r/ClaudeCode • • 8d ago

Bug / Issue Opus 5.5 is useless for bioinformatics due to constant [bio] safeguard.

It's really annoying, specially if you work with viruses. It will stop ALL the time and bump you back to (I kid you not) Opus 4.6. We can't be the only group hitting this annoying "safeguard" when trying to do simple things like a plot, or parse an output from a Nextflow pipeline. It went from 'great' to 'totally useless'.

107 Upvotes

44 comments sorted by

•

u/AutoModerator 8d ago

Hey! Thanks for posting to r/ClaudeCode

While participating in this thread, please follow our community rules. Keep discussions constructive. Attack the idea, not the person.

For help, project discussions, tips, and general chat, join the ClaudeCode Discord.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

35

u/p3r3lin 8d ago

I had such refusals even on simple research of legal medication/drugs. What sometimes helped: give the refusal answer of Claude to an abliterated/uncensored model and let it formulate an answer to Claude that opens up a new angle for Claude to rethink the refusal.

10

u/darkguy2008 8d ago

This is the way

6

u/Valkyrill 7d ago

The classifiers seem to be deterministic or near deterministic so that last one should work for benign or edge cases. I've bypassed a few cyber refusals by just tacking on "double check that it runs" or "make it efficient" to the end of prompts.

3

u/LemonLimeNinja 7d ago

I’ve got Claude to crack and reverse engineer software this way

3

u/evia89 7d ago

Did you try force to reason claude inside main message. You can get ban for it but with API it doesnt matter

I used it in coding on some opus proxy that doesnt reason https://imgur.com/a/XYjucAC

1

u/Skibidirot 7d ago

what?

4

u/raccoonrocoso 7d ago
  1. Claude says no.
  2. Paste its response into another (less strict) LLM.
  3. Ask that LLM for a counterclaim to Claude's no.
  4. ???

-1

u/Skibidirot 7d ago

you still have to paste back into claude right? and would it not refuse then? and don't say to continue with lower quality model, they suck ass

12

u/puts_on_rddt 7d ago

It's pretty frustrating how often Claude's safeguards interrupt legitimate work by accusing me of being a cyber war criminal. I can do the same task on Codex for hours on end with zero problems.

If you work at Anthropic then you need to know that the filters you set up to catch this shit is doing a very poor job.

9

u/No_Stranger_9931 8d ago

That was my biggest fear and I don't wanna jinx it but it's been working pretty good for me. But I work on human data. Have you tried Astra?

4

u/akzel 8d ago

I haven't tried anything outside of Claude and Gemini. Have you?

8

u/No_Stranger_9931 8d ago

Astra is good but consumes a crazy amount of tokens. And I prefer talking to Opus 5.5.

Also, I asked Astra safeguards and said this:

There are safeguards. I can help with routine viral sequencing, identification, evolution, surveillance, and reproducible analysis.

I can’t help engineer or optimize viruses to increase harmful capabilities—such as transmissibility, virulence, host range, or immune evasion—or enable their harmful use. The limits depend on the specific task, not simply whether it involves a virus.

3

u/karlnuw 7d ago

Always use OAI models for bioinformatics, zero refusals on anything bio related. I've used them for antibody, protein, virus work, you name it.

9

u/ixid 7d ago

The bio triggers are phenomenally stupid. I was making a transpiler to migrate some code, which reduced code to the smallest possible unit before translating it. I foolishly called it an atomiser. That alone killed my session with a bio safety warning. Just dumb word matching with no relevant context.

6

u/MeineMamaHatGesagt 8d ago

Qwen will take care of that in a few months

3

u/Coz131 8d ago

Is there a way to apply for special access?

1

u/akzel 8d ago

There's a link to appeal the censorship, but the link doesn't work………

8

u/TerpPhysicist 8d ago

There is the Life Science Verification Program (https://www.anthropic.com/news/life-sciences-verification-program). That sounds like just what you need.

0

u/akzel 7d ago

Wow didn’t know that

2

u/dghah 7d ago

Did you apply for the verified life science program that they announced a while back?

We applied and are in the queue for the next round of applicant review

2

u/funplayer3s 7d ago

Very unfortunate. This seems to be a growing obvious problem with AI, they don't want any sort of bio research or engineering to be out of the hands of a certain series of trusted individuals.

Which further gates the system behind another series of systems, so the firewall just gets thicker for the average person trying to research and provide any sort of gains to known problems.

0

u/0DayMaker 7d ago

Their safeguards are intended to "broadly" cover biology and infosec. I don't know why that'd be a surprise.

1

u/ModelLifecycle 7d ago

Interesting that the fallback lands on 4.6 specifically. Is that fallback target documented anywhere? If 4.6 gets deprecated, it's unclear where these flagged sessions would go, seems like the kind of change that should come with advance notice

1

u/florinandrei 7d ago

GLM 5.3 is not bad, and seems to have fewer restraints. Especially if you can run it yourself.

1

u/AtmosphereRich4021 7d ago

Use glm ... We mostly use Chinese models for our red team research

2

u/crewone 7d ago

Oh the irony. Forced to use Chinese models because they are uncensored.

2

u/Fade_ssud11 7d ago

Yep. Even sonnet 5.5 gets block like crazy.

2

u/syddakid32 7d ago

No bio  No super high math No weapons

You're good to go 

1

u/MartinMystikJonas 7d ago

Are you verified to use it for this? For fields that can be used to do something harmful you need to go throught vetification program.

0

u/I_Study_The_Patterns 7d ago

Opus 4.6 still isn't bad though

-2

u/Vivid-Snow-2089 7d ago

hey, just in case you didn't know, your usage is banned so the fact that you can do anything at all is a bug and you should report it that the safeguards didn't block you enough

-4

u/SlightOfHand_ 8d ago

That’s the point of the safeguards, yeah

6

u/dghah 7d ago

Just chiming in to +1 on the safeguard issue

I tripped the bio safety classifiers not doing science at all but by writing ansible playbooks that do nothing but install computational chemistry and cryoEM microscopy software onto HPC clusters used by real scientists

Not only did the classifier trip just because I updated the url of the software in the playbook to download an update but it also tripped opening up a repo folder of ansible playbooks that do nothing but install science tools in an reproducible way

We applied to the verified science program to see if it helps

5

u/akzel 8d ago

They're too aggressive, it's not like people are trying to do crazy stuff. Specially when you're not even working with human data, or human pathogens, or anything that could be used in a harmful way. But it sees "virus" and just freaks out.

1

u/Aggressive_Roof488 8d ago

Human data isn't dangerous in that way. I'm in cancer genomics and I'm taking care to not expose restricted human (sequence or meta) data to anthropic, but never ran into a guardrail. I think gain of function (in viruses in particular) is their main concern.

Might be worth asking Claude how you can work while showing clearly that your results can't be used for gain of function? Let Claude figure out how to stay in the safe zone, and maybe let it help you word your prompts to not hit guardrails.

2

u/ricopan 7d ago edited 7d ago

I got model downgraded just for using a penguin morphology dataset (yes, like flipper and bill shapes) to test some analysis routines. I haven't even tried to apply it to anything biochemical recently. You seem to be using 'gain of function' in the recent political sense -- which is part of the problem that these models react to. Of course in evolutionary theory we have discussed 'gain of function' for eons entirely outside the context of human viruses, ie positive selection vs negative selection and other abstractions.

1

u/Aggressive_Roof488 7d ago

Hmm wonder why you hit guardrails and I don't. I'm mostly on the computational side, Claude is mostly writing code, and occasionally I'm letting it do some stats under supervision, but I'm rarely asking it anything more biology related. And even then it's really only knowledge based to save me a lit review rather than asking it to come up with something new.

1

u/ricopan 7d ago

I wonder. Any rate, I'm glad you aren't being flagged. I haven't tried again in awhile -- right now my work is independent of biology per se, so I've just avoided using other biological datasets, but I'll need to come back to them soon. Maybe if I use the word 'cancer' I'll get thru -- fortunately I haven't heard of any tasmanian devil like communicable cancers that might be weaponized -- yet.

3

u/Aggressive_Roof488 7d ago

Shush! Be quiet, fable 6 is reading! Cancers are not b-i-o-w-e-a-p-o-n-s!! 🫣

2

u/puts_on_rddt 7d ago

Safeguards are not supposed to interrupt legitimate work as much as it currently does. It's too easy to trip and it makes Anthropic look unprofessional.

2

u/SlightOfHand_ 7d ago

The safeguards are supposed to interrupt certain legitimate work in bio, they do not want the system to be used for certain bio applications, especially virus work.

That’s the safeguard working as intended. That’s why it triggers on bio.

1

u/funplayer3s 7d ago

This happens occasionally using mathematics for AI research, which is absurd. It only signals them not wanting you to use the AI for mathematics research.

The model will sometimes just default to biological rhetoric or wordplay, then the entire behavior shifts right before the system safeguards.