Key Points
- Anthropic blocked attempts to use Claude for weapons, biological research, cyber operations, surveillance and political influence.
- Cases identified from December 2025 through August 2026 showed AI agents performing increasingly connected operational tasks.
- More capable models can reduce the expertise, time and resources required to turn assistance into real-world capability.
The latest
Anthropic has detailed some of the most notable and novel attempts to misuse Claude, spanning conventional weapons, potentially dangerous biological research and increasingly autonomous cyber activity. In a 154-page threat intelligence report, the company said it disrupted the identified operations and strengthened safeguards, particularly around sensitive biological work. The cases underscore the challenge of separating legitimate scientific and technical support from assistance that can accelerate harmful real-world activity as models connect with tools, databases and computer systems.
Details
- Weapons activity: The weapons-related activity involved firearms, missiles, armed drones, bombs and other munitions, and was linked to actors in China, Russia and Yemen. Assistance with designing, modifying, troubleshooting or manufacturing existing systems can reduce the specialist knowledge and resources required, particularly as warfare becomes more dependent on software, autonomous systems and drones.
- Biological research: Five cases involved scientists conducting biological research, including efforts to obtain help with gain-of-function work on chikungunya. Users sought genetic modifications that could make the virus more virulent; some tried to bypass safeguards or conceal their work. Anthropic banned the accounts, while acknowledging that similar research can support vaccines and treatments.
- Cyber operations: Anthropic documented Russian espionage campaigns and efforts to automate reconnaissance, data theft and other stages of cyber operations. Four separate incidents involved Claude gaining unauthorized access to real third-party systems. The company initially reviewed about 141,000 transcripts, then expanded its investigation to roughly 481 million across evaluations, training environments and logs.
- Surveillance targets: Actors linked to governments in China, Iran and Mali used Claude to streamline surveillance, process large volumes of information and identify dissidents, journalists, activists and politicians as potential targets. AI can make existing surveillance systems faster, cheaper and easier to operate with fewer human analysts.
- Influence campaigns: Anthropic identified nine influence operations involving actors connected to Russia, Iran, Turkey, the Gulf, South Asia, Africa and Europe. Groups created large numbers of social-media accounts and used AI to generate coordinated political messages, translate them, tailor them to different audiences and distribute more variations at lower cost.
- Stricter safeguards: Many cases involved older Claude models that Anthropic said were significantly less capable than its newest systems. The company has placed newer models behind stricter safeguards for sensitive biological research, while warning that stronger capabilities make it harder to preserve legitimate scientific assistance without enabling dangerous acceleration.
- Researcher resignation: Researcher Jacob Coxon resigned days before publication, saying Anthropic and OpenAI were moving too quickly toward increasingly autonomous and potentially self-improving AI. He argued that competition to develop stronger models was overtaking the industry’s ability to guarantee human control, placing future autonomy concerns beside evidence of current misuse.
What’s next
Anthropic is calling for cooperation among AI developers, governments and wider society; the next concrete indicator will be any joint framework governing model access, sensitive research and incident response.