On the Moonshots podcast, recorded on September 16, 2026, and published three days later, host Peter Diamandis, founder of XPRIZE, introduced Anthropic's September threat intelligence report with alarm. He listed the misuse it documents: cyber operations, surveillance, influence campaigns, conventional weapons, fraud and attempts to steal the model itself. Then he singled out "the line that matters most": five cases involving activity that could support biological weapons development.
Diamandis then read a sentence that he presented as a quotation. It said that Anthropic could no longer confidently assure that its frontier models were below the threshold at which they could meaningfully assist sophisticated users with dangerous biological research. He called it the first time a lab had said such a thing. "In plain English," he said, the lab was admitting it could not promise it had not crossed the biological red line that every lab says it wants to stay below.
The report itself, Detecting and countering misuse of AI: September 2026, describes something narrower than bioweapon plots, and more practical. Its five biological case studies concern dual-use research, meaning science that can serve beneficial and harmful ends. Anthropic does not claim that the scientists involved intended harm. The cases instead describe how hard it was for the company's safeguards to sort legitimate biology from risky biology.
What the five cases describe
The report covers misuse that Anthropic detected and disrupted between December 2025 and August 2026. The five biological examples differ in how much the model actually helped:
- A reseller of research access. The first case involved a service that resold access to the model for research. Its first dangerous requests were blocked, but access resumed after the bans.
- Weeks of planning with limited help. In the second case, someone spent weeks planning research using weaker models. Anthropic judged the assistance to be mainly clerical and limited.
- A grant in about an hour. The third case involved a grant proposal drafted with Opus 5 in roughly one hour.
- Toxin research presented as therapy. The fourth and fifth cases concerned two separate research programs involving toxins, largely presented as therapeutic work. Anthropic's classifiers, the automated filters that screen requests for dangerous content, generally allowed this work. The accounts were banned, but for violating Anthropic's regional access policy rather than for the research itself.
The report also describes a separate 30-day sweep. It found about 35 research efforts linked to institutions in adversarial states. Most of them were ordinary civilian science.
Anthropic's conclusion is that classifiers worked in narrowly targeted high-risk areas but were insufficient for the broader range of dual-use research. Alongside those filters, it advocates verifying who users are, checking the institutions they work for and keeping adequate visibility into how the models are used.
Why refusals are not enough
That conclusion matches the argument Dave Blundin, founder of Link Ventures, made on the podcast. He said it is "very hard" to train a model to behave safely, release it and keep "some very crafty person" from undoing that training. His example was reframing: a chemistry or biology project can be recast as a maths problem, so that the model seems to be helping with a difficult calculation or management problem. Then "the AI has a very hard time telling that you're actually designing a weapon."
In Blundin's view, that is why logging matters: a single request can look harmless, but a record of everything a user asks can reveal what they are really doing. When people use a model through an API, the programming interface through which a company serves its model, the provider can keep such a record. "When you have APIs and you're logging everything, you can easily detect that, which is what Anthropic is doing," he said. He compared logging to nuclear weapons inspections: "Inspection is job one. Once you have inspection, then you have data." Having that data, he said, leaves more time to debate what to do with it.
Blundin also placed the report within a broader geopolitical story. He said the Kimi K3 model was "the tipping point": in his view, something was now "out in the wild" that is "very capable of helping you with a chemical or biological weapon," and that started a clock just a few months ago. He argued that when China says a model has been trained so it cannot be used for anything dangerous and then releases it, there is "absolutely no chance" that it is actually contained. These are his assessments; the report's biological cases concern Anthropic's own models.
A skeptic who still wants outside controls
Salim Ismail, founder of Open ExO, was the panel's sharpest critic of the report. He called it "safety theater" and said that many of the abuses involved earlier models. He also questioned the timing, on the eve of an international summit, and said it was "not, I think, an accident." If a lab publishes this much negative material, he argued, it should also publish its defensive findings in forms others can use, whether through tools, training or other models.
Even so, Ismail reached a conclusion close to Anthropic's own: "permissions and kind of containment need to exist outside the model itself." Asking everyone to behave safely is not enough, he said. He linked this to what he called co-scaling defensively, the idea, which he credited to fellow panelist Alexander Wissner-Gross, that protections should grow alongside AI capabilities. He said this was "not a difficult thing to do" and that he was surprised by how little of it seemed to be happening.
Wissner-Gross, a computer scientist and founder of Reified, raised a different concern. He argued that the framing lets Anthropic present its frontier models as too dangerous for the public while still using them itself or with corporate partners under tight control. "Advanced biotech, for me, but not for thee," he said, and he hoped the arrangement would draw antitrust attention.
What this means in practice
In the report's cases, the difficulty was not blocking an obviously dangerous request. It was recognizing dual-use work that arrived as a grant draft or a therapeutic project, or through a reseller whose access came back after bans. Blundin adds the maths-problem disguise to that list. Anthropic's answer, and Blundin's, moves the checkpoint from the model's answer to the user and the record of their activity: who they are, which institution they work for and what their requests add up to over time. Ismail's objection is not to controls of that kind. It is to how the report was presented and to how slowly, in his view, the industry is building those defenses.