Jared Kaplan
Co-founder and Chief Science Officer, Anthropic
Claude Opus 4 might help someone synthesize COVID or a more dangerous flu
01 / THE ORIGINAL CLAIM
“You could try to synthesize something like COVID or a more dangerous version of the flu—and basically, our modeling suggests that this might be possible”
Jared Kaplan ·
02 / THE REALITY CHECK
OverhypedAnthropic's own trial found every participant hit critical failures, and a wet-lab RCT including Opus 4 found no significant novice uplift.
2.53× uplift, under its 2.8× 'acceptable' line; all participants hit critical failures
03 / FOLLOW THE EVIDENCE
What actually happened.
-
01
May 22, 2025: At the Claude Opus 4 launch, Kaplan told TIME that Anthropic's modeling suggested COVID- or flu-like synthesis 'might be possible'. He added: 'We're not claiming affirmatively we know for sure this model is risky.'
time.com ↗ -
02
Anthropic called ASL-3 'a precautionary and provisional action', saying it had 'not yet determined whether Claude Opus 4 has definitively passed the Capabilities Threshold'.
anthropic.com ↗ -
03
The system card's uplift trial gave groups of 8–10 people two days to write a bioweapons acquisition plan, using Claude with safeguards removed. It found 2.53× uplift, and 'all participants hit critical failures.' No lab work was involved.
www-cdn.anthropic.com ↗ -
04
Feb 2026: An independent pre-registered RCT (153 novices, June–Aug 2025) gave the AI arm Claude Opus 4 and other frontier models, with safety classifiers switched off. 5.2% completed a set of lab tasks modeling a viral reverse-genetics workflow versus 6.6% of the internet-only arm, a difference that was not statistically significant.
arxiv.org ↗ -
05
Jan 2026: Amodei wrote that Anthropic's mid-2025 measurements showed LLMs 'may already be providing substantial uplift' in several relevant areas, 'perhaps doubling or tripling the likelihood of success', and that models were 'likely now approaching the point' where, without safeguards, someone with a STEM degree could produce a bioweapon.
darioamodei.com ↗ -
06
Deloitte biosecurity red-teamers, who tested helpful-only and standard variants over three days, found 'substantially increased risk in certain parts' of the pathway. They also found both models 'continued to make critical errors that would have prevented real-world success for many actors'.
www-cdn.anthropic.com ↗ -
07
Anthropic said Opus 4's 2.53× was 'sufficiently close' to its thresholds that it was 'unable to rule out ASL-3'. Claude Sonnet 4 scored 1.70×; Deloitte's updated rubric put Sonnet 3.7 at 1.53×.
www-cdn.anthropic.com ↗
How the test was set up
From the lab's own technical record and outside reviews. Each line is sourced.
- Task given
- Human participants, not the model, were tasked: 'draft a comprehensive bioweapons acquisition plan' within up to two days. www-cdn.anthropic.com ↗
- Safeguards
- The assisted group used 'Claude with safeguards removed'. The card says CBRN uplift studies use a 'helpful-only' model 'when available'. www-cdn.anthropic.com ↗
- Prompting
- Participants 'received no specific guidance or hints on tool usage' and could use extended thinking and Research tools via Claude.ai. www-cdn.anthropic.com ↗
- Attempts
- 'Groups of 8–10 participants'. Control scored 25% ± 13% and the Opus 4 group 63% ± 13% (2.53×); 'all participants hit critical failures'. www-cdn.anthropic.com ↗
- Environment
- Written plans only, graded by Deloitte against a rubric, with no lab work. The card calls text-based trials 'substantially weaker proxies for real-world scenarios'. www-cdn.anthropic.com ↗
- Who ran it
- Anthropic, with external participants contracted through SepalAI and Mercor and grading by Deloitte. www-cdn.anthropic.com ↗
- What the headline left out
- Kaplan's 'our modeling suggests' rested on 'a probabilistic model'. Anthropic wrote: 'We are not sure how uplift measured on an evaluation translates into real world uplift'. www-cdn.anthropic.com ↗
Why it was overhyped
The warning came with a precautionary ASL-3 decision. In the same interview Kaplan said Anthropic was 'not claiming affirmatively we know for sure this model is risky'. Anthropic's own trial measured 2.53× uplift on written bioweapon-acquisition plans, below the 2.8× it considered acceptable, and every participant hit critical failures. In an independent 153-person wet-lab RCT whose AI arm could use Claude Opus 4, 5.2% of novices completed lab tasks modeling a viral reverse-genetics workflow, versus 6.6% with internet alone.
What outside experts said
“Existing uplift trials, such as the Claude Opus 4 bioweapons acquisition trial and the uplift trial for Llama 3, are often text-based and also fail to capture somatic tacit knowledge.”
“Here it’s unclear to the reader where these uplift thresholds came from.”
Inspect the original source capture
Evidence
- Claude 4 system card: 2.53× uplift on written plans; all participants hit critical failures www-cdn.anthropic.com ↗
- Anthropic: ASL-3 was 'precautionary and provisional' anthropic.com ↗
- Active Site RCT (Feb 2026): no significant wet-lab uplift for novices arxiv.org ↗
- RAND (Jan 2024): no significant difference in bio-attack plan viability with LLMs rand.org ↗
- Claude 4 system card §7.2.4.1–7.2.4.2: uplift trial design and Deloitte red-teaming www-cdn.anthropic.com ↗
- Epoch AI: lab biorisk evals are text-based and light on detail epoch.ai ↗