We're publishing our most detailed threat intelligence report to date.
It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them.
We disrupted every operation in the report, and used the lessons from them to strengthen our safeguards. Where appropriate, we also shared what we found with authorities and other AI companies.
These cases are not typical: we’re highlighting some of the most sophisticated misuse we’ve seen. But they’re especially important to discuss, because they show us where AI misuse is headed, where our safeguards work, and where they need to improve.
We’re publishing this report so others can spot the same activity on their own platforms, and so we can give the public a clearer view of how emerging threats develop.
Read the report: https://t.co/0EJUnYEgfz
Remember the name. Primecare Vet/Pet Hospital at Bellandur. Bastards were catching street dogs, breaking their legs and then practising surgery. This was done, since one must evidently be a total scumbag, without anaesthesia. https://t.co/v0MPbqNErD
I thought I had filled my SIR form carefully but I got a call from my BLO on Sep 8 saying I’ve got a notice. The BLO said my father’s details are not furnished acc. to their previous SIR. She doesn’t know how this happened even though my SIR form has the details of my father.
Dear @DrAMSinghvi Mecca Defense Alliance is a good & sensible organisation - first of its kind on the concept of collective security. Do find time to watch some of my videos. Thank you!
Some thoughts about the Anthropic report and the accompanying NYT piece on detecting nefarious biological applications of Anthropic's AI. Firstly, I am glad that they wrote this; describing how people might be potentially using your tech for doing bad things even as you are planning an IPO takes some courage. It's the responsible thing to do. That being said, here's my take:
One thing that bothers me about a lot of discussion around AI-enabled biological risk is the way the argument quickly moves through several very different layers and claims as though they were equivalent. The problem is that non-specialists especially can move through this chain very quickly to support unsubstantiated conclusions.
The chain roughly is: AI can do impressive biological reasoning and design, THEREFORE AI can substantially enable dangerous wet-lab biology, THEREFORE catastrophic biological attacks become much more likely.
But those are not the same proposition, and they hide a lot of devil-in-details subtleties. First of all, we must acknowledge that the evidence for the first is increasingly strong. AI systems can reason about biology, analyze sequences, propose protein and gene designs, generate hypotheses, suggest experiments, and in some cases outperform experts on computational tasks. As a computational scientist I myself do this all the time. There is no doubt at this point that AI gives you access to an incredible amount of compressed and potentially actionable information.
But the jump from that to real-world biological capability is much larger than it is often made to sound. A computationally plausible sequence is not a functioning phenotype. A functioning construct is not a robust organism. A robust organism is not necessarily stable, producible, transmissible, deliverable, or effective in the real world. Those of us who have worked in computational chemistry or biology for a long time know how riddled with false positives and negatives and plausible-but-wrong conclusions the results of these investigations are and how much work it takes to substantiate or falsify ideas. Getting an experiment to work on a small scale in biology is hard enough; scaling the experiment and make it robust and impervious to multiple external confounders is extremely difficult. The problem is not a lack of models, it's simply what we don't know. The value of ignorance in biology cannot be underestimated.
Especially in biology, the downstream steps are often where most of the science lives. This is why I think many biological AI-risk case studies have a structural problem. They often provide evidence for one or two links in a long causal chain - usually a combination of literature searching, hypothesis generation and computational design - and then hand-wavingly invite the reader to fill in the gaps and emotionally supply the rest. I say "emotionally" because that is in fact how lay readers will react to articles like the one in the NYT about Anthropic's report.
If we were to sketch the actual chain of biological discovery, it's more like:
Intent ---> access---> useful AI reasoning and hypothesis generation ---> successful design ---> successful experimental realization (including multiple independent runs with controls and confounders) ---> robust phenotype ---> scaled production ---> dissemination ---> consequential exposure.
This chain exists for both a cancer drug and toxin; it's just how science works. Showing that AI improves one or two of those steps does not establish that the entire chain has suddenly become easy. And yet the rhetoric frequently conflates multiple steps, as if the unmeasured gaps have already disappeared.
There is another important distinction here: capability versus qualitative improvement. The relevant question is not simply, “Can an AI system provide useful biological information?” Of course it can. The question is: how much does AI increase a person’s real-world ability to do something dangerous beyond what was already possible using PubMed, textbooks, protocols, databases, software, collaborators, and the Internet? If AI enables someone to accomplish in six weeks what they would have accomplished in six months, that's an impressive demonstration of AI acceleration, but by itself it does not make AI qualitatively more enabled to cause harm. Proving whether AI really takes the capability to the next level is a much harder empirical question, and one whose answer we frankly don't yet know. As mentioned earlier, there is now good evidence that AI can produce a meaningful and impressive signal on computational biology tasks. But evidence that this computational enhancement translates into comparable uplift across the physical bottlenecks required for serious biological misuse is still much thinner.
There is also a profound asymmetry here that deserves much more attention. Anthropic’s own researchers have acknowledged that, in many biological interactions, they could not reliably determine whether the user’s ultimate purpose is beneficial or malicious. That means the base rates are heavily skewed toward researchers doing important benign research. The overwhelming majority of people asking about proteins, mutations, viral biology, immune evasion, delivery, stability, expression, or experimental optimization are trying to do useful science, not build biological weapons. So a safety system designed around ambiguous capabilities rather than demonstrated malicious intent will inevitably face a false-positive problem. And because legitimate biological research is vastly more common than malicious biological research, even a seemingly “accurate” classifier can block far more beneficial work than harmful work.
When you cannot reliably infer intent, the burden of broad restrictions disproportionately falls on the enormous population of scientists, engineers, physicians, students, and companies trying to use the same capabilities for beneficial purposes. A false negative might enable misuse, but millions of false positives will quietly but insidiously suppress scientific progress much more than they will quell misuse. When this suppression translates to missed drugs for cancer, missed antibodies against immune disorders, missed cures for rare disease, the cost is very real and very significant.
None of this means biological risk from AI should be ignored. I am not saying nobody in the near future would ever be able to produce a reasonably potent virus or toxin substantially aided by AI. Precaution is reasonable, and genuinely dangerous capabilities should absolutely be evaluated. We have had preparedness and response frameworks for chemical and biological risk for a long time, and AI does not change the necessity for having them. But precautionary reasoning or preparedness should not be confused with evidence that a catastrophic capability already exists, nor does it give us license to amplify a low-probability, (relatively) low-impact scenario into a mass casualty event.
As a minor but important point, we should therefore make sure that certain words don't automatically translate into other words that are unsubstantiated. “Cannot rule out” is not the same as “has been demonstrated.” And “AI helped with biological design” is not the same as “AI erased the gap between biological knowledge and reliable biological weaponization.”
If we want a serious discussion of AI biological risk, we should estimate the whole causal chain rather than demonstrate the first few links and let fear fill in the rest. Otherwise we will cause panic, fear-mongering and greater public reluctance to adopt this technology, and instead of minimizing harm, all we will end up doing is to apply a blunt tool to a subtle problem and minimize the enormous good that AI can do.
https://t.co/0kKPYgyKxk
https://t.co/g2tFT2ijao
@ramez@p_maverick_b@SynBio1@baym@OmicsOmicsBlog@anshulkundaje@Noahpinion
Nothing disgusting and shameful about it. When building societies refuse to give flats to non-vegetarians, that is shameful. When there are no non-veg restaurants between Walkeshwar and Marine Drive in Mumbai, save maybe one, then that is surprising.
You eat what you want; we eat what we want.
I can see the backlash building, esp in Maharashtra and the South where there are sizeable gujju communities.
Their apartheid behaviour provokes. Bigotry and insularity provokes. Public vulgarity provokes. Giving Gujarat sports/cultural priority provokes
This will not end well
Wait, the EC decided who forms Govt in Maharashtra, Bihar & Bengal.
Henceforth, it will also decide who forms govt at Center.
Can't it decide the legality of a few structures ?
"A Bench of Justices Anil Kshetarpal and Shail Jain passed the interim order on petitions raising concerns about fraudulent GST registrations that are taken using stolen or frozen PAN card and Aadhaar details of unassuming citizens, to swindle money"
Just speechless.