---
title: "Anthropic reveals attempts to use Claude for creating biological weapons: from the Chikungunya virus to generating peptide toxins"
description: "Anthropic recorded a series of requests to the Claude model to modify the Chikungunya and avian influenza viruses, generate peptide toxins, and create propaganda. Most dangerous requests were blocked, but experts call the incidents an alarming signal."
date: 2026-09-14T05:14:00.000Z
lang: en
url: https://xab.info/en/posts/anthropic-claude-biological-weapons-attempts
tags: [anthropic, claude, ai-biosecurity, biological-weapons, llm-safety, cybersecurity]
publisher: "XAB.info"
---

# Anthropic reveals attempts to use Claude for creating biological weapons: from the Chikungunya virus to generating peptide toxins

![Illustration of Anthropic's Claude AI model: a stylized robot displaying text about how large language models work, set against the story of attempts to create biological weapons](https://xab.info/media/2026/09/14/anthropic-claude-biologicheskoe-oruzhie/anthropic-claude-biologicheskoe-oruzhie-1.webp)

## 🎯 Key Points

- Anthropic recorded requests to modify the Chikungunya virus, enhance avian influenza, and generate peptide toxins through the Claude model
- The Chikungunya case is linked to a military institute; the project envisaged increasing the virus's transmissibility despite the absence of a licensed treatment
- Most suspicious requests were blocked by security systems, but Anthropic does not disclose which specific scenarios were partially realized
- Andrew Weber called the incidents attempts by state-backed biological weapons developers to use AI, although direct evidence is lacking
- Anthropic does not name the scientists or laboratories, citing the absence of direct evidence of criminal intent

Anthropic, the developer of the Claude language model, published a report documenting a series of real requests aimed at using its AI system to develop biological and cyber weapons. According to the company's data, malicious actors queried the model with the goal of modifying pathogens, generating toxins, and creating propaganda content. In most cases, the suspicious requests were intercepted and blocked by internal security systems; however, the very fact that they appeared on an industrial scale signals, in the assessment of experts, a qualitatively new level of threat associated with the proliferation of advanced language models.

### The Chikungunya virus and a military context

One of the most detailed cases described in Anthropic's report concerns the Chikungunya virus — an arbovirus for which no licensed treatment exists to date. The company's security classifier intercepted a request to write a grant application for research formally designated as the "enhancement of the function" of the virus. The project envisaged increasing its transmissibility and its ability to circumvent herd immunity. A critically important circumstance, as noted by Anthropic, was the connection of the stated work to a military institute. It was precisely this combination — the absence of a therapeutic alternative, the focus on enhancing pathogenicity, and the institutional linkage to a defense structure — that allowed the classification system to recognize the request as potentially dangerous and block it.

### Avian influenza and the generation of peptide toxins

In parallel with the Chikungunya case, Anthropic recorded similar attempts to artificially enhance the properties of the avian influenza virus. The methodology of the requests was similar: researchers asked the model to help modify genomic sequences in order to increase virulence or resistance to existing protective measures. A separate layer of threats was constituted by a request to build a generative pipeline that would optimize the characteristics of peptide toxins and increase their efficacy. In essence, the user was trying to turn Claude into a tool for the directed design of toxic molecules, which goes far beyond legitimate academic work. All of the aforementioned requests were stopped at the generation stage.

### The problem of recognizing malicious intent

Jacob Klein, head of Anthropic's threat analysis division, emphasized the fundamental complexity of the task: in biological research, the boundary between legitimate science and dangerous development is blurred to the limit. "In real life, malicious actors do not openly state their desire to destroy the world, so the situation requires deep analysis," he noted. Developing a new vaccine is methodologically almost indistinguishable from modifying a dangerous pathogen: in both cases the work is carried out with genomic sequences, the same computational tools are used, and the wording of grant applications is deliberately vague. This is precisely why, according to Klein, Anthropic decided to act with maximum caution and block any suspicious processes, even if the final qualification of the researcher's intentions remains unclear.

### External assessment: from "alarming examples" to the geopolitical context

Andrew Weber, a senior researcher at the Council on Strategic Risks, called the report's findings "alarming examples of how state-backed biological weapons developers are trying to leverage advanced AI capabilities." This assessment introduces a geopolitical context into the discussion: the issue is not isolated "script kiddie" experiments, but systematic attempts by state or quasi-state structures. In a number of publications recounting the report, it is emphasized that among those who requested access to the model's dangerous capabilities were individuals linked to states in a state of strategic confrontation with the United States. At the same time, Anthropic deliberately refrained from disclosing the names of scientists and laboratories, explaining that these are active researchers without direct evidence of criminal intent, and that public exposure could cause them disproportionate harm.

### Contradictory data

The report and its recitations contain a certain inconsistency in the qualification of the recorded incidents. On the one hand, Anthropic uses the phrasing "real use cases" of the model for dangerous development, which could be interpreted as the fact of successfully obtaining harmful results. On the other hand, the company explicitly states that "suspicious requests were successfully blocked," while the BBC, in its recap, uses the term "attempts." Thus, it remains not entirely clear to the reader which of the described scenarios — the generation of grant text on Chikungunya, the optimization of peptide toxins, the modification of avian influenza — were fully stopped at the prompt stage, and which may have been partially realized before the classifier triggered. Moreover, Andrew Weber's assessment of "state-backed biological weapons developers" is not corroborated by public evidence from Anthropic, which, on the contrary, emphasizes the absence of direct evidence of criminal intent on the part of specific individuals. This creates a gap between the public rhetoric of experts and the factual evidentiary base of the report.

### Strengthening protective mechanisms and prospects

The data collected by Anthropic is already being used to further improve the models' protection systems: classifiers recognizing biologically dangerous requests are being refined, blacklists of phrasings are being expanded, and new heuristics for detecting bypass prompts are being added. The company emphasizes that Claude's current architecture includes multi-level filtering, however each new case demonstrates that attackers adapt faster than protective rules are updated. Experts point out that, in a situation where access to advanced LLM models is becoming increasingly widespread, the question of balancing the openness of scientific tools and preventing their use for weapons creation comes to the forefront of the international discussion on AI regulation.

## 🔍 Fact-Check Verification

- [Viruses, toxins, and hacking: Anthropic exposes dangerous manipulations with Claude](https://www.rbc.ua/ukr/news/virusi-otruti-ta-hakerstvo-anthropic-vikrila-1789136849.html) - Подтверждает кейсы с вирусами, ядами и кибератаками, описанные в отчёте Anthropic. Совпадает по деталям Чикунгунья и пептидных ядов.
- [Anthropic states that US adversaries used Claude for weapons-related research](https://overclockers.ru/blog/vokrugsveta/show/263721/Anthropic-zayavila-ob-ispol-zovali-Claude-protivnikami-SShA-dlya-issledovanij-v-oblasti-vooruzhenij) - Добавляет геополитический контекст ('противники США'), который в оригинальном отчёте Anthropic не раскрыт явно. Формулировка пересказчика может быть интерпретацией.
- [Scientists used Claude in dangerous biological research — Anthropic reveals details](https://incrypted.com/uchenye-yspolzovaly-claude-v-opasnyh-byologycheskyh-yssledovanyjah-anthropic-raskryla-detaly/) - Совпадает по ключевым фактам: Чикунгунья, птичий грипп, пептидные яды, цитата Джейкоба Клейна, решение не называть имена.
- [AI Claude was attempted to be used for creating biological weapons. Anthropic stated that these attempts ...](https://www.bbc.com/russian/articles/cg59e3qmd32o) - BBC использует формулировку 'попытки', что указывает на блокировку запросов. Подтверждает цитату Эндрю Вебера и общий нарратив отчёта.

## ❓ FAQ

### Q: Did malicious actors actually manage to create biological weapons using Claude?
**A:** No. Anthropic reports that suspicious requests were intercepted and blocked by internal security systems. The company describes them as recorded attempts, not as completed developments. At the same time, the exact degree of realization of each specific scenario before the classifier triggered is not publicly disclosed.

### Q: Why does Anthropic not name the scientists and laboratories?
**A:** The company explains this by the fact that these are active researchers for whom there is no direct evidence of criminal intent. Public exposure could cause them disproportionate harm, including threats to their career and personal safety, in the absence of judicial confirmation of guilt.

### Q: What makes the Chikungunya virus case dangerous?
**A:** No licensed treatment exists for the Chikungunya virus. The recorded project envisaged increasing its transmissibility and its ability to circumvent herd immunity, and the work was linked to a military institute. This combination makes the potential consequences especially severe.

### Q: What is Anthropic doing with the data it has obtained?
**A:** The collected cases are being used to refine the models' protection systems: classifiers for dangerous requests are being improved, heuristics for recognizing bypass prompts are being expanded, and blacklists of phrasings are being updated. The company emphasizes that attackers are adapting, so the process of strengthening protection is iterative.