Anthropic says several researchers tried to bypass Claude’s safeguards while pursuing biology work that could contribute to biological weapons. In a new threat report, the company describes five cases involving efforts to obscure a project’s purpose or circumvent controls, including users in regions where Anthropic does not offer access.

One case involved weeks of planning experiments related to avian influenza. Anthropic says its filters limited that user to weaker models, and it eventually banned the accounts discussed in the report. The company did not identify the institutions or countries involved.

The central difficulty is that dangerous and legitimate biological research can require much of the same information. Anthropic explicitly says it could not determine that the researchers intended harm; work relevant to a weapon might also be useful in developing a vaccine. That overlap makes simple topic-based blocking an incomplete defense.

The disclosures are company case studies rather than an independent audit, so they do not establish how often controls succeed or fail across all usage. They do show why AI providers are moving beyond prompt filters toward account monitoring and investigation. Anthropic published the examples to encourage coordination between governments and the AI industry on emerging biological risks.