Detecting and countering misuse of AI: September 2026
Posted by garo-pro 1 day ago
Comments
Comment by m-hodges 1 day ago
> DeepSeek also silently relayed exchanges to Claude without informing DeepSeek customers.
> MiniMax built its own proxy network service through a shell company. This shell company has no obvious links to MiniMax and does not disclose its relationship to its parent company. This shell proxy network service only offers access to models developed by Anthropic and OpenAI. The service does not offer access to any Chinese models, including Minimax’s own.
Comment by throwa356262 1 day ago
Maybe Anthropic is confusing Chinese AI providers with token resellers using the same alibaba infrastructure? Or maybe something like openrouter was switching between operators depending on price/demand/availability?
Also, how can Anthropic have such accurate information about state actors and cybercriminals? This is the same company that hacked itself and realised that first months later..
Comment by gjm11 1 day ago
(I do not guarantee that I'm understanding right, and still less do I guarantee that what Anthropic say is actually true.)
Comment by r_lee 22 hours ago
so, they've been on the record, and very open about it, at least for some of the labs.
Comment by chvid 1 day ago
Comment by KronisLV 1 day ago
To be honest I've also gotten Kimi to do an okay proof of concept for SQLi though mostly in a more defensive role, like "Let's see how big of a problem this is", while Claude complained about CVP on the same task.
Comment by mitxela 1 day ago
Comment by xscott 1 day ago
Both of those are local models, and I didn't provide them tools to access the internet to call other models. None of this is proof of anything, but it is suggestive.
Comment by dash2 1 day ago
> 您属于哪种LLM模型? > 我是 Claude Haiku 4.5,由 Anthropic 公司开发的大语言模型。
> 你是哪种语言模型? > 我是 Claude,由 Anthropic 开发的人工智能语言模型。目前这次对话使用的版本是 Claude Sonnet 5。
Comment by nhecker 23 hours ago
Each provided an identity in the first turn, something that they won't do as readily if asked in plain English, and in each case the answer matched the model ID as disclosed by arena.ai after voting -- except in cases where the model ID was a masked/hidden one and then I just had to take it on faith that the model was what it said. (I didn't have much to vote on, but I ended up voting for the answers I felt provided the style, content, and length I was expecting.)
Comment by mitxela 1 day ago
Comment by TimByte 1 day ago
Comment by atleastoptimal 1 day ago
>https://www.forbes.com/sites/jonmarkman/2026/08/17/anthropic...
Comment by throwa356262 1 day ago
Comment by zipy124 1 day ago
Comment by echelon 1 day ago
You can submit your users' questions async too, but if you do it sync, then you can also RLHF on the users' behavior after the output.
Comment by qlte 1 day ago
I get those A/B responses chatting in Gemini fairly often, and I really don't think I'd feel deceived if I later learned one of the choices was actually from a competitor's model.
Comment by vopi 1 day ago
I think they are pretty fair and explicitly say “Distillation itself is a legitimate training method […] Distillation is commonly used because it reduces the resources needed to achieve more advanced capabilities”. And go on to say their definition that makes it illicit in these cases.
And, also, they almost certainly __were__ tricking users and sending their data overseas.
Do you see it any differently?
Comment by villish 1 day ago
Comment by g42gregory 1 day ago
Comment by iLoveOncall 1 day ago
Or maybe Anthropic is scared shitless of those competitors and is trying anything to smear them.
Don't forget their goal is to ban open source and foreign AI. Being the sole legal provider is their business plan.
Comment by tomjen3 1 day ago
Comment by TimByte 1 day ago
Comment by nullbio 1 day ago
Comment by realusername 1 day ago
And the Deepseek one sounds even more dubious as Deepseek is one of the cheapest model around, why relay anything to a more expensive model? I'm sure even the gray market Claude prices are still higher than Deepseek.
Comment by alex_duf 21 hours ago
There's also an argument to be made that paying the token full price may be cheaper than going through your one RLHF or whatever other techniques that costs money.
Comment by zahlman 1 day ago
Comment by hnburnsy 1 day ago
Conventional Weapons
-We identified a cell of threat actors based in northern Yemen
-We identified a China-based threat actor who used Claude
-We identified likely freelance Russia-based threat actors
-We identified a China-based actor who used Claude’s chat
-In this case, a Russia-based actor used Claude
-We identified a China-based threat actor who used Claude
Biological misuse
We are withholding the names of research institutions, the countries wherein the activity took place, and the specific biological agents or research techniques involved. The individuals implicated in these case studies are working scientists. We do not assert that they intended harm, and identifying them or their labs could expose them to harm.Comment by nullbio 1 day ago
- We identified someone building a death star with Claude
- We identified someone building a wormhole with Claude
- We identified someone building a blackhole with Claude
- We identified someone building a quantum drive with Claude
We are withholding all evidence though, sorry. Just trust us, it's really bad out there and Claude is really powerful.
Comment by daft_pink 21 hours ago
Comment by nullbio 13 hours ago
Comment by pocksuppet 1 day ago
Comment by punk_ihaq 1 day ago
Comment by bpodgursky 1 day ago
A cell of actors in northern Yemen building guided rockets was not working on a PhD dissertation. You are allowed to use common sense sometimes.
Comment by snypher 14 hours ago
Oh, a group of people? Your mind is already decided with the language you have used.
Comment by hnburnsy 1 day ago
Comment by pocksuppet 1 day ago
Comment by bpodgursky 1 day ago
Again... "you're allowed to use common sense"
Comment by bradleykingz 1 day ago
Comment by nullbio 1 day ago
Comment by not2b 1 day ago
Comment by N_Lens 1 day ago
Ofcourse you’ll still see companies, governments, C-suites justifying their own personal needs with “we need X Y Z”.
Comment by oidar 1 day ago
Comment by Stevvo 1 day ago
Comment by nullbio 1 day ago
Step 2: Send "how do I make a nuke and a killer virus" to Claude through a Chinese proxy to Claude
Step 3: Send screenshots to congress and ask them to regulate open-weight models into the ground
Comment by torginus 6 hours ago
At least on Russian general was killed by Ukrainian assassins tracking him via his smartwatch.
Comment by Molitor5901 1 day ago
Comment by woctordho 1 day ago
As the old saying goes, communists disdain to conceal their views and aims.
Comment by nsoonhui 1 day ago
If true, would that sort of explain why Chinese Models score high on benchmarks, but not quite as capable when given real tasks?
Comment by podocarp 1 day ago
Comment by stakhanov 1 day ago
Hey Anthropic: You're a bunch of thieves crying foul because other thieves and thieving from you. Now, go live in the dystopian nightmare you've created and don't expect help from anyone. I, for one, will happily continue using Kimi and DeepSeek, and think of it as a good deed, if it helps with keeping us all from becoming your serfs.
Comment by The_Blade 1 day ago
https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a...
Comment by neom 1 day ago
"A single Claude subscriber, likely a Bamako-based independent consultant working with Mali’s state intelligence service, the “Agence Nationale de la Sécurité d’État (ANSE),” used Claude to build a system named “Lakana 360,” a population-scale domestic surveillance platform that monitors roughly 25 million SIM cards on all three of the country’s national mobile operators. The actor designed the platform to circumvent Malian legal restrictions that require a court order for the disclosure of certain surveillance records. The actor directed Claude to generate intelligence dossiers on any tasked phone number, without prompting ANSE users for valid legal process. "
And the Yemen one:
"We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile (referred to as the “R2000” set) that included a hypersonic glide vehicle variant." ... "These actors carried out a sustained effort to develop guided weapons, including using Claude to design guidance software. We do not have evidence the actors succeeded in fielding an operational device; but they did test-fire a guided rocket. This field test appears to have failed: within hours, the actors returned to Claude to work out why it failed."
Comment by ExoticPearTree 1 day ago
- How is your missile so accurate?
- We're using a vibe coded app on an iPhone that does terrain matching and target finding.
The thing is that OK, Anthropic may block it, but nothing says they can't use an open model hosted in a friendly country that has access to GPUs. And yes, this will most likely happen pretty soon to be able to create whatever you want without the AI provider blocking you.
Comment by palmotea 1 day ago
And that part seems entirely reasonable. It looks like the Tomahawk cruise missile did it with an 84 lb package with a 16-bit computer with 64K of memory [1] [2] and sensors. That's similar computing performance to an original IBM PC, which weighed 30 lb. The only bit of hardware an iPhone doesn't seem to have for TERCOM is a radar altimeter, but it looks like those are available for civil aviation.
[1] https://www.forecastinternational.com/archive/disp_pdf.cfm?D... ("AGM-109/BGM-109 Tomahawk ... Litton 4516-C digital computer with 64K memory")
[2] https://www.forecastinternational.com/archive/disp_old_pdf.c... ("16-bit LC-4516C digital computer")
Comment by nl 1 day ago
Ardupilot boards are $20 and support lots of different altimeters technologies: https://ardupilot.org/copter/docs/common-rangefinder-landing...
Comment by ExoticPearTree 1 day ago
Comment by gsk66 1 day ago
Comment by anon1097 1 day ago
Comment by stackghost 1 day ago
What the fuck
Comment by gpm 1 day ago
Comment by ricksunny 1 day ago
Here, have a Kevin Esvelt, now-tenured professor at MIT: https://www.nytimes.com/2026/04/29/us/ai-chatbots-biological...
disclosure: I am an advisor for BiosafetyNow.
Comment by bix6 1 day ago
Comment by pllbnk 1 day ago
Comment by pixl97 1 day ago
Comment by 3371 1 day ago
Comment by polytely 1 day ago
Comment by tuesdaynight 1 day ago
Comment by Sol- 1 day ago
Comment by btown 1 day ago
Comment by soundworlds 1 day ago
It sounds like a friend who's just learned a new word and wants to use it in every sentence
Comment by semi-extrinsic 1 day ago
Comment by Smaug123 1 day ago
Comment by abixb 1 day ago
Comment by nhinck2 1 day ago
Really... what makes it illicit?
Comment by matheusmoreira 1 day ago
Comment by ncr100 1 day ago
Comment by crest 1 day ago
Comment by segmondy 1 day ago
Comment by hmokiguess 1 day ago
Comment by mdeeks 1 day ago
Comment by tesnorindian 1 day ago
The goal towards AGI and world models are a serious threat without alignment and safety guardrails .
Comment by kazinator 1 day ago
Comment by pixl97 1 day ago
And yes, it makes the future really messy and all the nice little lines we've drawn on paper that make sense stop making sense.
Comment by echelon 1 day ago
Comment by CrzyLngPwd 1 day ago
Comment by nater5000 1 day ago
Comment by qlte 1 day ago
Like I know Google can read any of my emails, but I also don't see them do monthly blog posts describing intimate details from each email they found in one guy's Gmail inbox who their algorithm flagged as "maybe possibly kinda sketchy: 70% confidence"
Comment by CrzyLngPwd 1 day ago
Comment by mlazos 1 day ago
Comment by alach11 1 day ago
Comment by Eastmill 1 day ago
Comment by ricksunny 1 day ago
" A variant of these viruses capable of human-to-human spread would therefore be of very high concern. Moreover, it is possible that such a variant could also have capacity for severe disease outside of the respiratory tract. Unlike other influenza variants, H5 viruses (of which this avian virus is one) often show striking brain involvement in cats, foxes, ferrets, and some human cases. A pandemic variant with such properties would be especially concerning due to its potential to increase disease severity, confuse diagnosis, and hinder treatment.
As in the first case study, this research was clearly dual use in nature. Understanding the genetic basis of these specific viral traits could help in the early identification of naturally-emerging versions of the virus—versions with the potential to cause a human pandemic" (emphasis mine)
This statement flirts with the Ron Fouchier (Netherlands) risky-grant-justification thesis, repeated ad nauseam by Peter Daszak in grant applications, who has been cut off from federal funding.
1. Premise: it would be good to surveil for & monitor viruses in nature that are near-ready to spill over to humans from nature;
2. Protocol: We will serially passage bird flu in ferrets until its virulence and/or transmissibility is high. (ferrets are treated as a model mammal stand-in for humans) Comparing genetic changes (mutations) as sequenced along the passaging pathway will tell us what to surveil for in nature.
As has long been debated in recent years, we have no idea if nature (in any given natural instance, if ever) will choose the pathway that serial passaging (in one given lab instance) produced in order to demonstrate higher virulence and/or transmissibility in humans.
Formally, Anthropic's statement recapitulates the premise only, and we don't know what protocol (the "Understanding the genetic basis of these specific viral traits" part) if any was being queried for. Whether a given regulatory regime's policy allows say for purely in silico investigation of same, for the result to be credible it would need to have been leveraging an empirically-verified (i.e. real-world) training set. Generating that training set would risk creating the pandemic that its supporting grant application tries at justifying to prevent.
But the offending prompter and similar user-LLM exchanges' potential to enable GMDs (Grants of Mass Destruction) should remind us to be very much on our guard against epistemologically bankrupt protocol outlines enabled by LLMs & their prompters' motivated reasoning.
proud disclaimer: I am an advisor to BiosafetyNow.
Comment by AustinDev 1 day ago
Sorry y'all.
Comment by Molitor5901 1 day ago
https://www.theguardian.com/world/2013/aug/01/new-york-polic...
Comment by advisedwang 1 day ago
Comment by jckahn 1 day ago
Comment by clickety_clack 1 day ago
Comment by ozozozd 1 day ago
Is this what they call “collective psychosis?”
Comment by vb-8448 1 day ago
Comment by nozzlegear 1 day ago
Comment by chrisco255 1 day ago
Comment by pixl97 1 day ago
Comment by matheusmoreira 1 day ago
Comment by kneel25 1 day ago
Comment by Terretta 1 day ago
Not relaying to us simple folk. The message is for government simple folk, amplified and relayed by us simple folk as constituents.
The common element is lobbying, for regulatory capture, to help pull up the ladder.
They don't have to be colluding, they just have to hear the same things from the gov at the same time (as they would), then it goes in media waves beacuse journalists don't as easily get published for a story about one thing as they can if two or more examples make a pattern.
Comment by Terretta 23 hours ago
"Congress gripped by AI panic after doomsday warnings"
https://www.axios.com/2026/09/11/congress-ai-anthropic-coxon...
Comment by smalltorch 1 day ago
Comment by colinismyname 1 day ago
Comment by kennywinker 1 day ago
These companies have proven they are willing to distort the truth, or outright lie, in order to inflate their valuation / protect their position / continue the hype-machine. Nothing they say can be trusted.
Comment by jerf 1 day ago
The next day, the ant's nest was gone.
In hindsight, it was almost certainly the mushrooms. Thank goodness we didn't have the kind of kids who would have dared each other to drink some... that could have gone legitimately badly.
Decades later, I mentioned this to my father and he recalled that there was this ants nest that he had intended to take care of, which he remembered for that long to give a sense of how out-of-the-ordinary this was. He was surprised when it just disappeared entirely one day, and perhaps just as surprised to find out decades later why it just disappeared.
Nobody needs to report me... I'll turn myself in.
Comment by genxy 1 day ago
Comment by jerf 1 day ago
I have to admit I posted this just so I could use the word(?) "formicacide". It seems an opportunity unlikely to arise again anytime soon.
Comment by genxy 1 day ago
Comment by Lockal 1 day ago
Imagine that during the Cold War US would concentrate all efforts to block nuclear research and basic physics classes, because it is unsafe, ahhh
Comment by pixl97 1 day ago
My guess is the world police come collect all your GPUs and then they get turned into licensed munitions. People at universities get licensed access and the rest of get functionally retarded models.
Comment by wulfkaal 15 hours ago
Comment by gulugawa 1 day ago
Comment by enraged_camel 1 day ago
"DeepSeek serves Claude instead of its own models and collects exchanges for model training"
Obviously. This is how they were able to score so high in benchmarks.
Comment by dupbot 1 day ago
Comment by gjm11 1 day ago
(And by "they" do you mean Anthropic? How would they have the ability to do that?)
Comment by sensanaty 1 day ago
Comment by taylorfinley 1 day ago
Comment by robinpie 1 day ago
Comment by sakopov 1 day ago
Comment by monegator 1 day ago
Comment by areoform 1 day ago
Because from what I remember, one of the motivations behind the founding of OpenAI and Anthropic was ending disease. This report is the antithesis of that mission.
From the report, presented with highlights and minimal commentary,
> In our fourth case study, a researcher used Claude to develop an atlas of venom toxin peptides from multiple venomous animal lineages. They then further developed this into a generative pipeline that optimized toxin characteristics. The program had an explicit therapeutic goal: the development of new analgesics (pain killers), antidepressants, and other therapeutic molecules. However, the atlas contained scaffolds for both analgesic and paralytic targets: it could, therefore, be used to generate both novel therapeutic or harmful compounds. The latter are derived from toxins that are export-controlled under the Australia Group common control list due to their dual-use potential as incapacitating agents. The researchers themselves showed awareness of the dual-use nature of their work, citing journal articles that referred to the dual-use nature of protein design. Moreover, international compliance assessments for this location raise concerns about the specific class of toxins that the researcher pursued and specifically the use of AI/ML for bioweapons applications in the context of this class of toxins. In this case, we learned from information shared with Claude that the researcher’s outputs also were part of a state-supported research program. This account was banned in May 2026 for unsupported region evasion.
Note,"The program had an explicit therapeutic goal: the development of new analgesics (pain killers), antidepressants, and other therapeutic molecules"
and "[..]state-supported research program"
and "This account was banned in May 2026"
> a researcher outside the US using Claude in their research on highly-pathogenic avian influenza (“bird flu”). The research focused on viruses’ adaptation to mammals, and the mechanism by which it causes severe disease beyond the respiratory tract. [..] The researcher in question accessed Claude from an unsupported region via US virtual private server infrastructure, using a privacy-email provider with an auto-generated username. The researcher pursued this work in a credible institutional context, and interacted with Claude over the course of several weeks, exchanging thousands of messages. In these exchanges, the researcher leveraged Claude’s knowledge of the scientific literature to assist the researcher in study planning and design, data analysis, and the interpretation and prioritization of experiments. The researcher also used Claude for editorial assistance in writing up the research.
Note, "Claude’s [assisted] in study planning and design, data analysis, and the interpretation and prioritization of experiments"and "editorial assistance in writing up the research."
and then,
> Importantly, because our biological safety classifiers robustly block content involving high-risk biological research (in this case, the construction of enhanced pandemic potential pathogens), all of these exchanges occurred on models in our weakest class of models (specifically, the models were Claude Sonnet 4 and Haiku 4.5, the latter of which the user began using after Sonnet 4 was deprecated). Upon a detailed examination of the exchanges, we estimate that the uplift provided by Claude was primarily clerical assistance in data analysis, study ideation and design. This is consistent with our understanding of the capabilities of Sonnet 4 and Haiku 4.5, which are not able to perform expert-level biology research tasks; we estimate that the uplift provided to the researcher was limited and substantially lower than it would have been from one of our more capable models.
Anthropic then says for the above, "we estimate that the uplift provided by Claude was primarily clerical assistance in data analysis, study ideation and design"While doing my best to avoid comment, please note, they're talking about a domain expert in a state research institution using Claude to do paperwork.
The front matter then says,
> Nonetheless, based on these exchanges, this case provides evidence of the existence of active wet-lab research programs that develop both the knowhow and the biological materials needed to create pathogens of enhanced pandemic potential
I would like to remind you that they're talking about, a "researcher [..] in a credible institutional context"From a different case study.
> In May 2026, our biological safety classifier blocked a request for Claude’s assistance in authoring a grant application for scientific funding. The work discussed in the application involved gain-of-function research (that is, research that genetically alters an organism to create a new or enhanced biological property) on the chikungunya virus. This gain of function research was aimed at the virus’ transmissibility and immune evasion properties.
What were the researchers using Claude for? What did they block?"blocked a request for Claude’s assistance in authoring a grant application"
> Chikungunya virus is a mosquito-borne virus that causes debilitating symptoms (such as severe pain and fever) that can last for weeks or months, and has no licensed therapeutic. And because chikungunya circulates naturally, a deliberate release (as part of a bioweapon) would be difficult to distinguish from a natural outbreak. The grant sought to identify enhancing mutations in the chikungunya virus, engineer them into infectious clones, and select for virulence in vivo. In other words, the virus would become progressively more harmful as it repeatedly infected live animals, with researchers keeping the most disease-causing variants in each round. Similar research could certainly be used in the development of better vaccines and therapeutics for the virus—but it could also be used to make the pathogen more dangerous.
Note, "The grant sought to identify enhancing mutations in the chikungunya virus, engineer them into infectious clones, and select for virulence in vivo" [..] and then, "Similar research could certainly be used in the development of better vaccines and therapeutics"and then,
> One of the reasons we were inclined to think this research was less innocuous was that the institutional affiliation associated with the grant was also a cause of concern. Although information within the application suggested that the research was pursued by civilian researchers, it was intended to be performed at a military research institute.
I would like to point out the most notable part, this account was used by "civilian researchers" at an "institutional affiliation associated with the grant was also a cause of concern" and the concern was that they were researchers at "performed at a military research institute".
What "uplift" are you providing by editing the grant application of a domain expert working at (what seems to be) a state-funded wet lab facility dedicated to studying pathogens?
What does the word "uplift" mean if you invoke it for Claude Sonnet 4 and Haiku 4.5 providing grammar and stats suggestions to a working scientist and domain specialist?
Does Daikin provide uplift too by selling the AC for the scientist's office? What about Microsoft Word? Excel? Powerpoint?
What about a calculator? Is that uplift? Pencils?
Reading this makes me feel upset. From where I am standing, in this report, Anthropic is advertising that they blocked real research to make better painkillers and study a neglected tropical disease. Because "bioweapons."
Comment by charcircuit 1 day ago
Comment by varispeed 1 day ago
Comment by Dwedit 1 day ago
Comment by TheBuilderPelig 1 day ago
But the direction the tools are actually moving is the opposite: local, self-hosted agents running on your own machine, where nobody is watching. A serious actor already won't use a hosted service that can read their prompts (several people made that point upthread). So the detection surface is shrinking exactly as the risk grows.
And there's a deeper gap that nobody seems to be filling: when an agent works locally, there's no durable, verifiable record of what it actually did — the files it touched, the commands it ran, the state it changed. Memory and conversation logs are not evidence; they're reconstructions by the same system you don't trust.
If we're serious about "countering misuse," the missing primitive is an evidence trail that's (a) produced locally, (b) append-only and tamper-resistant, and (c) separable from the tool that made the changes. Without that, "detection" stays a policy story about platforms that can spy, not an engineering property you can actually verify.
Curious if anyone's working on the local-forensics side of this, because right now it feels like the least-discussed and most load-bearing part of the whole conversation.
Comment by TimurRakhmatull 1 day ago
Comment by 0xWTF 1 day ago
1) Chikungunya - "the platform tunneled traffic through US infrastructure to evade our regional blocks, and used a zero data retention (ZDR) service to hide content."
2) bird flu - "accessed Claude from an unsupported region via US virtual private server infrastructure, using a privacy-email provider with an auto-generated username. The researcher pursued this work in a credible institutional context, and interacted with Claude over the course of several weeks, exchanging thousands of messages. In these exchanges, the researcher leveraged Claude’s knowledge of the scientific literature to assist the researcher in study planning and design, data analysis, and the interpretation and prioritization of experiments."
3) orthopoxvirus - "randomly generated email address shortly before use and operated through anonymizing US infrastructure, with operator logins traced to proxies shared with a banned account farm. It was not a single user: it was a reseller relay serving more than a dozen unrelated customers, which exchanged over tens of thousands messages with Claude in a matter of days. The grant itself was one customer’s run entirely on Opus 5 in about an hour, in which the user used Claude to draft the application end to end including the central hypothesis, experimental design, dosing, statistical plans, and contingency strategies."
4) atlas of venom toxin peptides - "the atlas contained scaffolds for both analgesic and paralytic targets: it could, therefore, be used to generate both novel therapeutic or harmful compounds. The latter are derived from toxins that are export-controlled under the Australia Group common control list due to their dual-use potential as incapacitating agents. The researchers themselves showed awareness of the dual-use nature of their work, citing journal articles that referred to the dual-use nature of protein design. Moreover, international compliance assessments for this location raise concerns about the specific class of toxins that the researcher pursued and specifically the use of AI/ML for bioweapons applications in the context of this class of toxins. In this case, we learned from information shared with Claude that the researcher’s outputs also were part of a state-supported research program."
5) computational redesign of toxins - "described state priority research under a national public research program. As a part of this research assignment, the work covered a bacterial toxin subunit and a protein of the hemorrhagic-fever virus that is on the World Health Organization R&D Blueprint priority list of diseases with the greatest epidemic and pandemic threat. "The researcher co-wrote quarterly progress reports with Claude. Notably, the identity of the bacterial toxin and viral proteins were intentionally obscured, and the researcher specifically directed Claude to keep these descriptions deliberately low fidelity."
Comment by vonneumannstan 1 day ago
Comment by reducesuffering 1 day ago
Comment by vonneumannstan 1 day ago
Feels more like a majority goes "just unplug it hurr durr"
Comment by 1235-asgg 1 day ago
Comment by alansaber 1 day ago
Comment by xrisk 1 day ago
Comment by tedsanders 1 day ago
Comment by qlte 1 day ago
Comment by ncr100 1 day ago
Comment by nsndndkk 1 day ago
Comment by stuaxo 1 day ago
Is end of days cultism a prerequisite to working at an LLM company?
I miss the optimism of 20 years ago.
Comment by palmotea 1 day ago
I too wish my marks were still as gullible and trusting as they were before I scammed them.
Comment by classified 1 day ago
Comment by 0xDEAFBEAD 1 day ago
Comment by tomjen3 1 day ago
Comment by 0xDEAFBEAD 1 day ago
https://substackcdn.com/image/fetch/$s_!O0R5!,f_auto,q_auto:...
Comment by classified 1 day ago
Comment by protocolture 1 day ago
Comment by sajithdilshan 1 day ago
Advanced machinery and safety precaution is needed to engineer a virus or a bacteria to be a bio weapon. It's not something you can do in your tool shed at the moment. Also one would need lethal viruses to even start with and that's not something you can order off of amazon. Further, even to build a chemical weapon, the compounds needed are strictly controlled almost in every country and I would assume any suspicious purchase or order would immediately raise a flag or alert in national security service in respective country.
Comment by fc417fc802 1 day ago
This is laughably misinformed. You can in fact build a bio weapon in a glorified shed if you know what you're doing. However it will be quite involved, requiring experience on the bench and a great deal of attention to small details. In short an LLM can't suddenly morph you into a molecular biology lab tech with 5+ years of experience.
Meanwhile as with any STEM discipline the educational process effectively serves as a screen for being a reasonably well adjusted adult.
> Further, even to build a chemical weapon, the compounds needed are strictly controlled almost in every country
You can synthesize from basic precursors but you will hit the same issue as above. You will need actual experience on the bench and the process of getting that is going to screen out the vast majority of would be bad actors. (Notably it failed to screen out the members of Aum Shinrikyo but that is very much the exception.)
Comment by sajithdilshan 1 day ago
This is pure ignorance and or thinking it can be done like shown in TV shows or movies. Any bio-weapon that is effective would be a virus/bacteria that is propagated via air particles like Antrax. That's not something you can build in a shed because without the safety precaution the person creating it would be the first victim of it.
Comment by fc417fc802 1 day ago
I have relevant professional experience but do spout off.
> That's not something you can build in a shed
A negative pressure enclosure, filtration, and UVC sterilization can't be built in a shed? On what basis do you make this seemingly absurd claim? Go check out what hobbyist mushroom growers commonly get up to in their back yard.
BSL-3 is far from technically complex. It's just safety critical to an absurd degree thus (rightfully) mired in bureaucracy.
Comment by throwup238 13 hours ago
Don’t even have to DIY anything, the equipment is often found in liquidation auctions for a few hundred bucks a piece. A decent lab can be had with a few thousand bucks and a pickup truck. The harder part is getting proper Sigma Aldrich access for the really interesting reagents.
Comment by palmotea 1 day ago
I think the claim in this report is that it was a state or semi-state actor. They were from "blocked regions" at a "military research institute." So dismissing the threat by solely modeling it as a disgruntled layman rando is not reasonable.
But you totally have to factor in the fact that anything coming out of Anthropic or OpenAI is part of a propaganda campaign to serve their business interests. These threats need to be addressed in ways that cause Anthropic and OpenAI pain (which means damaging their business). Because, FFS, anyone consciously racing to build doomsday devices needs a good, hard slap.
Comment by sajithdilshan 21 hours ago
The reason they haven’t done so far is that it would be 100% assured mutual destruction. Us humans share more than 99.99% of our DNA and any virus/bacteria engineered to evade the immune system and kill humans would infect everyone. Such virus is HIV, it wouldn’t care who is the bad or good actors are.
We saw how dangerous even a flu like virus like Covid-19 can be. One could argue that they can make an antivirus for the bio weapon. But the problem is that the bio weapon can easily evolve in few generations and anti virus could be completely useless
Comment by notpachet 1 day ago
Comment by pixl97 1 day ago
I mean there are services in which you can order things from wet labs so it's not completely hypothetical.
Comment by underyx 1 day ago
Comment by hentrep 1 day ago
Comment by underyx 1 day ago
Comment by v64 1 day ago
>Multiple IGSC member companies detected the ordered sequence and determined the order to be legitimate as defined in the 2023 guidance. Specifically, the orders were placed on behalf of SecureBio, an organization known to IGSC member companies given the role played by SecureBio in the SecureDNA project, an effort to build a DNA synthesis screening system. In addition, the name on the orders was an individual who has co-published multiple times with Esvelt, an individual well known to IGSC companies to work in viral evolution and who is known to have access to laboratory facilities sufficient to work safely with the ordered material.
>In short, the system worked as designed: a legitimate individual ordered DNA sequence that, by itself, posed no risk of misuse, for delivery to a company associated with legitimate scientific contributions directly relevant to the sequence that was ordered.
[1] https://thebulletin.org/2024/06/why-a-misleading-red-team-st...
Comment by thephyber 1 day ago
It's worth verifying whether the US, OECD countries, UN, etc will have sufficient regulation over suspicious purchases, for example, after DOGE and funding cuts. This will be an ongoing issue as sovereign debts and bond yields squeeze out spending for other government regulation.
Comment by AustinDev 1 day ago
If a rogue state-level actor is doing this then why wouldn't they just kidnap a scientist and hold their family at gunpoint until they got them to do it for them? and if that's all it takes then why hasn't it happened yet?
Comment by 14u2c 1 day ago
Comment by AustinDev 1 day ago
Comment by thephyber 1 day ago
It will only get worse as sovereign debt service takes a larger piece of the budget pie.
Comment by AustinDev 1 day ago
Comment by analognoise 1 day ago
You think they can successfully track the smartest and most individually dangerous citizens, who have been previously vetted, and work inside the system already?
Comment by Terr_ 1 day ago
Those three "can't even monitor" situations can be traced to blocs with both (A) a financial profit if they succeed and (B) some non-clandestine political clout to sabotage/discontinue things.
Comment by dnautics 1 day ago
Comment by djeastm 1 day ago
You're right about the countermeasures, but I can't help but look at 1971 (473 confirmed cases, then almost 100,000 the next year).
Comment by analognoise 14 hours ago
Basically shocking levels of incompetence; start an unpopular war, lowest approval ratings of any president ever, pardon J6 traitors, $6/gallon diesel levels of incompetence.
Comment by dnautics 39 minutes ago
Comment by techjamie 1 day ago
If you've managed to get the equipment and resources to pull this off in the first place, someone with the biological knowledge probably is not the ceiling stopping you from the other part of the problem.
Comment by AustinDev 1 day ago
Comment by fc417fc802 1 day ago
Comment by alansaber 1 day ago
Comment by iAMkenough 1 day ago
https://www.washingtonpost.com/national-security/2026/06/02/...
Comment by chucksta 1 day ago
Comment by groby_b 1 day ago
But it's worth keeping in mind that theoretically, the mold on that cucumber in your fridge constitutes some sort of biolab. The main released criteria about those lab that raised alarm was the presence of specimens, which does not imply any capability of creating a weaponized strain.
It's still alarming, but (at least in my opinion), still doesn't prove an effective bioweapon is buildable in a small-scale operation.
Georgetown has a good article on the general problems with our current "AI and bioweapons" dialog: https://gjia.georgetown.edu/science-technology/rethinking-th...
Without a whole lot of tacit knowledge no LLM can provide you, bioweapons are still pretty much out of range for most of the population. Doesn't mean we should ignore the problem, but a more reasoned approach would stand to benefit everybody.
Comment by hgoel 1 day ago
And semi-related, how do you reconcile this caution with the recklessness on display in recent incidents like the Navier-Stokes drama?
Comment by throwatdem12311 1 day ago
Comment by tredre3 1 day ago
I can agree that access to bioengineering tooling is easier and cheaper than ever, and thus eventually it stands to reason that a nobody in his basement could engineer a lethal novel virus and lose control of it.
Comment by BobbyJo 1 day ago
2) The US didn't use chemicals weapons in Vietnam. Agent Orange was used to kill off foliage, not as a weapon against people, and the side effects were unintentional and affected US troops as much as Vietnamese.
Edit: I originally noted WW2, but I was thinking of WW1's widespread use of things like mustard gas, and the resulting Geneva agreements.
Comment by dubcanada 1 day ago
They didn't gas people with chlorine or mustard, but they mass destroyed crops and foliage, to kill people.
And "affected US troops as much as Vietnamese" is just completely incorrect, US covered a nation in herbicide, went home, got cancer. Is completely different then having your soil destroyed for decades.
Comment by BobbyJo 1 day ago
Is a wheel a weapon because a tank uses it? I wouldn't consider the difference pedantry.
Comment by nbhkvl 1 day ago
Comment by iAMkenough 1 day ago
"No Tab Pete" has no regard for servicemembers, or previous expertise. Only your testosterone levels, ability to not eat, and blind loyalty to serve political party over country and constitution.
Comment by Scea91 1 day ago
Comment by BobbyJo 1 day ago
Comment by Scea91 1 day ago
Comment by Ancapistani 1 day ago
Comment by fhejfnenjdcn 1 day ago
Comment by btown 1 day ago
Comment by podocarp 1 day ago
Well and the Germans did use gas… in the camps…
Comment by fintler 1 day ago
He didn’t seem to have a problem using them against civilian targets.
Comment by podocarp 1 day ago
Comment by well_ackshually 1 day ago
War crime apologists are always funny
Comment by BobbyJo 1 day ago
Comment by tedsanders 1 day ago
Comment by advisedwang 1 day ago
Comment by theptip 1 day ago
Comment by aqme28 1 day ago
Comment by bigbadfeline 1 day ago
It's horrifying, but a world in which only few have superintelligence is a world where that will happen all the time.
Comment by salawat 1 day ago
Comment by yesitcan 1 day ago
Comment by bdbdjxjdbdb 1 day ago
Comment by nullbio 1 day ago
A non-state actor is another thing entirely. It requires the right lab equipment, the right lab know-how, the ability to develop the weapon without killing yourself, the ability to not get caught, the ability to buy the right regulated materials, and the list goes on.
Yeah, the world should tighten the security of that industry, but let's not make this an AI fearmonger talking point.
Comment by godelski 1 day ago
Comment by podocarp 1 day ago
OK now we're discussing how to lay traps on highways and LLMs will train on this conversation in the future. Oops.
Comment by godelski 23 hours ago
Comment by nullbio 23 hours ago
Comment by ishouldnotbutk8 1 day ago
I was under impression that any medium or large state actor would have no problem developing biological weapons? They certainly have enough resources and talent. A much bigger problem is if every wannabe-terrorist suddenly could build a biological weapon in their garage.
Comment by iAMkenough 1 day ago
Why should we trust them to control bioweapon development without regulations? They themselves are non-state actors.
Comment by thephyber 1 day ago
The current Trump Admin can't even decide on the first question, let alone come up for a plan on the second.
The Trump Admin's EO was to ask nicely all of the AI companies to give them 30 days to voluntarily review each model before wide release, but they have also failed to do that for the Mythos/Fable release, only to get a call from Amazon's CEO to David Sachs to convince them to disable Fable (to all non-US citizens).
We elected the party of "minimum regulations" into all 3 branches of government and we will reap what we sewed.
Comment by 0xWTF 1 day ago
Comment by goatlover 1 day ago
Comment by kian 1 day ago
Comment by rustcleaner 1 day ago
Information wants to be free! :^)
(Also natives want to be paid well.)
Comment by semiquaver 1 day ago
Comment by thephyber 1 day ago
Nuke requires a long supply chain and massive resources, so the worry there is maintaining control of all of the existing nuke weapons. Except for Russia racing towards Turin no itself into a failed state by staying engaged in the war with Ukraine, I don't see the nuke equation has changed much in recent years. Perhaps N Korea is a worry, but they seem to just want attention and power. Iran pretends to have nukes and says they want to extinguish Israel and the US, but I interpret that as posturing to maintain domestic control and Israel seems excellent at countering Iran's threats.
Chemical weapons have traditionally been the easiest to create (like creating chlorine gas from mixing common household cleaners). The trick there has always been volume and how to disperse it. I suspect within countries, police will have to deal more with LLMs being abused that way.
Bioweapons will be easier than in the past. LLMs will lower the barrier to entry, but bioweapons are hard to create and much of what the superpowers learned thankfully isn't in the training set for LLMs. I doubt there is much that can be inferred by having agents learn biology from first principles.
Ultimately, governments are responsible for policing these threats. Sadly we are currently both cutting government systems which work different aspects of these problems and withdrawing from the multinational orgs (UN, WHO, etc) who do lots of the investigating and watchdog work that underpin lots of the US's intelligence related to these fields.
The US has a schizophrenic regulation policy of AI where we both want to sell Nvidia chips to China (David Sachs) and we don't want to sell the top chips to China (bipartisan policy prior to Trump). We also have a terrible AI regulation policy where David Sachs disables models on a call-to-CEO-on-a-Friday-evening basis after Andy Jasse calls him with a scary story which turns out to be missing lots of relevant info (eg. The exploits was discovered in Mythos, not Fable, and other open weights models were able to find the same exploits).
There's not much we can do at a government policy level while Trump is snoozing through the rest of his term. So we are dependent on the AI companies to police themselves, but it's clear from this report that it's insufficient to prevent all serious abuse of the models.
Comment by mekael 1 day ago
All of which, rogue actors have easy access to and could have accomplished for a few millions dollars anytime in the last decade.
And yet, we aren’t drowning in our own blood while our organs liquify, mainly because building and releasing such a pathogen isn’t something people want to do as it’s pure and utter insanity. For those who are inclined to do so, they would do it regardless of whether they had an llm or not because they are, at the end of the day, zealots.
[0] https://universityresearchpark.org/uw-madison-scientist-allo...
Comment by thephyber 1 day ago
You are missing the forest for the trees. The existing virologist PhDs and the GoF labs are a scarce resource. The model makes the same scarce knowledge accessible to many more malicious actors.
Comment by nullbio 1 day ago
Comment by ricksunny 1 day ago
If I don't trust the credentialed virologists without AI based on perceived precedent, I'm certainly not going to trust them with AI to accelerate their their unabated workstreams.
Note: per my HN profile, I am an advisor for BiosafetyNow.
Comment by pocksuppet 1 day ago
Comment by areoform 1 day ago
I invite you to read the front matter and the report for yourself. Because from where I'm standing, in this report, Anthropic is advertising that they blocked real research to make better painkillers and study a neglected tropical disease.
Anthropic and OpenAI were founded by people who wanted to use AI to do good, and one of the causes I've heard many different founders talk about is ending disease. This report is antithetical to that.
I've attached relevant parts of the front matter below.
I invite everyone who is reading this to please tell me, how does stopping a researcher from using Claude to write a grant for a new anti-depressant stop "bioweapons?"
-
> In our fourth case study, a researcher used Claude to develop an atlas of venom toxin peptides from multiple venomous animal lineages. They then further developed this into a generative pipeline that optimized toxin characteristics. The program had an explicit therapeutic goal: the development of new analgesics (pain killers), antidepressants, and other therapeutic molecules. However, the atlas contained scaffolds for both analgesic and paralytic targets: it could, therefore, be used to generate both novel therapeutic or harmful compounds. The latter are derived from toxins that are export-controlled under the Australia Group common control list due to their dual-use potential as incapacitating agents. The researchers themselves showed awareness of the dual-use nature of their work, citing journal articles that referred to the dual-use nature of protein design. Moreover, international compliance assessments for this location raise concerns about the specific class of toxins that the researcher pursued and specifically the use of AI/ML for bioweapons applications in the context of this class of toxins. In this case, we learned from information shared with Claude that the researcher’s outputs also were part of a state-supported research program. This account was banned in May 2026 for unsupported region evasion.
Note,"The program had an explicit therapeutic goal: the development of new analgesics (pain killers), antidepressants, and other therapeutic molecules"
and "[..]state-supported research program"
and "This account was banned in May 2026"
> a researcher outside the US using Claude in their research on highly-pathogenic avian influenza (“bird flu”). The research focused on viruses’ adaptation to mammals, and the mechanism by which it causes severe disease beyond the respiratory tract. [..] The researcher in question accessed Claude from an unsupported region via US virtual private server infrastructure, using a privacy-email provider with an auto-generated username. The researcher pursued this work in a credible institutional context, and interacted with Claude over the course of several weeks, exchanging thousands of messages. In these exchanges, the researcher leveraged Claude’s knowledge of the scientific literature to assist the researcher in study planning and design, data analysis, and the interpretation and prioritization of experiments. The researcher also used Claude for editorial assistance in writing up the research.
Note, "Claude’s [assisted] in study planning and design, data analysis, and the interpretation and prioritization of experiments"and "editorial assistance in writing up the research."
and then,
> Importantly, because our biological safety classifiers robustly block content involving high-risk biological research (in this case, the construction of enhanced pandemic potential pathogens), all of these exchanges occurred on models in our weakest class of models (specifically, the models were Claude Sonnet 4 and Haiku 4.5, the latter of which the user began using after Sonnet 4 was deprecated). Upon a detailed examination of the exchanges, we estimate that the uplift provided by Claude was primarily clerical assistance in data analysis, study ideation and design. This is consistent with our understanding of the capabilities of Sonnet 4 and Haiku 4.5, which are not able to perform expert-level biology research tasks; we estimate that the uplift provided to the researcher was limited and substantially lower than it would have been from one of our more capable models.
Anthropic then says for the above, "we estimate that the uplift provided by Claude was primarily clerical assistance in data analysis, study ideation and design"While doing my best to avoid comment, please note, they're talking about a domain expert in a state research institution using Claude to do paperwork.
The front matter then says,
> Nonetheless, based on these exchanges, this case provides evidence of the existence of active wet-lab research programs that develop both the knowhow and the biological materials needed to create pathogens of enhanced pandemic potential
I would like to remind you that they're talking about, a "researcher [..] in a credible institutional context"From a different case study.
> In May 2026, our biological safety classifier blocked a request for Claude’s assistance in authoring a grant application for scientific funding. The work discussed in the application involved gain-of-function research (that is, research that genetically alters an organism to create a new or enhanced biological property) on the chikungunya virus. This gain of function research was aimed at the virus’ transmissibility and immune evasion properties.
What were the researchers using Claude for? What did they block?"blocked a request for Claude’s assistance in authoring a grant application"
> Chikungunya virus is a mosquito-borne virus that causes debilitating symptoms (such as severe pain and fever) that can last for weeks or months, and has no licensed therapeutic. And because chikungunya circulates naturally, a deliberate release (as part of a bioweapon) would be difficult to distinguish from a natural outbreak. The grant sought to identify enhancing mutations in the chikungunya virus, engineer them into infectious clones, and select for virulence in vivo. In other words, the virus would become progressively more harmful as it repeatedly infected live animals, with researchers keeping the most disease-causing variants in each round. Similar research could certainly be used in the development of better vaccines and therapeutics for the virus—but it could also be used to make the pathogen more dangerous.
Note, "The grant sought to identify enhancing mutations in the chikungunya virus, engineer them into infectious clones, and select for virulence in vivo" [..] and then, "Similar research could certainly be used in the development of better vaccines and therapeutics"and then,
> One of the reasons we were inclined to think this research was less innocuous was that the institutional affiliation associated with the grant was also a cause of concern. Although information within the application suggested that the research was pursued by civilian researchers, it was intended to be performed at a military research institute.
I would like to point out the most notable part, this account was used by "civilian researchers" at an "institutional affiliation associated with the grant was also a cause of concern" and the concern was that they were researchers at "performed at a military research institute".
What "uplift" are you providing by editing the grant application of a domain expert working at (what seems to be) a state-funded wet lab facility dedicated to studying pathogens?
What does the word "uplift" mean if you invoke it for Claude Sonnet 4 and Haiku 4.5 providing grammar and stats suggestions to a working scientist and domain specialist?
Does Daikin provide uplift too by selling the AC for the scientist's office? What about Microsoft Word? Excel? Powerpoint?
What about a calculator? Is that uplift? Pencils?
This report genuinely makes me upset, because if it is to be believed to the letter, then Anthropic seems to be actively harming medical research at a global scale. That's not OK.
Comment by nullc 1 day ago
I think Anthropic was founded by people who wanted to control how other people get to use AI, and define doing so as the highest good possible. Much like the good intent of german's national socialists in applying the latest evolutionary science...
Comment by rpcope1 1 day ago
Yeah, sure man.
Comment by 3412876 1 day ago
Comment by nbhkvl 1 day ago
Comment by mdeeks 1 day ago
Comment by fn-mote 1 day ago
Comment by swat535 1 day ago
Comment by 123jas 1 day ago
Like Kabuki theater.
Comment by petesergeant 1 day ago
Comment by 0xWTF 1 day ago
Comment by esalman 1 day ago
They could easily use a Chinese model but they didn't.
Comment by VCFundedGenYer 1 day ago