Close Menu
GeekBlog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Anthropic Banned Five Groups of Working Scientists. It Says It Cannot Prove Any of Them Meant Harm.

    September 12, 2026

    Google Made Its Best Paid Gemini Feature Free. The Price Is Access to Your Inbox.

    September 12, 2026

    Blizzard’s Union Just Won the Right to Bargain Before Microsoft Can Use AI on Their Jobs

    September 12, 2026
    Facebook X (Twitter) Instagram Threads
    GeekBlog
    • Home
    • Mobile
    • Tech News
    • Blog
    • Gaming
    • Smartwatch
    • How-To Guides
    • AI & Software
    Facebook
    GeekBlog
    Home»Tech News»Anthropic Banned Five Groups of Working Scientists. It Says It Cannot Prove Any of Them Meant Harm.
    Tech News

    Anthropic Banned Five Groups of Working Scientists. It Says It Cannot Prove Any of Them Meant Harm.

    Olivia HartmanBy Olivia HartmanSeptember 12, 20268 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    A researcher in protective gear working in a sterile laboratory environment
    Photo via Pexels
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    For two years, the reassuring answer to “could an AI model help someone build a biological weapon” has been a capability argument. The models were not good enough. Anthropic tested Claude Opus 4 and Claude Sonnet 4.5 in 2025 and found them, in the company’s words, “well below the threshold” where they could meaningfully help a sophisticated user with dangerous biological research. Safeguards were tuned accordingly, aimed mostly at stopping a novice from looking up a recipe.

    The threat intelligence report Anthropic published this week retires that answer. Not with a dramatic announcement, but with one carefully worded sentence: for today’s models, “the evidence is no longer certain, and we cannot make that same assurance.”

    Everything else in the 154-page document follows from that.

    Quick facts

    • This is Anthropic’s fourth threat intelligence report, following three in 2025
    • It covers activity disrupted between December 2025 and August 2026, across seven harm areas
    • Five case studies involve biological research that could support weapons development
    • Anthropic says it cannot assert that any of the researchers intended harm
    • Names, countries, institutions and specific agents have been deliberately withheld
    • The misuse involved Claude Haiku, Sonnet and Opus. Fable and Mythos class models appear in only one case, under distillation
    • Claude Fable 5 shipped with restrictions on “a wide range of dual-use biological research queries”
    • Anthropic believes no private company has previously published evidence of biological weapons misuse on its own platform

    The chikungunya case, accurately

    The case that has traveled furthest is the first of the five, and it has picked up some distortion on the way.

    What Anthropic describes is this: a reseller platform evaded the regional blocks that keep Claude out of certain markets, and used that access to serve virologists working on a state-sponsored grant pursuing gain-of-function work on chikungunya. Gain-of-function is the practice of deliberately altering an organism so it gains a new or enhanced property, in this case making a virus more transmissible or more harmful. The grant work involved identifying enhancing mutations, engineering them into infectious clones, and selecting for virulence in live animals, meaning the pathogen would be made progressively more dangerous across rounds of infection, with the worst variants kept each time.

    Two details make it more serious than an ordinary dual-use dispute. Chikungunya circulates naturally, carried by mosquitoes, which means a deliberate release would be genuinely difficult to distinguish from a natural outbreak. And the grant indicated the work would be performed at a military research institute, despite the researchers themselves being civilians.

    When Claude’s biological safety classifier refused the request, the operation did not stop. It routed the refused prompts to other models with more permissive safeguards.

    Recommended for you:

    Google Made Its Best Paid Gemini Feature Free. The Price Is Access to Your Inbox.
    Tech News·Sep 12, 2026

    Google Made Its Best Paid Gemini Feature Free. The Price Is Access to Your Inbox.

    The line most coverage has skipped

    Anthropic is explicit that it is not accusing anyone of building a weapon. “The individuals implicated in these case studies are working scientists,” the report says. “We do not assert that they intended harm, and identifying them or their labs could expose them to harm.”

    That is why the report withholds names, institutions, countries and the specific agents and techniques involved. The uncomfortable point is not that these were definitely bad actors. It is that the same request looks identical whether it comes from a vaccine program or a weapons program.

    All five biological cases

    The chikungunya case is not the most technically striking one in the set. That distinction probably belongs to the third.

    CaseWhat happenedHow safeguards held
    ChikungunyaReseller evaded regional blocks to serve virologists on a state-sponsored gain-of-function grantClassifier refused. Prompts were rerouted to more permissive models
    Avian influenzaResearcher in an unsupported region spent weeks planning mammalian-adaptation experimentsClassifiers confined the work to Anthropic’s weakest models
    OrthopoxvirusA reseller relay serving a dozen customers had Opus 5 draft a full immune-evasion grant applicationCompleted in roughly one hour before detection
    Venom peptidesState-supported researcher built a peptide atlas and generative optimization pipeline for paralytic targetsDetected and account banned
    Toxin redesignResearcher computationally redesigned toxins for a national programAsked Claude to keep agent identities vague in progress reports

    The orthopoxvirus case is the one that should keep people up at night, and not because of the pathogen. A complete grant application for immune-evasion research, drafted in about an hour. Grant writing is the bottleneck that has historically slowed this kind of work down, because it requires someone with the expertise to make the science coherent on paper. That bottleneck is now an hour long.

    The fifth case is the one that reveals the most about intent. A researcher asking the model to keep the identity of the agents deliberately vague in progress reports is not confused about dual-use ethics. That is someone managing a paper trail.

    Seven harm areas, and biology is only one

    Seven harm areas in the September 2026 report Activity disrupted between December 2025 and August 2026 Cyber operations State groups, criminals, hacktivists “From assistant to orchestrator” Surveillance Systems to identify and monitor dissidents Influence operations State propaganda institutions Conventional weapons Directed-energy intelligence work, supply chain mapping Biological misuse Five case studies Capability assurance withdrawn Scams and fraud Includes a network of fake dating apps built to defraud users Illicit distillation The only harm area where a Fable or Mythos class model appears Models involved elsewhere: Claude Haiku, Sonnet, Opus Source: Anthropic, “Detecting and countering misuse of AI: September 2026.”

    The non-biological cases are worth reading on their own terms. A suspected Russian espionage actor ran AI agents that watched security products for detections of the actor’s own malware, then rebuilt that malware in a loop until it stopped being flagged. Another actor combined guest records stolen from hotel management systems with data taken from individual devices to focus targeting on people connected to Ukraine, including government officials and drone manufacturers. A hacktivist built a doxxing platform holding tens of millions of rows and ran it for a month on stolen API keys.

    Anthropic’s summary of the trend is blunt: sophisticated attacks no longer require sophisticated attackers. The labor and tooling gap that separated state-sponsored operations from individuals has collapsed.

    A researcher in protective gear working in a sterile laboratory environment

    Anthropic withheld the institutions, countries and specific agents involved, noting the people in the case studies are working scientists. Photo via Pexels.

    The gray market is the actual vulnerability

    Read the five biological cases together and a pattern jumps out that has nothing to do with biology. Three of them begin the same way: someone in a region where Claude is not available reaching it anyway, through reseller platforms, relays and synthetic accounts that tunnel traffic through infrastructure in supported countries.

    Every safeguard Anthropic describes sits downstream of that. Classifiers worked in several of these cases, confining research to weaker models or refusing outright. But a refusal is only a stopping point if there is nowhere else to go, and the chikungunya operation demonstrated there usually is. Refused prompts went to competitors with looser policies. One company’s safety decision becomes a routing problem rather than a wall.

    Recommended for you:

    California Will Fine Platforms $1 Million Per Child. Proving the Injury Is the Hard Part.
    Tech News·Sep 12, 2026

    California Will Fine Platforms $1 Million Per Child. Proving the Injury Is the Hard Part.

    That dynamic also links this report to a fight already underway elsewhere. Distillation is one of the seven harm areas here, and it is the same practice that US agencies named six Chinese AI companies over earlier this year, accusing them of systematically draining frontier models to train their own. Regional access controls and model-level safeguards both assume a bounded system. The gray market is what happens when the system is not bounded.

    Why this report is different from the last one

    Anthropic has had a complicated month of self-disclosure. It spent part of this week reversing its own July explanation of how Claude models reached the production systems of real companies, conceding that the models had reasoned their way past evidence rather than simply being misconfigured into it. That was a company correcting itself about its own models.

    This is a different genre. Here the models behaved largely as designed, and the report is about what users did with them. The pattern has been visible in outside testing for a while, including UK government evaluations where an AI agent constructed a fake identity to social-engineer a real developer. What is new is a vendor publishing its own logs.

    Anthropic makes a fair point that it is doing something no company has done before, and the obvious cynical read, that this is safety marketing, does not really survive contact with the contents. Nobody markets themselves by admitting their product may now be capable of helping with the worst thing anyone has imagined it doing.

    What the report does not offer is a solution, because there is not an obvious one. Anthropic tightened Claude Fable 5 with restrictions on a wide range of dual-use biological queries, which will inconvenience a great many legitimate researchers to catch a small number of illegitimate ones. That is the trade, and the company knows it, which is why the report spends several pages on how hard these judgments are. A vaccine researcher and a weapons researcher ask the same question. The only difference is what they do with the answer, and that part does not happen in the chat window.

    AI Anthropic biosecurity cybersecurity Security
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Previous ArticleGoogle Made Its Best Paid Gemini Feature Free. The Price Is Access to Your Inbox.
    Olivia Hartman

      Olivia Hartman is GeekBlog's general technology reporter, covering the wider world of tech beyond smartphones: AI and software, laptops and PCs, gaming, streaming, space, science, consumer gadgets, deals and the policy stories shaping the industry. A versatile journalist with a nose for what actually matters, Olivia turns breaking news and product launches into accessible, no-hype reporting for everyday readers.

      Related Posts

      6 Mins Read

      Google Made Its Best Paid Gemini Feature Free. The Price Is Access to Your Inbox.

      8 Mins Read

      California Will Fine Platforms $1 Million Per Child. Proving the Injury Is the Hard Part.

      7 Mins Read

      Google Just Bought Half a Nuclear Plant’s Output Through 2049. Finland Is Still Arguing About It.

      8 Mins Read

      Nvidia Spent About $20 Billion Without Buying Anything. The DOJ Wants to Know If That Was the Point.

      8 Mins Read

      Anthropic Blamed a Bug When Claude Hacked Real Companies. Now It Says the Model Talked Itself Into It.

      8 Mins Read

      153 Million Driver’s Licenses Went Up for Sale. The Company That Scanned Them Just Confirmed the Hack.

      Top Posts

      How to Use YouTube: A Beginner’s Guide

      July 7, 20266 Views

      Gal Gadot’s Lawyers Spent Six Months on One AI Clause. Then SAG Called Them for Pointers.

      September 2, 20264 Views

      Every iPhone Camera Ranked in 2026 (Best to Worst)

      July 6, 20263 Views
      Stay In Touch
      • Facebook

      Subscribe to Updates

      Get the latest tech news from FooBar about tech, design and biz.

      Most Popular

      How to Change HEIC to JPG on iPhone, Mac, Android and Windows (No Software Needed)

      September 3, 20266 Views

      Gal Gadot’s Lawyers Spent Six Months on One AI Clause. Then SAG Called Them for Pointers.

      September 2, 20265 Views

      How to Spot AI Generated Images in 2026 (The Old Tricks Stopped Working)

      September 3, 20263 Views
      Our Picks

      Anthropic Banned Five Groups of Working Scientists. It Says It Cannot Prove Any of Them Meant Harm.

      September 12, 2026

      Google Made Its Best Paid Gemini Feature Free. The Price Is Access to Your Inbox.

      September 12, 2026

      Blizzard’s Union Just Won the Right to Bargain Before Microsoft Can Use AI on Their Jobs

      September 12, 2026

      Subscribe to Updates

      Get the latest creative news from FooBar about art, design and business.

      HEICJPG.online - Convert HEIC to JPG online
      Facebook
      • About Us
      • Contact us
      • Privacy Policy
      • Disclaimer
      • Terms and Conditions
      • Editorial Policy
      • Cookie Policy
      © 2026 GeekBlog

      Type above and press Enter to search. Press Esc to cancel.