Skip to content

Security1 publisher3 min readPublished

About 133 million contractor exchanges ran through Claude with bio-risk filters off

Anthropic's threat report, published September 10, carries one logged biological case and a year in which the control meant to catch such cases was switched off on contractor traffic. Roughly eight months of misuse data sit behind it.

The Watch · Security desk

Photograph accompanying About 133 million contractor exchanges ran through Claude with bio-risk filters off
Photo: gadgetreview.com

What happened

  • Anthropic released a threat-intelligence report on September 10, 2026 covering roughly eight months of misuse data, and says it disrupted several attempts by scientists using Claude for research that could assist biological weapons work.
  • In May a scientist asked Claude to help draft a grant application for research to engineer chikungunya mutations making the virus more harmful and able to repeatedly infect live animals.
  • Six documented cases involve software relevant to conventional weapons design, three of them linked to China, two to Russia and one to Yemen.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Anthropic says it cannot separate dual-use research from weapons development, so the deciding signal is who is asking and where the work will run. A requester who omits the military affiliation presents a different case to the same reviewer.
  • contradiction Weber's remedy is denying access to researchers in Russia, China and North Korea; North Korea comes from his statement and does not appear in the cases. The report's own enforcement was dismantling relays built to defeat regional controls.
  • precedent A safety filter that can be switched off per traffic class was off for twelve months, and it took a retrospective review to find it. Vendor safety commitments now invite a scope question.
  • decision Buyers who counted vendor-side bio-risk filtering as a compensating control have to decide whether to verify coverage per traffic class or run the check on their own prompts.

The chikungunya request read like a grant application [4]. What Anthropic acted on was the setting: the work was to be carried out at a military research institute, and gain-of-function research has legitimate scientific uses [5]. Jacob Klein, Anthropic's head of threat intelligence, said, "It's an incredibly nuanced situation." [8] He told the New York Times that "You are not seeing someone in a comic book kind of way say, 'Hey, I want to build a biological weapon to kill everybody,'" [7].

From May 2025 to April 2026, bio-risk filters were disabled on contractor traffic covering approximately 133 million exchanges with around 50,000 contractors [11], which is twelve months [4] and about 2,660 exchanges per contractor [2]. The retrospective review flagged 1,197 transcripts as high risk, one in roughly 111,000 exchanges [12][1]. Anthropic says it found no confirmed evidence of actual bioweapons uplift from that gap [12].

The report came out September 10, 2026 and covers roughly eight months of misuse data [1]. Counting back, its window opens near January 2026, so it overlaps roughly the last four months of the period when the filters were off [3].

The state attributions sit elsewhere in the report. In this account of the report, the blocked biological research goes unattributed [5]. Russian state media used Claude to craft propaganda framed as independent reporting, including fabricated claims about a Moldovan election [13]. Suspected Chinese and Iranian government-linked actors used the models for dissident surveillance and to target diaspora communities, according to the report [14]. Six cases involve software relevant to conventional weapons design, three linked to China, two to Russia and one to Yemen, which the report implicitly ties to the Iran-backed Houthi militia [15].

Andrew Weber, a senior fellow at the Council on Strategic Risks and a former U.S. Assistant Secretary of Defense for nuclear, chemical and biological defense programs, reviewed the report before publication [16]. He called some findings "chilling examples of state-sponsored biological weapons developers tapping into the rapidly advancing capabilities" of leading AI models, according to the New York Times [17]. "The fact that Russia, China and North Korea continue to develop prohibited biological weapons makes it imperative that we deny their researchers access to these extraordinarily capable models," Weber said, according to the Washington Examiner [18]. North Korea is not among the states named in the report's misuse cases [6]. Susan Monarez, a microbiologist and former acting CDC director, also reviewed the report before publication [19].

Regional access controls were already being circumvented. Anthropic says it banned the associated accounts and dismantled the relay networks used to get around those controls [3].

Anthropic's own evaluations carry the capability claim: older Claude models could not meaningfully assist in dangerous biological research, and current, more capable models can complete complex scientific tasks [10]. The company also says it cannot definitively determine whether blocked research is legitimate dual-use work or weapons development, and that it erred toward blocking [9].

What to watch

  • Whether Anthropic publishes which traffic classes bio-risk filters now cover, and whether the retrospective review found other disabled controls.
  • Any referral of the 1,197 flagged transcripts to a government body, or a revision of the no-confirmed-uplift finding.
  • Whether other model vendors publish misuse telemetry with dates and exchange volumes attached.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories