Must read: Anthropic’s AI researcher exits AI industry with a warning: ‘Do not underestimate its power’
How Claude AI can be misused
According to the report, people used Claude Haiku, Sonnet, and Opus models across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation.
“The cases we share here aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date,” the report said.
It highlighted that a user tried to use Claude while preparing a grant application for gain-of-function research involving chikungunya virus. Gain-of-function research is useful for understanding diseases and developing treatments, but some experiments can also make pathogens more dangerous or easier to spread.
Another case involved research into a bird flu variant that could potentially spread among mammals. “Biological misuse is one of the most serious risks of frontier AI models,” Anthropic wrote. “Without the correct safeguards, such capabilities could have catastrophic consequences.”
After identification, the company banned the account, but it did not reveal the names of the researchers or the country where it took place. It also revealed many other examples where people or groups allegedly used Claude for harmful or suspicious activities, beyond the biological-weapons cases.
Must read: What will the AI economy look like? Anthropic sees US GDP soar 32% by 2030, but jobs crisis looms
The company said, “We're publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society's defenders act to make them safer.”
Anthropic’s safeguard against misuse
In the report, Anthropic highlighted that none of the cases included the use of newer or more capable AI models like the Claude Fable or Mythos-class models. It highlighted that older models like Claude Opus 4 and Claude Sonnet 4.5, in which safeguards “were less stringent, directed mostly at preventing access to content that might uplift novices in recreating known bioweapons,” the company said.
As a result, Anthropic has applied “stronger safeguards that restrict access to a wide range of dual-use biological research queries” in its latest generation models to prevent misuse.