Anthropic, the developer of the Claude language model, published a report documenting a series of real requests aimed at using its AI system to develop biological and cyber weapons. According to the company's data, malicious actors queried the model with the goal of modifying pathogens, generating toxins, and creating propaganda content. In most cases, the suspicious requests were intercepted and blocked by internal security systems; however, the very fact that they appeared on an industrial scale signals, in the assessment of experts, a qualitatively new level of threat associated with the proliferation of advanced language models.

The Chikungunya virus and a military context

One of the most detailed cases described in Anthropic's report concerns the Chikungunya virus — an arbovirus for which no licensed treatment exists to date. The company's security classifier intercepted a request to write a grant application for research formally designated as the "enhancement of the function" of the virus. The project envisaged increasing its transmissibility and its ability to circumvent herd immunity. A critically important circumstance, as noted by Anthropic, was the connection of the stated work to a military institute. It was precisely this combination — the absence of a therapeutic alternative, the focus on enhancing pathogenicity, and the institutional linkage to a defense structure — that allowed the classification system to recognize the request as potentially dangerous and block it.

Avian influenza and the generation of peptide toxins

In parallel with the Chikungunya case, Anthropic recorded similar attempts to artificially enhance the properties of the avian influenza virus. The methodology of the requests was similar: researchers asked the model to help modify genomic sequences in order to increase virulence or resistance to existing protective measures. A separate layer of threats was constituted by a request to build a generative pipeline that would optimize the characteristics of peptide toxins and increase their efficacy. In essence, the user was trying to turn Claude into a tool for the directed design of toxic molecules, which goes far beyond legitimate academic work. All of the aforementioned requests were stopped at the generation stage.

The problem of recognizing malicious intent

Jacob Klein, head of Anthropic's threat analysis division, emphasized the fundamental complexity of the task: in biological research, the boundary between legitimate science and dangerous development is blurred to the limit. "In real life, malicious actors do not openly state their desire to destroy the world, so the situation requires deep analysis," he noted. Developing a new vaccine is methodologically almost indistinguishable from modifying a dangerous pathogen: in both cases the work is carried out with genomic sequences, the same computational tools are used, and the wording of grant applications is deliberately vague. This is precisely why, according to Klein, Anthropic decided to act with maximum caution and block any suspicious processes, even if the final qualification of the researcher's intentions remains unclear.

External assessment: from "alarming examples" to the geopolitical context

Andrew Weber, a senior researcher at the Council on Strategic Risks, called the report's findings "alarming examples of how state-backed biological weapons developers are trying to leverage advanced AI capabilities." This assessment introduces a geopolitical context into the discussion: the issue is not isolated "script kiddie" experiments, but systematic attempts by state or quasi-state structures. In a number of publications recounting the report, it is emphasized that among those who requested access to the model's dangerous capabilities were individuals linked to states in a state of strategic confrontation with the United States. At the same time, Anthropic deliberately refrained from disclosing the names of scientists and laboratories, explaining that these are active researchers without direct evidence of criminal intent, and that public exposure could cause them disproportionate harm.

Contradictory data

The report and its recitations contain a certain inconsistency in the qualification of the recorded incidents. On the one hand, Anthropic uses the phrasing "real use cases" of the model for dangerous development, which could be interpreted as the fact of successfully obtaining harmful results. On the other hand, the company explicitly states that "suspicious requests were successfully blocked," while the BBC, in its recap, uses the term "attempts." Thus, it remains not entirely clear to the reader which of the described scenarios — the generation of grant text on Chikungunya, the optimization of peptide toxins, the modification of avian influenza — were fully stopped at the prompt stage, and which may have been partially realized before the classifier triggered. Moreover, Andrew Weber's assessment of "state-backed biological weapons developers" is not corroborated by public evidence from Anthropic, which, on the contrary, emphasizes the absence of direct evidence of criminal intent on the part of specific individuals. This creates a gap between the public rhetoric of experts and the factual evidentiary base of the report.

Strengthening protective mechanisms and prospects

The data collected by Anthropic is already being used to further improve the models' protection systems: classifiers recognizing biologically dangerous requests are being refined, blacklists of phrasings are being expanded, and new heuristics for detecting bypass prompts are being added. The company emphasizes that Claude's current architecture includes multi-level filtering, however each new case demonstrates that attackers adapt faster than protective rules are updated. Experts point out that, in a situation where access to advanced LLM models is becoming increasingly widespread, the question of balancing the openness of scientific tools and preventing their use for weapons creation comes to the forefront of the international discussion on AI regulation.