Security & AI news

Agentic AI research · By FireAI Security & Research Team · Published

Anthropic reports that about 950 parallel Claude agents mined phage genomes for a novel enzyme system

Anthropic reported on 23 September 2026 that Claude agents, run in parallel for 21 hours, surfaced an unknown enzyme system. What it shows about agents on a Mac.

An AI agent icon beside the FireAI research mascot, illustrating Anthropic’s report of about 950 parallel Claude agents searching phage genomes.

Anthropic reported on 23 September 2026 that Claude agents searched large DNA sequence databases for reverse transcriptases (RTs) and surfaced a previously uncharacterised enzyme system in bacteriophages, which the company calls array-associated reverse transcriptases (ART) [1]. The biology is outside the scope of this item. What matters for Mac users is the way the work was organised: many agents in parallel, a coding harness around them, and human scientists who reviewed the output and did all of the laboratory work.

Background

A single AI assistant answers one request at a time. An agentic workflow runs many model sessions that read sources, use tools, write down their reasoning and pass results on. Anthropic says the work used Claude Science, Claude Code and a custom harness that coordinates parallel Claude sessions [1]. The same pattern, on a smaller scale, is what a developer starts when Claude Code or a similar agent runs on a personal Mac.

Findings

According to Anthropic, about 950 agents ran in parallel for 21 hours and used 210 million tokens. They gathered more than 200,000 RT candidates, narrowed these to 3,500 new candidate systems and produced human-readable reports on the 20 most compelling [1]. The workflow involved reading the literature, reproducing established results, searching for uncharacterised family members and writing evaluations that propose a function with supporting evidence [1].

The system Anthropic describes has three parts: an RT from a jumbo phage that had been identified before, a partner gene next to it, and an array of evenly spaced non-coding DNA repeats [1]. Anthropic says Claude noticed that the array resembles a CRISPR repeat array, and that early experiments show the array is expressed as distinct short RNAs [1]. Anthropic states that the primary function of the system is still unknown and that further experiments are under way [1].

Anthropic describes the human role as follows. Scientists gave high-level direction for the database search, reviewed the candidate reports and eliminated most candidates. All laboratory work was done by human scientists, at biosafety levels 1 and 2, without human-infecting pathogens, and their feedback was used to refine the agents' instructions over time [1]. The article also quotes Feng Zhang of MIT and the Broad Institute, who called the identification of RNA-repeat arrays associated with reverse transcriptases "genuinely intriguing" and worth further investigation [1].

Implications for Mac users

The report is a case study of delegation at scale. Three design choices in it carry over to a desktop: the number of agents running at once, the tools each agent may use, and the point at which a person reviews the result [1]. In this case the review points were explicit. Humans filtered the candidate list and humans ran the experiments, so the agents produced proposals and reports rather than actions in the physical world [1].

On a Mac the same questions apply at a much smaller scale. An agent started from a terminal or an editor runs with the permissions of the account that launched it, and several can run side by side. The report does not describe the permissions, sandboxing or network limits of the Anthropic setup, so it offers no evidence on how such controls were applied [1].

Recommendations

  1. Decide in advance which results an agent may act on by itself and which must be reviewed by a person first.
  2. Give each agent only the folders, accounts and tools that the current task needs.
  3. When running several agents at once, keep track of which one is doing what, so that an unexpected action can be traced.
  4. Treat an agent report as a proposal to be checked, in the way the scientists checked candidate reports before any experiment.
  5. Review the network destinations that agents contact and look for ones that do not match the task.

Relevance to FireAI

FireAI is a firewall for one Mac. The Agent profile recognises 19 AI agents, including Claude Code, learns for the first 3 days which destinations each normally contacts, and then flags a new destination or an upload spike for review, using only host names and byte counts. Per-app rules let a user block a destination for one app, and the privacy promise states that FireAI sends no telemetry.

FireAI does not run, schedule or coordinate agents, and it does not limit how many agents run, which files or tools they use, or how many tokens they consume. It does not read an agent's prompts, reports or reasoning, and it does not read the inside of an encrypted connection. It is not involved in laboratory or scientific work and says nothing about the biology in the report.

Limitations

This item rests on one source, Anthropic's own account of its own research [1]. An independent secondary article could not be retrieved while this item was prepared, so none of the figures has been confirmed by a second outlet. Anthropic states that the function of the system is unknown, and this item makes no claim about what it does. The article refers to a technical pre-print, which was not reviewed here, and the item does not assess how the agents were configured, what they could access or how the work would transfer to other fields.

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. Anthropic, 23 September 2026: Claude discovers a novel enzyme system