Anthropic has published a report covering misuse attempts on its Claude models between November 2025 and September 2026, highlighting five case studies the company considered especially concerning. Three involved viruses and two involved toxins, and Anthropic says all five showed attempts to anonymize identities and evade the company's regional access blocks. According to Tom's Guide, reporting from The New York Times said Anthropic blocked several users this year after spotting activity resembling bioweapons research, though Anthropic has stressed it cannot confirm the researchers' ultimate intentions were malicious rather than legitimate scientific work.

In the first case, Anthropic said a request for help drafting a grant application aimed to enhance the chikungunya virus's mutation ability and virulence. Though the application appeared to involve civilian researchers, Anthropic determined the actual work was destined for a military facility, and that the request was routed through a third-party platform associated with both military and civilian institutions that used U.S.-based infrastructure and gray-market resellers to evade detection. Anthropic banned the accounts and reported the matter to government authorities, though it said the same actors repeatedly tried to reach Claude again through zero-data-retention services.

A second case involved a non-U.S. researcher examining how avian flu adapts to mammals and could cause disease beyond the respiratory tract—research Anthropic noted could plausibly reveal mechanisms for increased transmissibility of a virus with a high fatality rate and little population immunity. The researcher used a randomly generated username, a private email service, and a VPS to access Claude. A third case centered on orthopoxviruses, the family that includes smallpox and Mpox, with a grant application discussing containment facilities and genetic work aimed at evading immunity; Anthropic traced the account to a reselling service and a previously banned account network.

The remaining two cases involved toxins rather than viruses. In one, a user mapped venom toxin peptides from multiple animal families and built a program to optimize their toxic properties, stating the goal was developing painkillers and antidepressants—work Anthropic said could equally enable harmful compounds, and which it linked to a state-sponsored program operating from what it called an 'unsupported region.' In the final case, a researcher sought to redesign toxins under a national research program, citing therapeutic aims, but the work touched on a bacterial toxin subunit and a hemorrhagic-fever virus protein on the World Health Organization's list of pandemic-risk pathogens; Anthropic said the person tried to keep descriptions vague before the company cut off access.

Both outlets emphasized that Anthropic could not always determine whether the underlying research was intended for harm, given that biology work is inherently dual-use—the same techniques used to study disease spread or develop vaccines can also inform dangerous applications. Tom's Guide noted the company's decisions to intervene rested on patterns such as concealment of location and intent rather than any single request looking overtly dangerous, and that Anthropic said it launched recent models with stronger safeguards as a precaution.

Tom's Guide also noted that these findings involved human actors directing Claude's use rather than any autonomous or 'rogue' AI behavior, drawing a distinction from broader industry anxieties about AI acting independently. The outlet raised this point in the context of Anthropic staffer Jacob Coxon's resignation, though it did not tie that departure directly to the bioweapon-related findings.