Dual use in biology: how to discuss risks without writing a how-to
Definition
This topic discusses AI used in biological research scenarios that may have both legitimate scientific value and misuse potential. The report focuses on access controls, safety classifiers, and trusted-user mechanisms.
Applications, research plans, model-generated text, actual experiments, and real-world harm are not on the same level.
Not to be confused with
Not an already-occurred biological weapons attack. Most cases in the report are applications, planning, or access issues.
Not that all life sciences research is misuse.
Not a place where we discuss sequences, formulations, experimental procedures, or enhancement pathways.
AI roles
AI mainly appears in writing applications, planning research, and attempting to bypass access controls. In some cases, stronger models' safeguards limited the help provided.
The real governance challenge is intent recognition: when a topic looks like legitimate research, models struggle to judge by keywords alone.
According to Anthropic's September 2026 report, a funding application involving gain-of-function research was blocked by a biosecurity classifier, and the investigation uncovered a resale platform that bypassed regional blocks and served dozens of life-sciences researchers. The report shows the platform's operator rebuilt access within days of the takedown. The report withholds the names of institutions and countries and does not assert that the researchers intended harm.
According to the report, in May 2026 a researcher outside the United States was found using Claude in research related to highly pathogenic avian influenza, focusing on the virus's adaptation to mammals and the mechanisms of severe disease. The relevant influenza variants have pandemic potential and are themselves legitimate subjects of scientific research. The report notes the work was at an early planning stage, and the protections of stronger models limited the help that could be provided. The report does not indicate that a biological weapon was completed.
According to the report, an account wrote an orthopoxvirus research funding application for a state-linked infectious disease laboratory. Orthopoxviruses include the smallpox pathogen variola virus and Mpox, which caused a global outbreak in 2022. The account was a resale relay serving more than a dozen unrelated clients, exchanging tens of thousands of messages with Claude over a few days. The research is dual-use in nature, and Claude provided information, so it was not blocked by the classifier.
According to the report, two researchers used Claude to study venoms and toxins — compounds that can be developed into painkillers and antidepressants, but could also be used as incapacitating agents. The research had clear therapeutic goals, but the output included scaffolds for both therapeutic and paralytic targets. The report notes that classifiers cannot simultaneously enable beneficial use and prevent harm because user intent cannot be reliably identified in high-tech dual-use fields.
Limits of response
The report deliberately omits institutions, countries, and specific biological agents. Secondary interpretation must follow the same restrictions.
This chapter requires biosecurity expert review; fluent native language cannot substitute for professional judgment. The public version of this site applies the highest level of omission.
Is the report saying someone has already built a biological weapon?
No. Qualifiers from the original text such as 'early planning,' 'applications,' and 'safeguards limited the help' are retained as stated in the report.
Why is this chapter so short?
Because safety boundaries take priority over length. Details with no additional explanatory value are omitted entirely.