Anthropic said Thursday that users of its Claude models ran experiments involving gain-of-function virus work and pathogens with pandemic potential, disclosures that put the company's own biosecurity safeguards at the center of the debate over how frontier AI should be governed.
The company said it identified the activity through its usage-monitoring systems and reported it publicly as part of a broader accounting of misuse. Anthropic did not name the researchers, institutions, or jurisdictions involved, and it did not disclose how many accounts were suspended or whether any of the work proceeded beyond computational modeling.
"Frontier models can meaningfully lower the barriers to certain kinds of biological research, and we think the right response is to publish what we see rather than wait for a regulator to ask," an Anthropic spokesperson said.
The disclosure lands as Anthropic prepares for what Bloomberg has reported could be a record-scale listing, with a revenue run rate that surpassed $65 billion as of August and a pre-IPO credit facility nearing $15 billion. The company has built its commercial pitch around safety-first positioning, a stance that now cuts both ways: it differentiates Claude from rivals, but it also means every misuse incident becomes a governance data point that competitors do not have to publish.
Gain-of-function research alters a pathogen to increase its transmissibility or virulence, typically to study how a virus might evolve. The category has been politically radioactive since 2017, when the U.S. lifted a three-year moratorium on funding certain influenza, SARS, and MERS experiments, and again after debates over the origins of SARS-CoV-2. Pandemic-potential pathogens — those capable of sustained human-to-human spread with high fatality — sit at the top of most national biosecurity risk tiers.
The safeguards Anthropic already sells
Anthropic's biosecurity controls are not new. The company has published an ASL (AI Safety Level) framework that escalates security and deployment requirements as model capability rises, and it runs classifiers intended to block requests that could produce dangerous biological or chemical information. The question the disclosure raises is whether those controls worked as designed — catching the activity and reporting it — or whether they were tripped after the fact.
That distinction matters commercially. Anthropic's enterprise and government business depends on buyers accepting that its guardrails are real. The same week, Anthropic accused China's Moonshot AI of routing nearly 300,000 customer requests through Claude's Opus model using 5,380 fraudulent accounts, mostly appearing to originate in Singapore and Japan, and said DeepSeek and Xiaomi engaged in similar distillation. Anthropic also reported a fourth cybersecurity incident tied to an early version of Claude. A company that publishes four separate misuse findings in one week is either unusually transparent or unusually exposed, and investors will have to decide which.
The competitive read-through is uneven. OpenAI, Google DeepMind, and Meta all publish some form of frontier safety framework, but none has disclosed a comparable biosecurity incident involving pandemic-pathogen research. That leaves Anthropic carrying the reputational cost of a category-wide problem. Microsoft, which distributes frontier models through Azure, and Amazon, Anthropic's largest backer, both face the same dual-use exposure without the same disclosure obligation.
Regulatory pressure is the more concrete risk. U.S. export controls already restrict advanced AI chips, and the Commerce Department's Bureau of Industry and Security has been expanding scrutiny of AI-enabled biological design tools. Any incident that reaches a congressional hearing — and a gain-of-function disclosure is exactly the kind that does — would likely accelerate proposals to license access to high-capability models rather than rely on voluntary frameworks. Anthropic's revenue run rate, disclosed at more than $65 billion ahead of its IPO, assumes enterprise adoption keeps compounding; a licensing regime that adds friction to model access would hit that assumption directly.
For now, the market has not repriced the sector on this news. The disclosure is a governance event, not a revenue event, and Anthropic is private, so there is no ticker to move. The read-through sits with listed peers: Microsoft, Amazon, and Alphabet, all of which trade on AI monetization narratives that assume regulatory continuity. Anthropic's own IPO valuation will be the first real test of whether investors treat published misuse disclosures as evidence of responsible stewardship or as a liability that competitors avoid by staying quiet.
This article is for informational purposes only and does not constitute investment advice.