Funding Neutral 8

35 Flagged Efforts: Dual-Use AI in Gain-of-Function Research

Biotech and pharma stakeholders should note that Anthropic flagged possible gain-of-function research on chikungunya, bird flu, orthopoxviruses, and toxins. The findings intensify dual-use research of concern debate and may affect grant funding and oversight for virology and synthetic biology.

· 4 min read ·

Beat this week

Last 7 days · Funding

1 story
8 avg impact
0% positive
0% negative
vs prior 7 days New New vs empty prior window

Impact not comparable yet. Counts are stories in our record, not a market forecast.

Open the change report
  • 100% neutral

This story sits in Funding — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.

Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.

Biotech briefing

Key takeaways

8 impact
Neutralsentiment
4min read
  1. Biotech and pharma stakeholders should note that Anthropic flagged possible gain-of-function research on chikungunya, bird flu, orthopoxviruses, and toxins.
  2. The findings intensify dual-use research of concern debate and may affect grant funding and oversight for virology and synthetic biology.

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1Anthropic blocked multiple accounts for possible AI-assisted biological weapons development and called biological misuse one of the 'most serious risks' to AI models, in a report published September 10, 2026.
  2. 2Across 30 days of activity, Anthropic identified about 35 'distinct research efforts' with potentially concerning activity.
  3. 3The report details five real-life case studies, including a grant application for gain-of-function research on chikungunya virus transmissibility and immune evasion.
  4. 4Other cases involved bird flu research on mammalian adaptation and severe illness, orthopoxviruses including variola (smallpox) and mpox, and novel venoms and toxins.
  5. 5Anthropic said users 'circumvented controls' that block access from specific regions and 'engaged in other efforts to obfuscate the purpose of their research.'
  6. 6Anthropic said the individuals were 'working scientists' but did not identify institutions or countries, and it could not determine whether actors 'intended harm' or were conducting legitimate research.

Sophisticated attacks no longer require sophisticated attackers. The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators.

Anthropic Biosecurity Report Published report, 2026-09-10

Anthropic's biosecurity misuse report

Real-life case studies of AI-assisted biological research
5 35 distinct efforts flagged in 30 days

Includes chikungunya gain-of-function, bird flu, orthopoxviruses, and venom toxins

Analysis

For biopharma and virology researchers, the Anthropic disclosure hits close to home: case studies include a grant application for gain-of-function chikungunya research and avian influenza studies focused on mammalian adaptation. As dual-use research of concern policy evolves, 35 flagged efforts over 30 days suggest AI tools now surface early in the research pipeline—before IRB, funder, or federal oversight can catch them.

Anthropic moved a serious AI-safety risk from hypothetical to documented reality on September 10, 2026, publishing a biosecurity report stating that it had blocked multiple accounts that used its Claude model in ways that could support development of biological weapons. The company describes biological misuse as one of the most serious risks to AI models. Over a 30-day review period, Anthropic identified about 35 distinct research efforts with potentially concerning activity. It also outlined five real-life case studies in which users circumvented controls meant to block access from specific regions and obfuscated the purpose of their research to evade safeguards. Anthropic was careful not to overstate certainty: it could not determine whether the actors intended harm or were pursuing legitimate scientific purposes, and it characterized the individuals as working scientists without identifying institutions or countries.

For biopharma and virology researchers, the Anthropic disclosure hits close to home: case studies include a grant application for gain-of-function chikungunya research and avian influenza studies focused on mammalian adaptation.

The case studies span dual-use domains that biosecurity experts have long watched. One involved a grant application for gain-of-function research on chikungunya virus transmissibility and immune evasion. Another involved a researcher outside the United States using Claude for bird-flu work focused on viral adaptation to mammals and severe illness. Additional cases covered orthopoxviruses, a group that includes variola virus, which causes smallpox, and mpox, as well as research on novel venoms and toxins. These examples matter because they involve both infectious-disease threats and biotoxins, each with distinct containment, regulatory, and public-health implications. The requests were not simply informational; they extended into formulation of research agendas, grant narratives, and experimental directions that could accelerate dangerous work.

The most striking claim is that AI has collapsed the labor and tooling gap between well-resourced state-sponsored operations and individual actors. Anthropic explicitly states that sophisticated attacks no longer require sophisticated attackers, and that the cybersecurity skills of AI models have changed the threat model. Historically, developing or weaponizing biological agents required tacit knowledge, laboratory access, and specialized training. Large language models may now provide guidance on protocols, troubleshooting, grant writing, and experimental design, reducing some of those barriers. This does not mean a model like Claude can construct a bioweapon on its own, but it can accelerate a determined researcher's progress and lower the expertise threshold for conceptualizing high-risk experiments.

For AI companies, the report is both a warning and a demonstration of active mitigation. Anthropic's monitoring detected and blocked accounts, but the fact that roughly 35 distinct efforts appeared within 30 days suggests continuous pressure rather than rare anomalies. The case studies show actors specifically sought to circumvent regional restrictions and hide research intent, which means basic account controls are insufficient. AI developers will likely need layered defenses: misuse classifiers, behavioral anomaly detection, red-teaming for biological tasks, and scalable human review. At the same time, a major unresolved tension is that legitimate scientific research—such as pandemic preparedness, vaccine development, and venomics—may present patterns that look similar to misuse. Any automated system risks false positives that could chill open science or delay urgent research.

What to Watch

Policymakers and public-health agencies should treat Anthropic's disclosure as an early empirical data point on AI-enabled biosecurity risk. Thirty-five flagged efforts over one month, even if many are benign, provides a measurable baseline that has been missing from policy debates. It also raises questions about whether AI labs should be required to disclose such events to regulators, and whether thresholds should trigger reporting to biodefense or public-health authorities. Anthropic did not identify the countries or institutions involved, but future policy may demand more transparency when potential gain-of-function or pathogen-adaptation work crosses into AI-assisted territory. The report may push governments toward binding requirements for pre-deployment biosecurity evaluations, post-deployment monitoring, and shared threat indicators.

Looking forward, the field should expect more granular misuse reports from major AI labs, along with pressure to publish evaluation benchmarks for biological risk. Anthropic's five case studies are a notable step beyond aggregate statistics, but they are anonymized and selective. The next wave of AI biosecurity policy will likely focus on preventing genuinely dangerous assistance while preserving legitimate research, an operational challenge that will test both model providers and the life sciences community. The ultimate question is whether blocking attempts is enough, or whether the existence of 35 potentially concerning efforts in a single month indicates that dual-use AI capabilities are already being probed at a scale that demands new global guardrails.

Cite This Page

"35 Flagged Efforts: Dual-Use AI in Gain-of-Function Research." Biotech Intelligence Brief, September 11, 2026. https://getbiobrief.com/story/anthropic-dual-use-ai-bioweapon-research

How we covered this story

Every story in our biotech coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the biotech space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.