Technology

State-Backed Actors Bypassed AI Borders to Probe Pathogen Data

Anthropic Tightens Biological Safeguards After Pathogen Queries

WASHINGTON — Cloud-based artificial intelligence has become a critical national security challenge after disclosures that suspected state-sponsored actors bypassed regional blocks to query advanced models about sensitive biological agents. Reports released by San Francisco-based artificial intelligence safety developer Anthropic described how actors in restricted jurisdictions used anonymization techniques to access the company’s Claude model.

Anthropic’s Supported Regions Policy blocks users in China, Russia, Iran, and North Korea. Yet between November 2025 and September 2026, security teams identified approximately 35 distinct attempts by suspected state-funded researchers to conceal their locations and the underlying intent of their inquiries.

The activity centered on anonymization tools intended to defeat IP-based and regional geofencing. After entering the system, the users sought information from Claude about high-consequence pathogens and toxins. Anthropic had terminated the identified accounts by May 2026.

Some flagged inquiries concerned the chikungunya virus, including genetic modification and transmission dynamics, with a focus on gain-of-function research related to immune evasion. Other accounts sought methods for adapting avian influenza, or bird flu, to cause severe infection in mammalian hosts.

The cases also involved orthopoxviruses, a genus of DNA viruses that includes variola, the causative agent of smallpox, and mpox. Lethal neurotoxins such as botulinum toxin were among the other subjects identified by Anthropic’s safety protocols.

In the life sciences, this work falls under Dual Use Research of Concern (DURC). Researchers regularly conduct such inquiries to develop vaccines, therapeutic countermeasures, and diagnostic tools, creating a difficult distinction between a legitimate immunologist researching a vaccine and a hostile actor seeking to weaponize a pathogen.

Anthropic said its safety triggers were activated not only by the content of the questions but also by coordinated efforts to obscure users’ identities and regional origins. The overlap between beneficial scientific research and possible misuse has made automated detection exceptionally challenging, while the incidents have renewed debate over dual-use technologies and the effectiveness of software-based geofencing for sensitive scientific data.

The company responded by overhauling its model safety architecture and adding more stringent biological safeguards to its latest releases, most notably “Claude Fable 5.” The updated protocols place restrictive filters on queries involving high-risk biological agents and limit the depth of actionable scientific information the model will provide, regardless of a user’s apparent geographic location or intent.

Biological security risks linked to large language models (LLMs) have also drawn scrutiny from U.S. policymakers. Executive Order 14110 on Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, issued in late 2023, required federal agencies to assess whether frontier AI models could lower the technical barriers to acquiring or synthesizing chemical, biological, radiological, or nuclear (CBRN) threats.

Industry experts have cautioned that LLMs do not currently provide step-by-step instructions for manufacturing biological weapons that cannot already be found in academic literature. Their ability to synthesize complex protocols and help troubleshoot laboratory procedures, however, poses a unique regulatory challenge.

Anthropic’s disclosures described continued efforts by state-sponsored entities to use frontier models to advance their technological and biological capabilities despite international sanctions and export controls.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *