Anthropic published its third misuse report on Thursday, September 10, covering threat activity its researchers found between December 2025 and August 2026. Most of the report is the expected inventory of internet bad behavior at a larger scale: spyware vendors, politically motivated individuals, state-sponsored groups running propaganda.

One section is different, and one sentence in it is the reason this story matters.

The Request That Was Blocked

Among the findings were unnamed actors attempting to use Anthropic's models for research that could have led to biological weapons. In one instance, the company said its systems blocked a request for Claude's assistance in authoring a grant application for scientific funding.

Per the report, as reported by the Associated Press: "The work discussed in the application involved gain-of-function research (that is, research that genetically alters an organism to create a new or enhanced biological property) on the chikungunya virus. This gain of function research was aimed at the virus' transmissibility and immune evasion properties."

Two terms are doing the work there. Transmissibility is how easily a virus spreads between hosts. Immune evasion is how well it slips past the defenses a body has already built — from a past infection or a vaccine. Research aimed at increasing both, in the same organism, is the specific category that biosecurity policy has argued about for over a decade.

Chikungunya is a mosquito-borne virus that causes debilitating symptoms including severe pain and fever. AP reports the grant proposal sought to enhance mutations to make the virus progressively more harmful.

Why This Is Hard Rather Than Simply Alarming

Anthropic's own framing is the most useful thing in the report, because it declines the simple version. Such research, the company said, could "certainly" be used to develop better vaccines and treatments — and "it could also be used to make the pathogen more dangerous."

Both halves of that sentence are true, and they describe the same experiment.

This is what "dual-use" means in practice. You cannot separate the knowledge of how a virus becomes more transmissible from the knowledge of how to block it. Legitimate vaccine development depends on understanding exactly the properties that would also make a pathogen worse. Real virologists, at real institutions, with real oversight, do versions of this work.

Which is why the blocked grant application is not, by itself, evidence of a bioweapons program. It is evidence that an AI system was asked a question it could not safely distinguish from a legitimate one.

The Sentence That Actually Matters

Anthropic said none of the cases in its report involved its newer, more powerful Claude Fable or Mythos-class models — with one exception, an illicit distillation case the company described as "an industrial-scale, covert campaign to extract a model's capabilities and replicate them in another model without authorization."

Then it explained why its older models had lighter protections. Claude Opus 4 and Claude Sonnet 4.5, both from 2025, "were well below the threshold where they could meaningfully assist a sophisticated user in carrying out dangerous biological research." So, the report says, "safeguards on these models were less stringent, directed mostly at preventing access to content that might uplift novices in recreating known bioweapons."

And then: "But for today's models — which are capable of assisting in a range of complex scientific research tasks — the evidence is no longer certain, and we cannot make that same assurance."

Sit with what that concedes. The old safety story was: a trained expert gets nothing useful from the model, so we only need to stop beginners. That story has been retired. The company is stating on the record that it can no longer promise its current systems are incapable of meaningfully helping someone who already knows what they're doing.

Anthropic says it has responded by applying "stronger safeguards that restrict access to a wide range of dual-use biological research queries" in more recent models, such as Claude Fable 5.

Who Decides?

This is where a technical report becomes a governance problem.

John Thickstun, an assistant professor of computer science at Cornell University, told AP that it is an uncomfortable position for companies like Anthropic and OpenAI to be in when they are expected to determine what is safe versus unsafe behavior and make "value judgments at societal scale without any kind of democratic or deliberative oversight."

That is the whole issue in one sentence. Right now, a private company is the entity deciding which biological questions get answered — by criteria it authored, enforced by systems it operates, reviewed by nobody outside it. When it blocks a legitimate researcher, no appeal exists. When it allows something it shouldn't, no external body finds out unless the company publishes a report like this one.

Voluntary disclosure is meaningfully better than silence. It is not the same thing as accountability, and Anthropic is not claiming it is.

The Rest of the Report

Two other findings are worth noting.

Influence operations at scale. Anthropic found groups that created hundreds of social media accounts designed to look like ordinary people, then posted material amplifying a single political view over the course of a week. The company outlined nine such cases, originating in Russia, Iran, Turkey, and across the Persian Gulf, South Asia, Africa, and Europe. Its stated advantage over platform-side detection: while social media companies can detect an operation once posts are circulating, "we may see it on Claude while the operation is still being built."

The timing. The report landed two days after Anthropic researcher Jacob Coxon resigned publicly, saying the company and OpenAI "are racing straight to self-improving superintelligence and gambling with our lives." Anthropic's report is not a response to him — these take months to assemble — but the two documents describe the same tension from opposite sides of the wall.

Anthropic says it blocked each of the malicious activities it identified, used the experience to strengthen safeguards, and shared information with government authorities and industry partners. In the report's words: "We hope that the findings in this report will help other developers recognize similar patterns on their own platforms, give governments and civil society a clearer view of how emerging threats take shape, and strengthen collective defenses."

What to Take From This

A blocked request is a system working, not a system failing. The safeguards caught it. That is the reported outcome, and it deserves to be stated plainly before anything else.

The capability admission is the news. Everything else in this report describes people misbehaving, which is constant. The novel fact is a frontier lab formally withdrawing a safety assurance about its own product because the product got better.

Dual-use isn't solvable by filtering. There is no phrasing that separates "help me make a safer vaccine" from "help me make a worse virus" at the level of the question. Any system that blocks the second will sometimes block the first, and any system that permits the first will sometimes permit the second. That tradeoff is now being tuned by companies.

For parents and teachers: this story has no household implications and needs none. It is not about chatbots your child uses, and there is no consumer safety action here. It matters because it's a concrete, documented example of the thing AI policy debates are usually abstract about — a capability threshold being crossed, noticed, and disclosed. That is worth understanding as a citizen. It changes nothing about screen time.

Want practical AI guidance for parents and educators every week? Subscribe: https://www.aibyage.com/?modal=signup&utm_source=beehiiv&utm_medium=newsletter