News: 0185594528

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Anthropic Says It Blocked Possible Efforts to Build Biological Weapons

(Thursday September 10, 2026 @11:30PM (BeauHD) from the detecting-and-countering dept.)


Anthropic says it has disrupted several cases this year in which scientists [1]used Claude for biological research that could potentially aid bioweapons development . "In a report describing misuses of its A.I. models, Anthropic said it could not determine whether the research served a legitimate or nefarious purpose because valid biological inquiry -- the kind that can lead to breakthroughs like vaccines -- can also help engineer dangerous pathogens," reports The New York Times. "In the face of that uncertainty, Anthropic said it erred on the side of caution because the consequences of missing malicious activity could be severe." From the report:

> The potential for cutting-edge A.I. models to facilitate the development of known or entirely new biological pathogens is among the gravest concerns experts have about a technology that is developing so rapidly that even its leading architects doubt whether humans will be able to fully control it. Andrew Weber, a senior fellow on the Council on Strategic Risks who reviewed Anthropic's report before its release, said the findings were "chilling examples of state-sponsored biological weapons developers tapping into the rapidly advancing capabilities" of leading A.I. models.

>

> The [2]lengthy report Anthropic published on Thursday cataloged a litany of misuses of its A.I. models, including the chatbot Claude, over the past eight months. Some examples were similar to past disclosures from Anthropic and other A.I. labs, including suspected Chinese and Iranian government-linked actors targeting dissident and diaspora communities for surveillance.

>

> The report also highlighted cases of Russian state media using Claude to generate online propaganda masquerading as independent reporting, including fabricated claims about an election in Moldova. Anthropic documented another genre of abuse it said was new: attempts to use Claude to develop software for conventional weapons design and development, including firearms, missiles, armed drones and bombs. It detailed three cases in China, two in Russia and one in Yemen. The report does not identify by name which parties were involved in the Yemeni case, but the context makes clear that it is referring to the Iran-backed Houthi militia.



[1] https://www.nytimes.com/2026/09/10/us/politics/anthropic-ai-biological-weapons.html

[2] https://www.anthropic.com/threat-intelligence-report-september-2026



It was just ordinary research... (Score:2)

by drnb ( 2434720 )

It was just ordinary fertilizer and pesticide research, like Germany's prior to 1913.

Re: (Score:3)

by 0123456 ( 636235 )

Oddly, I saw some biology researcher saying this morning that they were switching to local models because a) these clown models won't let him do his work and b) he's now worried that they'll steal his work.

Re: (Score:2)

by butt0nm4n ( 1736412 )

Yup local private models are the way to go. Trying to encourage the same in my gaff.

These AI companies are dependent on harvesting content, and their success in dross manufacture and copyright law suits they are defending prove that behaviour. The most obvious predictor of future behaviour is past behaviour. Don't trust them with your content, it will be on chatGPT soon.

It's fascinating to watch the marketing narrative of AI. We need all content to make a Gen AI that will either save us or destroy us. Blin

Re: (Score:2)

by gweihir ( 88907 )

Local private models may also eventually give us possibilities to customize things. I want to be able to tell any interactive AI tool I use how to do things and improve its approaches. Before that is possible, using one would just waste my time. Guardrails and system-prompts are clearly not the way there.

Re: It was just ordinary research... (Score:1)

by Midnight_Falcon ( 2432802 )

What kind of hardware is he running? To run frontier open weight model like Kimi K3 you need at least 500k-1mm in compute equipment, meaning minimum two NVIDIA DGX B300s; which are often unobtainium due to high demand. Then you need ridiculous cooling and electricity, not something you put in a garage or office server closet. Or you can use a zero data retention cloud provider and pay per usage...

Re: (Score:2)

by 0123456 ( 636235 )

Don't know. You can run decent models like Deepseek V4 Flash on two DGX Sparks but I've no idea how good that is with biological work.

Or, yeah, you could just rent GPUs in 'the cloud' when you need to run the models.

Re: (Score:2)

by tragedy ( 27079 )

They did say a biology researcher. Whether that's corporate or university, they probably do have the computing resources available and probably shared among many researchers. Of course, you do run into the issues that, these days, those resources are probably running on cloud servers. So still quite possibly not actually local.

Re: It was just ordinary research... (Score:2)

by Midnight_Falcon ( 2432802 )

For sure, a (large/well-founded) university or a big corporation could run these, but I'm not sure who would call that "local" so much as private datacenter or internal. You could run it on AWS Bedrock or Azure foundry too and those don't really share data back to the AI companies, or zero data retention cloud for open weight models. I think "local" as having maybe an rtx5090 or a super up Mac studio, which will very slowly run some lightweight models but I'm not sure if those are particularly useful for

Re: (Score:2)

by tragedy ( 27079 )

Yeah. Even just doing casual research you run into troublesome censorship of information issues with these LLMs. For example, I was interested in the whole process of production of pennicillin and I had a long discussion going over all the principles from scratch: how to find, isolate, assay, and force evolve the most productive strains of pennicillin looking at how things were done historically, how to grow in aerated flasks with continuous feed nutrient systems (with discussion about corn steep liquor bei

Re: (Score:2)

by gweihir ( 88907 )

> Oddly, I saw some biology researcher saying this morning that they were switching to local models because a) these clown models won't let him do his work and b) he's now worried that they'll steal his work.

With the recent very likely stealing of the Navier-Stokes proof, (b) seems like a very real risk.

Re: (Score:2)

by geekmux ( 1040042 )

> It was just ordinary fertilizer..research..

* snort *

Sorry. Just made me laugh wondering if Anthropic can tell the difference between someone talking shit , and someone talking shit.

Re: (Score:2)

by machineghost ( 622031 )

It absolutely can ... it's just that when you ask it to do so:

30% of the time you'll get a simple correct answer

30% of the time you'll get a 10-page dissertation of the answer

30% of the time you'll get either a dissertation or one line ... that's wrong

10% of the time it will answer "they were talking shit" with no further explanation.

Re: (Score:2)

by Brain-Fu ( 1274756 )

Most, if not all, scientific research is weaponizable. This seems like a dangerous precedent to set.

Re: (Score:2)

by HiThere ( 15173 )

It is dangerous. So is deciding the other way. I think this is one of those cases where there isn't any really good answer. I bet the one they settle on is that "approved" researchers will be allowed to get answers.

Re: (Score:3)

by 0123456 ( 636235 )

Where "approved" means anyone who pays 10x the regular subscription fee.

It's all about the money.

It's all so tiresome (Score:3, Insightful)

by 0123456 ( 636235 )

Just more propaganda to support their push to ban open AI models so we'll all be forced to pay them instead.

Yep (Score:3)

by abulafia ( 7826 )

"Our secret sauce isn't secret, please regulate our competitors away."

I think they may be playing a game with the fight they picked with the math folks over the Navier Stokes finding, too. To normal folks that looks greedy and shortsighted. To a wannabe dictator, that looks like a magic mirror.

They blocked it. (Score:2)

by Valgrus Thunderaxe ( 8769977 )

But who's blocking their employees from using the same systems to make the same weapons?

Re: (Score:2)

by Alain Williams ( 2972 )

Or even a nation state that gets hold of a copy of Claude, I can think of many that would happily use it for this -- and worse.

Re: (Score:2)

by machineghost ( 622031 )

This was a terrible comment, and it absolutely deserved to be down-voted into oblivion ... but for what it's worth Anonymous Coward, you made me laugh.

Re: (Score:2)

by gweihir ( 88907 )

And, more important, what did they not block? And what did they not even see?

And this isn't happening here in the USA? (Score:2)

by Required Snark ( 1702878 )

Grow up.

Not buying it! (Score:3)

by methano ( 519830 )

I could be wrong, but I suspect when OpenAI and Anthropic warn us of all the bad things that their creations are up to, it's more a ploy to show us how supposedly powerful they are rather than really inform us of something wrong. If they're using their computers to break into other people's computers, they're criminals, not the overlords of some new, amazing technology.

Re: (Score:2)

by drinkypoo ( 153816 )

In this case it's making a strong argument (not a legal one, but an emotional one) for regulating it heavily or even banning it completely, because eventually even shitty models that you can run on your phone will have that kind of power.

Re: (Score:2)

by gweihir ( 88907 )

Yes. Obviously, you can look this stuff up and read up on it. But most people stupid enough to think attacking civilization is a good idea are not capable on that level. Now add an LLM that gives them nice step-by-step instructions to the mix and you have a recipe for disaster.

Re: Not buying it! (Score:2)

by greytree ( 7124971 )

I have a big gun.

So listen to ME !

Re: (Score:2)

by gweihir ( 88907 )

IMO it is both. Yes, the LLM assholes currently try to pretend their toys are incredibly powerful because their business numbers are abysmally bad and the moment the stupid cash dries up, they implode. But what LLMs can do is lift somebody stupid (and willing to do damage but not really capable of it) to the level of a, say, lower medium-level attacker. Any good STEM engineer and scientist knows how easy it is to do a lot of damage. The stupid do not. But fit them with an LLM that explains things to them, t

Crime Gaekeepers (Score:2)

by awwshit ( 6214476 )

Only we are allowed to be criming. Your criming will be blocked. Can't explain exactly why we keep failing to stop our own criming, its bleeding edge criming you know.

And the real question is what did they not block (Score:2)

by gweihir ( 88907 )

Because that is where the actual danger lies. But I expect that would be so bad that they are not even looking because the truth could kill them.

In personal conversations with technical people, I call myself a hacker. But
when I'm talking to journalists I just say "programmer" or something like that.

- Linus Torvalds