Anthropic, the prominent artificial intelligence research company known for its focus on safety and its Claude family of models, has disclosed multiple attempts by external actors to use its systems for potentially malicious purposes. In a report published Thursday, the company detailed interventions against users attempting to leverage its technology for severe biological threats. Most notably, the firm reported disrupting research aimed at adapting bird flu into a human-transmittable strain with what it described as "pandemic potential."

The disclosure arrives amid escalating scrutiny over the dual-use nature of frontier AI systems and the capacity of private labs to police their own infrastructure. Alongside the biological security threats, Anthropic also identified coordinated efforts by foreign competitors to extract its proprietary model behaviors. According to the report, the company detected distillation campaigns originating from Chinese technology entities, including the e-commerce conglomerate Alibaba, as well as AI startups Moonshot AI and DeepSeek.

The mechanics of model distillation

The identification of distillation campaigns points to a structural vulnerability in the current generative AI ecosystem. Model distillation occurs when a competitor systematically queries a highly capable, proprietary model—in this case, Claude—and uses the generated outputs to train a smaller or less advanced system. This practice effectively allows rival developers to bypass the massive capital expenditure and compute resources typically required to train a frontier model from scratch, instead siphoning the behavioral intelligence of an existing product.

By publicly naming Alibaba, Moonshot AI, and DeepSeek, Anthropic is drawing a clear line on acceptable use while highlighting the porous nature of API access. Moonshot AI and DeepSeek are both emerging Chinese AI research firms racing to close the capability gap with Western labs. The revelation that these entities, alongside a well-resourced incumbent like Alibaba, are allegedly relying on Western model outputs underscores the intense geopolitical and commercial pressures driving AI development. It also illustrates the difficulty of enforcing terms of service when state-backed or highly capitalized foreign actors are incentivized to scrape proprietary data.

Balancing commercial scale with biological security

Beyond intellectual property concerns, the report’s details on biological weapons research expose the severe tail risks associated with broadly deployed AI assistants. The attempt to use Claude to engineer a human-transmittable variant of bird flu represents exactly the type of catastrophic misuse scenario that AI safety advocates have long warned about. While Anthropic successfully disrupted this specific inquiry, the incident highlights the ongoing tension between scaling a commercial product to millions of users and maintaining rigorous guardrails against rogue actors.

This dynamic is particularly relevant given the internal culture at Anthropic, which was founded by former OpenAI researchers specifically to prioritize safety over rapid commercialization. However, as the company competes for the massive venture capital funding required to sustain model training, it faces the same pressure to expand its user base as its rivals. The publication of this report serves a dual purpose: it demonstrates the efficacy of Anthropic's current safety protocols while simultaneously signaling to regulators and investors that the threats of AI misuse are active and evolving, requiring continuous, capital-intensive monitoring.

The findings present a sobering view of the operational reality for frontier AI developers, who must now act as both intellectual property enforcers and global security monitors. As the capabilities of these models advance, the sophistication of both distillation attacks and malicious research queries is likely to scale in tandem, leaving the industry to navigate an increasingly complex threat landscape.

With reporting from The Information, TechCrunch.

Source · The Information