The Morning Jolt

National Security & Defense

The Emergence of AI-Designed Viruses

(metamorworks/Getty Images)

On the menu today: Just because the New York Jets are undefeated doesn’t mean all is right with the world. It seems the whole political and economic chattering class is worried about artificial intelligence, and in particular, departing and current employees’ warnings about a small but real risk of an apocalypse. Rich Lowry warns, “Any deal with the Chinese to slow down research couldn’t be trusted, and it might simply allow them to pass us in the AI race by subterfuge. In other words, we’d still get Skynet, only with Chinese characteristics.” John Puri urges everyone to be wary about business leaders asking the federal government to regulate their industry. Noah Rothman remembers that AI was supposed to have started mass layoffs by now.


But there are more mundane and familiar threats, much closer. Late last week, Anthropic gave the public a sense of how some potentially malicious actors have tried to use their products in biological weapons research. Read on.

Health Scare

Between my writing on the origins of the Covid-19 pandemic and writing Hunting Four Horsemen, I spent about two years of my life marinating in the world of biological weapons. There’s a reason normal people don’t like to think about this stuff very often. It’s a dark topic, with a disturbing history, and once you get a sense of how this stuff works, you realize how terrifyingly easily it is to attempt to weaponize disease . . . and how easy it is for those efforts to spin out of control.

You don’t have to be particularly bright to execute a biological weapons attack; back in 1984, some nutty cult led by Bhagwan Shree Rajneesh “dressed in nondescript clothing and infiltrated 10 restaurants across The Dalles, sprinkling their Salmonella samples across salad bars, slipping it into coffee creamer, and outright pouring it into salad dressing,” poisoning 751 people, sending 45 people to the hospital.




Nuclear weapons entail specialized knowledge, are hard to assemble, and require access to uranium or plutonium. Chemical weapons are comparably easy to make; I’ll bet you’ve got at least some of the ingredients to build something harmful with the cleaning products underneath your kitchen sink. But the effectiveness of those weapons is also limited by their tendency to disperse; wind can mitigate the effects of a chemical weapon, or even blow it back toward the side that used it.

But biological weapons . . . because viruses and bacteria are living things and multiply, they can spread.


Hunting Four Horsemen was a thriller, but it was also a warning that if a form of warfare is comparably cheap, comparably easy, and hard to trace back to the perpetrator, it will be very tempting, particularly for non-state actors or any kind of death cult. Up until very recently, the primary hesitation surrounding biological weapons was driven by the difficulty controlling released viruses or bacteria; once released, there was always a chance that your own side would become infected and be forced to deal with the same consequences as your enemy. Our modern ability to edit genetic codes within viruses means that, at least theoretically, you can now create viruses designed to target particular genes.

(Published in November 2020, Hunting Four Horsemen envisioned virulent left-wing antisemitism — the kind associated with the likes of former United Kingdom Labour Party leader George Galloway — becoming a dangerous menace. Boy, what a nut I was, huh?)

Anthropic, one of the largest and most prominent artificial intelligence companies, posts monthly updates on its security, and its most recent one included a doozy, revealing “five case studies of actors using our models in ways that could support biological weapons development”:

In May 2026, our biological safety classifier blocked a request for Claude’s assistance in authoring a grant application for scientific funding. The work discussed in the application involved gain-of-function research (that is, research that genetically alters an organism to create a new or enhanced biological property) on the chikungunya virus. This gain of function research was aimed at the virus’ transmissibility and immune evasion properties.

Chikungunya virus is a mosquito-borne virus that causes debilitating symptoms (such as severe pain and fever) that can last for weeks or months, and has no licensed therapeutic. And because chikungunya circulates naturally, a deliberate release (as part of a bioweapon) would be difficult to distinguish from a natural outbreak. The grant sought to identify enhancing mutations in the chikungunya virus, engineer them into infectious clones, and select for virulence in vivo. In other words, the virus would become progressively more harmful as it repeatedly infected live animals, with researchers keeping the most disease-causing variants in each round. Similar research could certainly be used in the development of better vaccines and therapeutics for the virus — but it could also be used to make the pathogen more dangerous.

One of the reasons we were inclined to think this research was less innocuous was that the institutional affiliation associated with the grant was also a cause of concern. Although information within the application suggested that the research was pursued by civilian researchers, it was intended to be performed at a military research institute.

Anthropic also noted, “In the first example, a reseller platform evaded regional blocks to serve virologists working on a state-sponsored grant to pursue chikungunya gain-of-function work, later routing refused prompts to models with more permissive safeguards.”


That sure makes it sound like someone who works at a military research institute is awfully determined to figure out a way to design a more virulent strain of chikungunya virus.

Anthropic’s second example involved a researcher in an “unsupported region” — they mean countries not on their “supported” list — which means Afghanistan, Belarus, the People’s Republic of China, Cuba, the Democratic Republic of the Congo, Iran, Myanmar, North Korea, Russia, Russian-occupied territories of Ukraine, Syria, Venezuela, and Yemen.

In the second case, Anthropic reported:

In May 2026, we discovered a researcher outside the U.S. using Claude in their research on highly pathogenic avian influenza (“bird flu”). The research focused on viruses’ adaptation to mammals, and the mechanism by which it causes severe disease beyond the respiratory tract. . . .

The researcher in question accessed Claude from an unsupported region via U.S. virtual private server infrastructure, using a privacy-email provider with an auto-generated username. The researcher pursued this work in a credible institutional context and interacted with Claude over the course of several weeks, exchanging thousands of messages. In these exchanges, the researcher leveraged Claude’s knowledge of the scientific literature to assist the researcher in study planning and design, data analysis, and the interpretation and prioritization of experiments. The researcher also used Claude for editorial assistance in writing up the research.

All the evidence we have points to this being a research plan in its very early phases. However, the details of the plan show that this was research into a pathogen with enhanced pandemic potential. The plan involved genetic-engineering approaches aimed at introducing mutations associated with mammalian adaptation and airborne transmissibility in animal models. . . .

Now, as Anthropic’s report makes clear, the sorts of questions you ask, and data that you collect, when you’re trying to figure out how to prevent a pandemic are often hard to distinguish from what you do when you’re trying to figure out how to start a pandemic. Researching how viruses work, and how they become more virulent and contagious, by itself, is not necessarily a sign of malign intent.


The third example involved “an account that authored a grant application for orthopoxvirus research at a state-associated infectious disease laboratory. The application described access to high-containment facilities and planned work with live orthopoxviruses. Orthopoxviruses include variola, the agent of smallpox, and Mpox, which caused a global outbreak in 2022.” Anthropic concluded, based upon the inquiries, that the “grant application proposed to identify genes that shut down a particular host antiviral pathway, and confirms that the deletion of this viral gene attenuates (loses its disease-causing virulence) the virus in mice.”


If you’re researching how to make a virus less harmful, you probably don’t have malicious intent.

Anthropic offered fewer details about the fourth and fifth cases, researchers who “pursued investigations into non-transmissible novel venoms and toxins.” In the fourth case, “We learned from information shared with Claude that the researcher’s outputs also were part of a state-supported research program. This account was banned in May 2026 for unsupported region evasion.” In the fifth case, “The identity of the bacterial toxin and viral proteins were intentionally obscured, and the researcher specifically directed Claude to keep these descriptions deliberately low fidelity. We banned both accounts in May 2026 for violating Anthropic’s Supported Regions Policy.”

Of course, if someone in an “unsupported region” country could get access to Claude once, it’s not clear what would stop them from getting access again with a new account.




No government admits to having a biological weapons program; 187 countries have signed the Biological Weapons Convention, which “effectively prohibits the development, production, acquisition, transfer, stockpiling and use of biological and toxin weapons.” All the countries on Anthropic’s “unsupported region” list signed the convention (although Afghanistan signed it in 1975, and Iran signed it in 1973) several years ago.

Anthropic also reported, “We swept 30 days of activity associated with adversarial state institutions and found roughly 35 distinct research efforts, most of them ordinary civilian science, but some with notable dual-use potential.”

The use of artificial intelligence in biological research is rarely in pursuit of a nefarious agenda: “Scientists from Stanford University and the Arc Institute used artificial intelligence to design the first genomes for viruses that are not found in the natural world. The synthetic viruses are bacteriophages, which target bacteria and, in this case, destroyed E. coli in a lab setting.” In fact, the AI-generated viruses succeeded against the bacteria where natural viruses did not:

We also tested whether the generated phages could overcome bacterial resistance, a central challenge in developing phage-based antimicrobial therapies, and found that a mixture of designed phages rapidly overcame ΦX174-resistant E. coli strains, whereas a comparable mixture of naturally sourced ΦX174-like phages could not.

One of the increasing worries of the medical world is the emergence of bacteria that is both highly infectious and resistant to some antibiotics, including E. Coli.

Medical researchers can now give an AI the DNA of the bacteria they’re targeting; the AI will analyze that genetic code for weaknesses and give you a blueprint for a virus that will target that bacteria and nothing else.


Mind you, the use of AI to engineer new types of biological weapons can be done by human beings. None of this involves artificial intelligence “going rogue,” becoming “self-aware,” or any of the AI-takes-over scenarios you may have heard about lately.

As mentioned above, you can’t buy a nuclear weapon or chemical weapons on the black market. But viruses and bacteria are all around us, thankfully mostly not that harmful to humans. That cult up in Oregon that used Salmonella — a common foodborne illness — had built a lab and “purchased samples of the pathogen from a medical company called VWR Scientific in Seattle.”

I should also point out that editing DNA of viruses or bacteria requires specialized equipment, and that equipment is not cheap, and you still need to know how to operate the equipment. So, the local nut down the street is probably not going to be doing this in his garage. (That said, every now and then the feds bust some ominous off-the-books biolab.)


Your run-of-the-mill homicidal psychopath probably won’t feel any need to use AI to alter the genes of an existing virus or bacteria; they’re dangerous enough already.

The good news is, Anthropic is on the lookout for bad actors attempting to use Claude or other products to develop biological weapons and feels confident enough about their efforts to put them out in a detailed report like this one.

The bad news is, Anthropic isn’t the only artificial intelligence company in the world.


ADDENDUM: Remember Graham Platner? Remember how he was everywhere? He was on the cover of Time magazine on the issue dated June 8. By July 8, he announced he was withdrawing from the race.

Since then, the guy has disappeared — not appearing at events he was scheduled to appear. Now, considering he’s been accused of sexual assault, that’s not exactly shocking. But it’s like the guy got abducted by aliens.

Spring and summer, Platner was the hottest thing in Democratic politics — “that’s my kind of man,” Senator Elizabeth Warren declared — and now you have better odds of catching a glimpse of Bigfoot.

Exit mobile version