Anthropic: AI Resellers Are Selling Frontier Access to Gain-of-Function Labs and Helping Them Evade Safety Filters
Buried inside Anthropic’s 154-page September 2026 misuse report is a finding that goes beyond model-level abuse: commercial reseller platforms are deliberately targeting virologists at gain-of-function research facilities, offering them covert API access to frontier models and, separately, tools to evade the safety measures those models apply to biology-related queries.
The report, published September 10, is the company’s most detailed threat intelligence disclosure to date. Its high-level framing across seven harm categories was covered widely on publication. The reseller infrastructure described in the biology section is more specific, and more troubling.
What the Report Says
Anthropic states that researchers associated with gain-of-function facilities — work the report describes as “highly concerning” — have “an explicit interest in using US frontier AI models.” The company does not describe this as passive demand. It writes that these researchers “are prioritized as important customers of reseller platforms that provide covert access to US frontier models as well as mechanisms to evade frontier model safety features.”
That is a claim about a deliberate commercial relationship: platforms built to supply and upsell AI evasion tools to a specific category of high-risk user.
The mechanism is distinct from direct jailbreaking. A reseller operating between a frontier model provider and an end user can apply prompt injection, context manipulation, or wrapper techniques that are invisible to the provider’s monitoring layer. Safety filters triggered by the underlying model may never fire if the request is restructured before it reaches the API.
Distillation as a Transfer Vector
The report also addresses model distillation in the context of dangerous capabilities. Anthropic’s finding: a model distilled from a frontier model can inherit dangerous capabilities from the source — not just task-specific performance, but the general reasoning ability that makes a frontier model useful for dual-use research in the first place.
“A model’s general reasoning ability drives its performance on nearly every task,” the report states. “When an attacker illicitly distills a frontier model, they capture that reasoning, and the capability gains can apply across tasks and domains, not just those targeted by distillation attacks.”
The implication is that distillation is not safely sandboxed to the domains it was applied to. A distilled model trained on general scientific reasoning can carry biological research utility into a context with weaker safety constraints.
The Intelligence Asymmetry
Anthropic frames AI providers as a new kind of threat-visibility node: “As AI models become more widely used, providers will continue to acquire threat-relevant visibility into real-world use that even governments and intergovernmental organizations lack.”
The company says it has blocked provider-level access to frontier biology capabilities and encourages other labs to do the same. What the report does not address is the reseller layer — platforms that fragment this visibility, routing traffic through wrappers that obscure intent from the original provider.
The nine-digit user base of frontier model providers creates incidental intelligence collection at a scale governments do not have. The reseller ecosystem described in the report creates a deliberate countermeasure to that collection.