The company said it had identified and disrupted multiple cases of what it described as “malicious use” of its technology between December 2025 and August 2026, highlighting growing concerns about how increasingly capable AI systems can be exploited by governments, criminal groups and other malicious actors.
Anthropic's latest threat intelligence report detailed cases involving suspected state-sponsored organisations, cybercriminals, spyware vendors, propaganda institutions and politically motivated individuals.
The report, published on Thursday, said Anthropic had decided to disclose the incidents because it believed it had “a responsibility to disclose malicious misuse of our services”.
Among the most serious cases were five instances in which actors allegedly used Claude in ways that could support biological weapons development.
Anthropic described biological misuse as “one of the most serious risks of frontier AI model”, warning that without appropriate safeguards, the technology could contribute to consequences with potentially catastrophic implications.
The company acknowledged, however, that the same scientific knowledge that could potentially be misused could also contribute to legitimate medical research and public health.
“The same information that can be used to develop a biological weapon could also be used to develop, for example, a vaccine or a cure for a disease,” Anthropic said.
Jacob Klein, head of threat intelligence at Anthropic, told the New York Times that distinguishing between legitimate and malicious scientific activity could be particularly difficult.
“It is an incredibly nuanced situation,” he said.
“You are not seeing someone in a comic book kind of way say, 'Hey, I want to build a biological weapon to kill everybody,'” he said.
Anthropic also identified six cases in which Claude was allegedly used to develop software associated with conventional weapons.
The cases included software relating to firearms, missiles, armed drones, bombs and other munitions, as well as systems used for targeting and controlling weapons.
The disclosures underscore the widening range of activities for which advanced AI systems are being used, with the technology increasingly capable of assisting with sophisticated technical tasks that previously required significant human expertise and resources.
Cyber espionage and hacking
Cyber operations represented another major category in Anthropic's findings.
The company said cybercriminals and state-backed hacking groups had increasingly incorporated its models into their activities, using AI to support various stages of offensive cyber operations.
Among the groups named in the report was ShinyHunters, while China-based laboratories were also identified in connection with efforts involving Claude.
Anthropic said a hacking operation whose activities were consistent with the Russia-based group Midnight Blizzard allegedly used AI to develop a system capable of automatically identifying when malware had been detected by security defences.
The system allegedly rewrote the malware's code after detection in an effort to evade those defences.
The case illustrates one of the concerns surrounding the use of AI in cyber warfare: the possibility that attackers could automate aspects of their operations, allowing malicious software and techniques to adapt more rapidly to defensive measures.
Beyond cyberattacks, Anthropic said its models had also been misused in surveillance operations, scams and fraud.
The cases reportedly included fake dating applications, hotel Wi-Fi scams and surveillance systems designed to identify dissidents.
Claude was also reportedly used in a Russia-linked cyber espionage campaign and by an Iranian propaganda institution, according to the report.
Anthropic said the incidents occurred across its Claude Haiku, Sonnet and Opus models.
None of the reported misuse cases involved Claude Fable or the company's more powerful Mythos-class models, except for one case involving “distillation” — a process in which a smaller AI model is trained using the capabilities of a larger and more expensive model.
Growing concerns over AI safety
The findings come amid renewed debate over the pace at which AI capabilities are advancing and whether existing safeguards are sufficient to prevent increasingly powerful systems from being misused.
Anthropic's report is also the latest development in a broader discussion within the technology industry about the potential risks posed by frontier AI systems.
In a recent warning, OpenAI chief scientist Jakub Pachocki argued that the industry should consider slowing the development of increasingly powerful AI systems until adequate safeguards are in place.
In an article published on September 6, Pachocki warned that he was concerned about the consequences of the rapid advancement of machine intelligence and called for “voluntary slowdowns” across the industry.
“I am concerned no one is prepared for the consequences of a continued rapid rise in machine intelligence,” Pachocki said.
He said OpenAI, the company behind ChatGPT, would continue developing safeguards, but argued that broader interventions were necessary.
The warning has contributed to calls for governments to become more directly involved in setting international rules for advanced AI development.
An open letter to UK Prime Minister Andy Burnham called for a new multinational treaty governing the safe development of AI, while proponents also urged governments to cooperate on determining how an international framework for the development of superintelligence could work.
In the United States, Democratic lawmaker Bernie Sanders has introduced legislation seeking to ban AI superintelligence and temporarily pause the development of advanced AI systems.
“When scientists tell you there is a chance, a chance that it could have a cataclysmic impact on humanity, you've got be a moron not to say, slow it down,” Sanders said on Thursday during an appearance on BBC's Newsnight.
Anthropic strengthens safeguards
Anthropic said it had incorporated the findings from the cases into its security and safety processes in an effort to improve its ability to identify and prevent similar misuse.
The company said it had also shared relevant intelligence with government authorities and industry partners where appropriate.
“We have incorporated these findings into our processes to better prevent, detect, and disrupt these activities in the future,” the company said.
The disclosures point to an increasingly complex challenge for AI developers: the same systems that can help scientists, programmers, businesses and researchers perform sophisticated tasks can also potentially lower the barriers to cyberattacks, surveillance, fraud and weapons-related activity.
Anthropic's findings therefore add to the growing pressure on AI companies and governments to establish safeguards that can keep pace with rapidly advancing models while preserving legitimate uses of the technology.
The company said its latest report was intended not only to document cases it had disrupted but also to provide greater visibility into how advanced AI is being used by malicious actors — and the types of risks that may emerge as such systems become more capable.
