Vaccine Research or Development of Dangerous Pathogens: The Unseen Intentions Faced by an AI Company

Vaccine Research or Development of Dangerous Pathogens: The Unseen Intentions Faced by an AI Company

"No one says, 'Let's make biological weapons.'"

When it comes to safety measures for generative AI, many people think of "chatbots that refuse dangerous questions." However, the threat intelligence report released by Anthropic in September 2026 revealed a more troublesome reality.

Malicious users may not honestly input their intentions. Especially in life sciences, research that investigates the mechanisms of infectious diseases, develops vaccines and treatments, and makes pathogens more dangerous can share the same terminology, experimental plans, and data analysis up to a certain point. If you isolate a single question, it can appear to be either beneficial research or preparation for weaponization.

Anthropic compiled a 154-page report on the misuse and inappropriate use of AI confirmed between December 2025 and August 2026. The report covers seven areas, including cyberattacks, surveillance, public opinion manipulation, fraud, conventional weapons, and biological misuse. Among these, five cases where the use of Claude was judged to potentially support biological weapon development drew significant attention.

The first thing to note here is that the company has not concluded that it discovered a "biological weapons program." The names of research institutions and countries are withheld, and it does not claim that there was an intention to harm the scientists involved. What was confirmed were multiple warning signs, such as high-risk research content, circumvention of regional restrictions, anonymization, and obfuscation of objectives.


Military Research Institutions and Chikungunya Fever

The most symbolic case is the research grant application targeting the chikungunya fever virus. Chikungunya fever is a mosquito-borne infectious disease that causes fever and severe joint pain, with symptoms that can become prolonged. Since it is a disease that occurs naturally, intentional spread could be difficult to distinguish from natural outbreaks.

According to the report, the application dealt with research that alters properties related to the transmission and immune evasion of the virus. While such knowledge can aid in predicting outbreaks and developing vaccines and treatments, it can also be repurposed to make pathogens more dangerous. Furthermore, the fact that a military research institution was indicated as the research site heightened Anthropic's vigilance.

The usage route was also unusual. It involved using U.S. infrastructure from regions outside the service area, employing systems that leave no data, resellers, and fake accounts. There was even a system in place to redirect questions rejected by Claude to other models with looser restrictions. The company suspended related accounts and worked with stakeholders to cut off the relay network, but operators reportedly resumed connections through alternative routes in a short time.

This case demonstrates that the rejection function of a single model is not sufficient. Even if one company's AI stops it, users can switch between multiple models and change communication routes and accounts. Safety measures must inevitably shift to a system that includes not only question text judgment but also access routes, user affiliations, and continuous behavior patterns.


Avian Influenza, Orthopox, and Toxin Design

The second case involved research on the mammalian adaptation of highly pathogenic avian influenza. Researchers reportedly conducted thousands of interactions over several weeks, using Claude for literature organization, research planning, data analysis, and writing. Anthropic evaluated that access to high-performance models was blocked by a system detecting dangerous content, and the support provided remained mainly administrative and auxiliary.

This is an important caveat. The report does not state that Claude immediately designed unknown pathogens or completed biological weapons. Rather, the "added capabilities" confirmed at this stage were limited. Nonetheless, the fact that experts with potential access to actual research facilities and samples were attempting to use advanced AI by circumventing geographical restrictions anticipates the risks if future models become more advanced.

In the third case, a research grant application for orthopoxviruses, which belong to the same classification group as smallpox and mpox, was quickly assembled by Claude. The research purpose appeared to be in the direction of virus attenuation, so the safety classifier did not stop the response. However, knowledge of immune evasion mechanisms can be used both for attenuation and, conversely, to preserve and enhance those functions.

The remaining two cases involved the design of toxins and toxic peptides. Even if the research claimed to be for drug discovery, such as painkillers or antidepressants, there is a possibility that paralyzing substances could emerge from the same design base. In another case, instructions were given to Claude to keep the identity of the target substance ambiguous in the research report. Here, a system that merely detects dangerous words was hardly effective due to the technical overlap between therapeutic and harmful purposes.


The Real Challenge is "Dual Use"

Biological dual use is not a new issue. Understanding the infectivity, immune evasion, and toxicity of pathogens is essential for public health. At the same time, that knowledge is valuable to attackers. AI did not create this long-standing problem but changed its scale and speed by accelerating literature searches, hypothesis formation, analysis, code creation, and application writing.

Traditionally, advancing cutting-edge research required a team with expertise, long training, and cooperation across multiple fields. As AI approaches being a "universal scientific assistant" that connects these areas, researchers can handle a wide range of domains even with a small team. While this brings significant benefits to drug development and infectious disease control, it increases the number of tasks to monitor and shortens the preparation time for dangerous plans.

Moreover, the cost of misjudgment is asymmetrical. Missing dangerous research can lead to extremely large damages. On the other hand, blocking legitimate research can delay drug discovery and infectious disease control, excluding researchers from specific regions. Leaning towards safety undermines scientific freedom and fairness, while prioritizing freedom increases catastrophic risks. A simple keyword filter cannot provide an answer to this dichotomy.


Three Reactions Reflected on Social Media

On social media immediately after the report's release, at least three reactions were observed. However, these were a small number of posts shortly after publication and cannot be generalized like a public opinion survey.

The first is a strong sense of crisis. If AI can accelerate the planning and grant applications for pathogen research, there is a view that common rules involving governments and research institutions are necessary, not just leaving it to companies. Some posts took seriously the combination of not only biological weapons themselves but also circumvention of regional restrictions, anonymous accounts, and automatic distribution to multiple models.

 

The second is skepticism towards Anthropic's explanation. In related Reddit threads, there were voices sarcastically suggesting that the report might be publicity emphasizing the crisis, and questions about how much factual verification can be done with the company's own investigation. Some suggested that companies disadvantaged in model competition might be using safety as a differentiating factor. Regardless of whether these criticisms are justified, as long as country names, institution names, and verifiable evidence remain undisclosed, the problem of being unable to fully verify from the outside persists.

The third is concern that safety measures lead to increased surveillance. Anthropic argues that providing advanced biological functions requires a system to select trustworthy users, verify accounts and affiliated institutions, and maintain certain usage records. In response, on social media, there were voices raising issues with the normalization of identity verification, pressure on services that do not store data, the structure of private companies reviewing research content, and the lack of means to appeal against misjudgments.

Additionally, some posts speculated about countries and past infection origins not specified in the report. However, Anthropic withheld country names and did not conclude malicious intent. Spreading such speculations as facts can lead to unjust attacks on researchers and geopolitical biases. When reading social media reactions, it is necessary to distinguish between "what the report confirmed" and "what users speculated."


Is Corporate Self-Regulation Enough?

Anthropic's response has certain significance. It blocked dangerous uses, reflected the signs obtained into safety measures, and shared them with governments and other companies. AI companies are in a position to observe new threats early through usage logs and interactions with models, which even government agencies find difficult to grasp.

However, that position also means significant power. It becomes a matter for a single company to decide which researchers to trust, which countries and institutions to open advanced functions to, and where to consider dangerous. There is a need for accountability and remediation procedures in case of misjudgment, third-party audits, confidentiality for researchers, and criteria for reporting to authorities.

Furthermore, if regulations apply only to one company, dangerous users will move to other models or open models. In this report, a mechanism was confirmed where requests rejected by Claude were redirected to other models. What is needed is not reliance on the "conscience" of specific companies, but cross-industry sharing of signs, identity and affiliation verification according to risk levels, independent audits, and connections with international export controls and research ethics.

On the other hand, overly broad prohibitions can backfire. If legitimate researchers are driven to closed routes and move away from safe commercial services, the potential for monitoring decreases. Low-risk research should be widely accessible, while high-risk tasks should be limited to vetted researchers, with the ability to appeal decisions—such a phased access approach is realistic.


"Not an Immediate Catastrophe," but "Early Warning of Capability Enhancement"

Reading these five cases as evidence that AI can already create biological weapons is not accurate. Anthropic itself states that these are not evidence of imminent biological threats created by Claude. Many of the confirmed supports were limited to tasks like document editing and information organization.

Nevertheless, the report is significant because it shows that highly skilled experts attempting to use advanced AI exist in reality, and markets and technologies to circumvent regional restrictions and safety features are already beginning to take shape. As models approach expert levels, the impact of the same usage patterns will grow.

The issue is not whether AI has malice. It is a question of institutional design: who stops it at what stage when humans hiding malice, scientific knowledge usable for both good and evil, cross-border access means, and competing AI companies come together.

AI can become a powerful tool for advancing life sciences. To protect that potential, mechanisms to detect dangerous uses are necessary. However, if left solely to the secret judgments of companies, transparency and trust will be lost. Between full openness and total prohibition, can we build an access management system that is verifiable, allows for appeals, and is internationally coordinated? The report by Anthropic highlights not only the fear of technology but also the fact that society has yet to fully design its boundaries.


Source URL