Anthropic & Claude

Avian flu, chikungunya, drone swarms: the weapons chapter of Anthropic's report

2 min read AI-generated

Five case studies of biological misuse, plus kamikaze drones and missile software. Anthropic banned the accounts and admits it does not know what the people behind them intended.

Featured image for "Avian flu, chikungunya, drone swarms: the weapons chapter of Anthropic's report"

When Anthropic published its threat report on Thursday, the cyber chapter got the attention. The Financial Times and Bloomberg have since spent time with the chapter next to it: weapons. It reads differently.

Five biology cases

Anthropic describes five case studies in which users circumvented controls and obfuscated what their requests were actually for. The users sat in countries Anthropic does not allow access from in the first place: Russia, China, Iran.

In one case a researcher in an unsupported region spent weeks planning avian influenza experiments. Safety filters pushed that work down onto the weakest models. Another involved an enhanced version of the chikungunya virus. State-sponsored virologists got help writing grant applications for military research.

Anthropic then says the uncomfortable part itself: it does not know whether these people meant harm. Planning a pandemic and developing a vaccine require much of the same information.

Drones and missiles

Next to biology sits the conventional chapter. Russian users with no visible state affiliation worked on software for autonomous kamikaze drone swarms, trained on footage from the war in Ukraine. Houthi-controlled actors in Yemen used Claude for missile software - Anthropic found no evidence any of it became a working device.

Every account involved has been banned. The report names no institutions and no countries where the incidents took place. And Fable and Mythos appear in none of these cases; throughout, it was the smaller models.

Why this one stuck with me

Anthropic says it wants these examples to start a conversation, in the industry and with governments. That sounds like PR, and here it is the more honest half: the company is admitting its filters were worked around five times, and publishing the cases along with the admission.

What stays with me is the ambiguity. In the cyber chapter you can say an attack is an attack. In biology you cannot. The same question about avian flu can come from a lab trying to stop an outbreak or from one planning one. A filter cannot tell those apart. An originating IP address can do a bit better, and in these five cases that is what it came down to.

Sources:

AnthropicSicherheitClaudeMissbrauch