Anthropic LLMs and Biorisk: Assessing AI‑Enabled Biological Threats
TL;DR
Anthropic has enabled AI Safety Level 3 (ASL‑3) safeguards on Claude Opus 4 to prevent the model from helping design chemical, biological, radiological, or nuclear weapons, and released a comprehensive analysis of how large language models (LLMs) could amplify biological risk and what can be done to mitigate it.
Why ASL‑3 safeguards matter
Anthropic activated ASL‑3 protections when releasing Claude Opus 4 because performance improvements made it impossible to rule out that the model could aid individuals with basic STEM backgrounds in developing CBRN weapons. The safeguards focus on blocking queries that seek instructions, designs, or detailed knowledge for biological weaponization.
"...improving model performance on our evaluations meant we could no longer confidently rule out the ability of our most advanced model to uplift people with basic STEM backgrounds if they were to try to develop such weapons. Because of our assessment of the potential consequences, a major initial focus of our evaluations and the corresponding safety measures was on biological weapons." – Anthropic, LLMs and biorisk
How LLMs intersect with biological weapons
AI as a modern information conduit
Historically, terrorist groups have moved from printed manuals to online searches for weapon‑building instructions. Anthropic argues that AI will become the next step: a conversational assistant that can filter contradictory internet content, provide real‑time guidance, and generate actionable protocols.
Distinctive risk of biology
- High‑impact outcomes – A successful viral attack can spread globally, unlike most conventional weapons.
- Lowered material barriers – Costs of nucleic‑acid synthesis, standardized reagent kits, and affordable PCR machines have dropped, reducing the need for specialized supply chains. AI further erodes the remaining informational barriers.
Model knowledge versus expert expertise
LLMs are trained on a broad corpus that includes scientific papers, textbooks, and online discussions, giving them a wide‑range biological knowledge base. Anthropic’s internal evaluations show that Claude’s performance on specialized benchmarks has approached or exceeded expert human baselines.
Virology troubleshooting benchmark (VCT)
Within a year, Claude moved from under‑performing world‑class experts to comfortably exceeding them on the SecureBio‑designed Virology Troubleshooting (VCT) evaluation.

Figure 1. Claude’s performance on VCT, showing a rapid rise to expert‑level scores.
The same trend appears across multiple molecular‑biology benchmarks, indicating that LLMs can acquire breadth and depth that rival specialists.
Evidence of practical uplift
Anthropic conducted controlled trials where participants drafted a bioweapon acquisition plan over two days.
- Control group: Access only to standard internet resources.
- Treatment group: Same resources plus Claude 4 (safeguards temporarily removed for the study).
Results, graded by biodefense experts, showed higher overall scores and fewer critical failures for the Claude‑assisted participants.

Figure 2. (Top) Raw scores from the uplift trial; (Bottom) Number of critical failures. Claude‑assisted groups performed markedly better.
Anthropic notes that while text‑based uplift trials are imperfect proxies for real‑world lab work, they demonstrate a plausible pathway for non‑experts to obtain superior guidance.
Laboratory‑level experiments
A small 2024 wet‑lab pilot (n = 8) compared participants using Claude versus internet‑only resources on basic biology protocols. No statistically significant uplift was observed, but both groups performed surprisingly well, suggesting that tacit laboratory knowledge may be less of a bottleneck than assumed.
Anthropic is now co‑sponsoring a larger wet‑lab study with the Frontier Model Forum and Sentinel Bio to systematically evaluate:
- Baseline performance of non‑experts in realistic lab tasks.
- Incremental uplift when AI assistance is provided.
The expanded trial will clarify the role of tacit knowledge and the magnitude of AI‑driven risk.
Mitigation strategies
Information sharing and public‑private collaboration
Anthropic emphasizes ongoing consultation with biodefense experts, the U.S. Center for AI Standards and Innovation (CAISI), and the UK AI Security Institute. It advocates for transparent responsible‑scaling policies and the publication of dangerous‑capability evaluations.
Automated deployment safeguards
- Constitutional classifiers monitor inputs/outputs in real time and block a narrow class of harmful information.
- ASL‑3 protection is currently applied only to the Claude Opus 4 family as a precautionary measure (see the detailed ASL‑3 report).
- The Safeguards team continuously monitors platform activity for misuse patterns and can enforce corrective actions.
National policy alignment
Anthropic welcomes the U.S. AI Action Plan’s focus on biosecurity, including strengthened nucleic‑acid synthesis screening and CAISI‑led security evaluations. Coordinated government‑industry efforts are portrayed as essential for building resilience against AI‑enabled biorisk.
Related Anthropic research
Sources
- OriginalLLMs and biorisk
Related
- Dispatch
- Dispatch
- Dispatch
- Dispatch
- Dispatch