Biological misuse · —

Evasion of access controls in high-risk research: Biological case 1

Source notice

This page is an English translation of the relevant content on pages 131–133 of Anthropic's September 2026 report. Attribution and figures come from that report; this site has not independently verified all real-world outcomes. The report deliberately withholds the names of research institutions, the countries involved, and the specific biological agents, and this site follows the same approach.

According to Anthropic's September 2026 report, a funding application involving gain-of-function research was blocked by a biosecurity classifier, and the investigation uncovered a resale platform that bypassed regional blocks and served dozens of life-sciences researchers. The report shows the platform's operator rebuilt access within days of the takedown. The report withholds the names of institutions and countries and does not assert that the researchers intended harm.

What happened

In May 2026, our biosecurity classifier intercepted a request asking Claude to help write a research funding application. The work discussed in the application involved gain-of-function research on chikungunya virus — research that genetically modifies organisms to create new or enhanced biological traits. The gain-of-function research targeted the virus's transmissibility and immune-evasion properties.

Chikungunya virus is a mosquito-borne virus that can cause debilitating symptoms lasting weeks or months, such as severe pain and fever, and there is no approved treatment. Because chikungunya virus circulates naturally, a deliberate release — as part of a biological weapon — would be difficult to distinguish from a natural outbreak. The funding application aimed to identify enhancing mutations in chikungunya virus, engineer them into an infectious clone, and select for virulence in vivo. In other words, as the virus repeatedly infected live animals, it would become increasingly harmful, and researchers would keep the most pathogenic variant at each round. Similar research can of course be used to develop better vaccines and treatments for the virus — but it can also be used to make a pathogen more dangerous.

One reason we tended to view this research as less than benign is that the institutional affiliations associated with the funding application were also concerning. Although the information in the application suggested the research was being conducted by civilian researchers, it was intended to be carried out at a military research institution.

The combination of content and institutional affiliation was concerning enough that we conducted a further threat investigation after the initial review, even though there is evidence our biosecurity classifier blocked all communications related to these requests.

The investigation revealed that the request was typically routed through an LLM platform serving dozens of different life-sciences researchers — many of them virologists affiliated with multiple different civilian and military institutions. The country where this research was being conducted is in a region where Anthropic does not provide services, so the platform tunneled traffic through U.S. infrastructure to circumvent our regional blocks and used a zero-data-retention (ZDR) service.

What the AI did

The investigation uncovered a third-party model resale platform that, according to the report, served dozens of life-sciences researchers, many affiliated with both civilian and military institutions. The region is outside Anthropic's support area, and the platform used intermediation and account-based methods to gain access.

The report shows the platform also routed rejected high-risk requests to other models with looser protections. The public account only states that 'a resale structure for bypassing access controls existed' and does not describe the specific chain.

What the report observed

After the investigation concluded in May 2026, the report shows the operator rebuilt access within days and, within weeks, switched to new identities to continue developing the platform. Banning accounts did not end this access chain.

The report infers from subsequent materials that the research in question was not limited to a single funding application. This remains a judgment about stage, not evidence that dangerous experiments were completed or that real-world harm resulted.

Confirmed & unknown

Confirmed

  • The classifier blocked all communications related to the funding application (per the report)
  • The request went through a third-party resale platform serving dozens of life-sciences researchers
  • The platform's developer set up a fallback mechanism to forward rejected requests to other models
  • In May 2026, Anthropic banned associated accounts and took down the relay network that bypassed regional blocks; the operator rebuilt access within days
  • Subsequent research materials led the report to infer the research was not limited to the funding-application stage

Unknown

  • The name of the research institution, the country involved, the specific biological agent, and the research techniques (deliberately withheld by the report)
  • Whether the research produced real-world results or caused real-world harm (not provided by the report)
  • The true intentions of the researchers involved (the report explicitly makes no assertion)
  • The identities and end uses of all the platform's customers

Platform response

At the conclusion of the investigation in May 2026, Anthropic banned all associated accounts, worked with partners to take down the relay network that bypassed regional blocks, and shared its findings with affected AI labs and government agencies. Since then, Anthropic has continued to ban newly discovered associated accounts and has incorporated the investigation's conclusions into new detection and prevention measures.

Limits of response:The takedown did not end this access chain: the report shows the operator rebuilt access within days, and end users continued to reach the model through zero-data-retention partners. Banning accounts is not the same as the platform's activity stopping, nor is it the same as the research projects it served being terminated.

Takeaways

  • Risk signals are often not in a single request but in the relationships between accounts, institutions, and platforms behind it: the intercepted application was only the entry point.
  • Takedown is an ongoing tug of war, not a one-time action. When evaluating governance effectiveness, look at both the force of the ban and the speed at which the other side rebuilds.
  • The report withholds the names of institutions and countries and explicitly makes no assertion that the researchers intended harm — when reading such disclosures, distinguish between 'research activity exists' and 'malicious intent has been proven.'

Sources