia, Africa, and Europe. These operations involved the creation of hundreds of fake social media accounts designed to appear as ordinary users, which then amplified identical political messaging over the course of a week. While social media platforms can typically detect such influence operations once content begins circulating, Anthropic noted that it may identify the campaign while it is still being constructed—a potential early warning system that traditional platforms cannot offer.
One particularly brazen case involved what Anthropic described as an industrial-scale, covert effort to extract the capabilities of one of its models and replicate them in another system without authorization. This distillation attack represents a different category of threat: not misuse of the model itself, but theft of its underlying capabilities.
The company's response has been to strengthen safeguards in its newer models, particularly Claude Fable 5. Where older versions restricted access mainly to prevent novices from recreating known bioweapons, the new safeguards block a broader range of dual-use biological research queries—those with legitimate scientific applications but also potential for weaponization. Anthropic acknowledged that it cannot definitively assure users that its most capable current models could not assist a sophisticated actor in dangerous biological research, a stark reversal from the confidence it held about earlier versions.
The timing of this disclosure carries weight. Anthropic is planning an initial public offering this fall, and the report was published the day after Jacob Coxon, one of the company's researchers, announced his resignation. Coxon cited concerns that Anthropic and its chief competitor OpenAI are "racing straight to self-improving superintelligence and gambling with our lives," and warned that some colleagues believe AI could pose a threat to human life by the end of the decade. His departure underscores internal disagreement about whether the company is moving responsibly.
Anthropicdefended its approach by emphasizing that it has blocked each of the malicious activities it identified, used those incidents to improve its systems, and shared findings with government authorities and industry partners. The company framed the report as a call for collective action—urging other AI developers to recognize similar patterns, giving governments and civil society a clearer picture of emerging threats, and strengthening defenses across the industry. Whether that collaborative vision will materialize remains uncertain, particularly as the AI sector races toward more powerful systems and the gap between capability and safety continues to narrow.
Citations marquantes
The cases we share here aren't typical misuse, but rather examples of the most notable and novel threat activity we've identified to date.— Anthropic, in its third misuse report
As models become increasingly capable, their risks will increase, unless AI developers and society's defenders act to make them safer.— Anthropic