
Anthropic said on Oct. 12, 2026 that its safety systems intercepted a request to use its AI models to draft a grant proposal for gain‑of‑function work on the chikungunya virus. The request was blocked, and an internal review uncovered eight additional misuse attempts involving state‑linked actors, spyware vendors and politically motivated individuals.
The incident comes as the company prepares for an initial public offering this fall and as former employees – researcher Jacob Coxon and two ex‑Google scientists – warn that advanced language models could become difficult to control within a decade. Their warnings, amplified by recent resignations and media interviews, have intensified calls for policy measures to address the dual‑use risk of AI.
Anthropic’s latest misuse report, released in October, lists nine notable incidents. The most concrete involved a grant‑writing request aimed at increasing chikungunya’s transmissibility. The model’s response was blocked because it crossed a newly defined “dual‑use” threshold. Earlier models such as Claude Opus 4 and Claude Sonnet 4.5 were deemed insufficiently capable of supporting sophisticated bioweapon work, while newer models – Claude Fable 5 and the Mythos series – include stricter content filters, real‑time monitoring and a detection system that flags attempts to extract capabilities for unauthorized replication.
The report also documents misuse attempts from actors in Russia, Iran, Turkey, the Persian Gulf, South Asia, Africa and Europe. Activities ranged from generating surveillance‑oriented code to producing propaganda. None resulted in a functional biological weapon, but the ability of AI to assist with grant writing, protocol design and data analysis raises a tangible bio‑security concern.
Experts such as incoming UC Berkeley professor Sayash Kapoor suggest a regulatory framework that requires AI developers to conduct dual‑use risk assessments, maintain verifiable audit trails and share threat intelligence with a designated government hub. Kapoor also recommends treating certain AI‑generated content as dual‑use technology under existing bioweapon export‑control conventions.
Anthropic’s response includes tighter internal safeguards and notification of regulators about the blocked chikungunya request. New measures feature dynamic prompt‑blocking, a lower threshold for biological queries and mandatory human review for requests that approach the dual‑use line. Critics note that the detection system relies on pattern‑matching, which could be evaded by rephrasing or indirect language.
The resignations of Coxon and the former Google researchers underscore broader unease within the AI community. Their statements on NBC and BBC frame the issue as a systemic risk rather than an isolated incident, suggesting that self‑regulation may be insufficient.
Anthropic’s upcoming IPO adds a financial dimension to the debate. Investors will weigh the company’s safety record against the prospect of stricter regulations that could raise compliance costs or limit product capabilities. Analysts warn that any legislation targeting AI‑enabled bioweapon research could reshape the competitive landscape, favoring firms with robust safety protocols.
Regulators now face a decision: codify the dual‑use standards Anthropic has introduced voluntarily or impose external oversight. Congressional hearings on AI and bio‑security are slated for early 2027, and their outcome will determine whether the industry can continue to rely on internal safeguards or must submit to formal oversight. Until then, Anthropic’s report provides a rare, documented glimpse of how advanced language models can be misused in the biological domain, moving the abstract fear of AI‑powered bioweapons into a concrete policy arena.