One of the scenarios that has been described for years as the great nightmare of the age of artificial intelligence now seems to be moving from theory to reality: Attempts are being made to use advanced AI models to develop missiles, drones, bombs, and research that could contribute to the creation of dangerous biological weapons.
Anthropic, the creator of Claude, revealed in a new threat report that it had identified and halted a series of attempts in which users sought to exploit its models for military and potentially biological programs.
Findings reported by the Financial Times and the New York Times show just how rapidly the scope of the threat is expanding: from a group in northern Yemen linked to the Houthis that used Claude to write missile guidance software, to scientists who attempted to use it in research that, under certain conditions, could lead to more potent pathogens.
Anthropic emphasizes that it has no evidence that the biological research programs were necessarily intended for weapons development. However, the fact that some users concealed the true purpose of their research and attempted to circumvent security measures was enough for the company to terminate their access.
“You don’t see someone, like in a comic book, saying, ‘I want to build a biological weapon to kill everyone,’” Jacob Klein, head of Threat Intelligence at Anthropic, told The New York Times. “It’s an incredibly complex situation.”
Claude as a Missile
“Engineer” One of the most concerning cases involves a group operating in northern Yemen. Anthropic has not officially identified it as the Houthis, however, the geographical area is largely under the control of the Iran-backed organization, and, as the New York Times notes, the details of the case point to it.
According to the company, the team was working on three different weapons programs: a ballistic missile, a missile with various variants, and a guided rocket. What is most concerning is that users did not view Claude merely as a tool for searching for information.
They used it, as Anthropic reports, “in place of human software engineers” to develop the weapon guidance, navigation, and control system.
The model was used to integrate open-source autopilot software into a smartphone-level flight computer, to write control and positioning software, to adjust parameters, to produce firmware, and even for flight simulation. In other words, an attempt was made to transform a commercially available artificial intelligence system into a digital partner for a weapons systems development program.
They tested a rocket and then asked the AI why it failed
The project was not limited to theoretical exploration. Anthropic reports that the team conducted a test launch of a guided rocket. The test appears to have failed. Within a few hours, the users turned back to Claude to analyze what had gone wrong and attempt to fix the problems.
The company clarifies that it has no evidence that this specific program resulted in a functional weapon. The fact, however, that artificial intelligence was used in a real-world cycle of design, testing, and correction represents a qualitatively different level of threat.
How the Safety
Measures Were Bypassed Claude’s mechanisms rejected many of the relevant requests, but not all of them. According to Anthropic, users had developed techniques to conceal what they were actually building. They did not reveal the software’s ultimate purpose from the outset and divided the work across many different conversations, so that no single session would reveal the entire plan.
This tactic has also been observed in other cases of Claude’s misuse, which poses a difficult problem for AI companies: a single request may seem completely innocent, but only when combined with dozens of others is the true objective revealed.
An even more alarming issue: biological weapons
. While the use of AI for missiles is cause for concern, the most dangerous part of the report concerns biological research.
Anthropic revealed that over the course of the year, it halted several instances in which scientists were using advanced Claude models for research that could contribute to the development of biological weapons.
Research on viruses and mutations can lead to new vaccines and treatments. However, it can also be used to create more dangerous pathogens.
This is precisely the so-called dual-use problem of modern biotechnology.
Anthropic reports that it was unable to determine with certainty whether the scientists had legitimate or malicious intentions. It chose, however, to suspend the relevant activities due to the potentially catastrophic consequences of a mistake.
The chikungunya
virus experiment One of the most notable cases occurred in May. A scientist asked Claude for help in drafting a research grant proposal on the chikungunya virus, which is transmitted by mosquitoes and can cause severe pain and other serious symptoms for months.
The planned research involved gain-of-function experiments, in which a pathogen is modified to study its mutations and characteristics. Such studies can have entirely legitimate scientific value and lead to the development of vaccines.
In this particular case, however, the scientist sought to create mutations that could make the virus more harmful as it was repeatedly transmitted among animals. Anthropic’s concern grew even greater when it discovered that the research was intended to be conducted at a military research institute.
“What we don’t know is whether the research was intended for military use,” Klein said. “But a military institution conducting gain-of-function research is concerning.”
“Pathogens could be created that we won’t see coming.”
Susan Monarez, a microbiologist and public health expert who had examined U.S. national biosecurity preparedness during the Obama administration, described the findings as a clear indication that malicious actors are already trying to secretly exploit the most advanced models.
As she warned, the very capabilities that can lead to spectacular medical discoveries can simultaneously allow dangerous actors to “hide in plain sight,” using seemingly legitimate scientific research to develop pathogens that may prove extremely difficult to stop once released.
Andrew Weber, former U.S. Under Secretary of Defense for Nuclear, Chemical, and Biological Defense Programs, described the cases “chilling examples” of state-sponsored researchers attempting to exploit the rapidly evolving capabilities of advanced AI models.
According to him, access to systems capable of supporting such advanced biological research should be restricted to absolutely trustworthy scientists.
China, Russia, Yemen, and Weapons
Programs The Anthropic report also includes other instances of Claude’s use for military purposes. Three cases are documented in China, two in Russia, and one in Yemen, in which attempts were made to use the model to develop conventional weapon systems, ranging from artillery and drones to missiles and bombs.
At the same time, the company identified suspicious users linked to China and Iran who were using Claude to monitor dissidents and diaspora communities.
According to the report, Russian state media also exploited the model to produce online propaganda presented as independent journalism, including fabricated claims surrounding the elections in Moldova.
The New Race Among AI
Companies The findings come at a time when leading models are becoming much more capable of performing complex scientific and technical tasks. Anthropic itself notes that earlier versions of its models, when tested last year, were not yet capable of providing meaningful assistance in high-risk biological research.
Today’s models, however, have significantly greater capabilities. This has forced the company to tighten its safeguards for a wide range of dual-use biological research questions. The problem is that defense evolves at the same time as the attack.
The smarter the systems become, the more they can assist scientists, programmers, and engineers. And the more valuable they become to governments, armed groups, or individual users who seek exactly the opposite of what they were designed for.
Even if an account is closed, the knowledge remains
. Anthropic announced that it had banned accounts linked to dangerous activities and shared information with government and private entities. In the case of Yemen, however, it discovered something even more alarming.
The team had already built offline simulation tools that could function without further access to Claude. In other words, when the company shut the door, some of the know-how it had already generated had slipped out of its control.
And this is perhaps the most difficult question raised by the two studies: in an era where an AI model can simultaneously function as a scientific collaborator, a programmer, and an engineer, how easy is it to stop a dangerous use once the necessary knowledge has already been generated?