AI technology has become highly sophisticated, but as companies such as Anthropic and OpenAI develop increasingly powerful models, the possibility of these tools being abused has also grown. In a comprehensive safety report, Anthropic has detailed several attempts to misuse its Claude AI, covering activities ranging from espionage and mass surveillance to biological weapons research.
The report examines a number of incidents that Anthropic said it disrupted between December 2025 and August 2026. According to the company, those cases involved suspected state-sponsored organisations, financially motivated criminals, propaganda groups, spyware companies and politically motivated individuals.
Anthropic said its Claude Haiku, Sonnet and Opus models were involved in the cases described. None of the incidents involved Claude Fable or Mythos-class models, apart from one instance involving model distillation. The company said these were not examples of routine misuse, but represented some of the most significant and unusual threats it had detected so far.
Was Claude used in biological weapons research?
Anthropic said some of the most sensitive incidents involved biological research conducted by professional scientists, including users it believed could have been supported by states. The company noted that determining whether such research was legitimate or intended for harmful purposes was not always possible.
Anthropic said it adopted a cautious approach because legitimate biological research can sometimes overlap with work that could potentially facilitate the creation of dangerous pathogens. Jacob Klein, Anthropic’s head of threat intelligence, explained that malicious intent is not always obvious in such cases, making them particularly difficult to assess.
The company outlined five biological misuse cases. In one incident in May, a scientist asked Claude to help prepare a grant proposal for gain-of-function research involving chikungunya, a mosquito-borne virus that can cause prolonged severe pain and other symptoms. The proposed work involved introducing mutations designed to increase the virus’s harmfulness through repeated infections in live animals. Anthropic said it was especially concerning because it believed the research was connected to a military research institute.
Anthropic said its biological safety system initially blocked the request, but the user subsequently bypassed the restriction using a third-party evasion service. That platform later added a fallback option involving another AI model when Claude refused to provide the requested assistance.
In another case, a reseller relay serving unrelated customers enabled a user to complete an orthopoxvirus immune-evasion grant proposal using Opus 5 in roughly an hour. Orthopoxviruses are a group of viruses that can cause human diseases, including smallpox. In another incident, a researcher planning experiments involving the adaptation of avian flu to mammals over several weeks was restricted to Anthropic’s least capable model tier.
The company also said it had stopped two state-backed programmes involving the redesign of venom or toxins. During a 30-day review of state-linked activity, Anthropic identified around 35 separate research projects. Most appeared to involve legitimate civilian research, although some had potential dual-use applications. The company stressed that it was not claiming those researchers intended to cause harm and warned that revealing their identities or laboratories could put them at risk.
According to Anthropic, some users bypassed restrictions preventing Claude access from countries where the service is unavailable and attempted to conceal the real purpose of their research. The company subsequently banned the accounts and used several additional measures in biological cases, including strict refusals, moving users to less capable models and conducting proactive investigations.
State-linked attempts to develop weapons with AI
Anthropic said misuse extended beyond biological weapons, with some groups attempting to use Claude to create software for conventional weapons such as firearms, missiles, armed drones and bombs. The company identified three cases connected to China, two to Russia and one to Yemen.
In Yemen, Anthropic said a group of malicious actors relied on Claude Code instead of human specialists in guidance, navigation and control while developing software for a guided rocket, a multistage ballistic missile designed to travel more than 2,000 kilometres and a version of a hypersonic glide vehicle. The company said the group carried out a test launch of the guided rocket, but the field test appeared unsuccessful.
In Russia, Anthropic identified a freelance operator associated with an initiative called DronDoc or Serafim. The operator allegedly used Claude Code to develop an autonomous, full-stack swarm of first-person-view kamikaze drones. According to Anthropic, the system could independently identify targets, including people, and detonate without human intervention. Its vision capabilities were trained using scraped footage from the war in Ukraine.
In China, Anthropic said an account potentially connected to the military-industrial sector used Claude to develop a 16-part electronic warfare and air-defence suppression system. The company said the user eventually moved from a generic simulation to 12 real-world targets in Taiwan, including a command bunker and Patriot and Tien Kung air-defence systems.
Anthropic reports surveillance attempts linked to China and Iran
Weapons development was not the only area in which Claude was allegedly misused. Anthropic also identified numerous attempts to use AI for large-scale surveillance. The company recorded nine such incidents.
In one case, an organisation suspected of having links to China allegedly used Claude to monitor, profile and recruit Uyghurs and journalists connected to the Syrian Army. Anthropic said the operation relied on large amounts of data collected from WhatsApp and Telegram conversations to create individual profiles. Claude was also reportedly used for live translation and role-playing exercises intended to assess deceptive tactics.
Anthropic also reported surveillance operations originating from China that targeted Catholic cardinals, Taiwan’s Presbyterian Church, Tibetan Buddhists and Falun Gong practitioners. In one instance, an actor reportedly changed its prompts after Claude initially refused a request and eventually obtained guidance concerning the suppression of 10 private individuals, along with intelligence related to planned protests overseas.
In Iran, Anthropic said two connected units operating through 16 Claude accounts claimed to have monitored or profiled 6,388 Iranians over a 12-month period. They reportedly analysed 155,216 tweets to identify 39 opposition accounts and used a malicious Firefox extension to collect identities into a shared case-management platform called Arman. The company also said an Iran-linked actor used Claude to identify US naval targets. Anthropic noted that its policies prohibit surveillance and profiling conducted without consent.
Claude allegedly used for espionage
Anthropic said AI was also being used to automate parts of cyber operations, including reconnaissance, exploitation and monitoring.
In one case, a Russian-speaking operator allegedly used Claude during attacks against more than 20 Ukrainian and European government, defence and diplomatic organisations, as well as drone manufacturers. According to Anthropic, the operator obtained an entire software development kit for a drone vision system, manipulated hotel WiFi DNS records to install malware on guests’ devices and gained control of officials’ WhatsApp accounts by disabling read receipts. The operator also reportedly acquired more than 300,000 national identity records and over 500,000 company registry records from a government organisation in North Africa.
Anthropic said automated AI monitoring agents could identify when security software detected the malware and then rewrite the malicious code until it once again avoided detection. The company said it banned the accounts, created new detection systems based on behavioural patterns and worked with Microsoft, whose separate reporting had also identified the hotel WiFi technique.
Another China-linked operation, which allegedly included two university students, reportedly used multiple AI workstreams for firmware reverse engineering, open-source intelligence gathering on foreign governments and automated intelligence collection. Anthropic said the activity resulted in around 50 organisations worldwide being compromised.
AI-generated influence campaigns
Anthropic also identified groups using Claude to organise influence campaigns and create misleading or fabricated material. The company said it disrupted at least nine operations involving Russia, China, Iran, Bangladesh and Kenya.
The largest genuine audience reach, according to Anthropic, occurred when state-controlled media outlets were used to distribute the material through radio and television.
Among the examples were Russian state-media employees, including a former editor-in-chief of Sputnik Moldova, who reportedly used Claude as an editorial assistant to produce content for the outlet. Anthropic also described a Russian-speaking coordinator in Bangui who used Claude for Radio Lengo Songo, a station established by Wagner, to create pro-Russian and anti-French material. The system was also allegedly used to forge Central African Republic government documents and prepare human-resources paperwork. Anthropic said Claude rejected one request asking it to identify real people as militants for security operations.
Data theft and a fake dating network
Financially motivated groups also allegedly exploited Claude. In one case associated with ShinyHunters affiliates, Anthropic said operators downloaded 1.8 million Android application packages and searched them for embedded secrets. The information was then reportedly supplied to a Telegram-based carding operation. Other linked breaches involved more than 1TB of stolen information from a technology company, tens of millions of airline passenger records and a software supply-chain compromise.
In April 2026, Anthropic said it uncovered a China-based network involving more than 20 dating apps advertised as being operated by “fully human” users but largely powered by Claude-generated personas.
During a two-week investigation, the company identified more than 4,700, or almost 5,000 depending on the counting method, AI personas. These accounts collectively sent about 2.36 million messages to at least 25,000 real users. Anthropic said the operation combined AI personas with human gig workers at approximately a three-to-one ratio and instructed the AI personas not to disclose that they were automated. The company subsequently banned the accounts and organisations involved.
Rival AI companies accused of distilling Claude
Anthropic also reported incidents involving rival AI companies that allegedly used Claude to help train their own models. The company refers to this practice as illicit distillation, in which outputs from one AI model are collected to improve another system.
The report named campaigns associated with Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax. Anthropic said the largest campaign it measured was linked to Alibaba, reaching almost three million exchanges per day at its peak. Between May and July 2026, the operation allegedly generated more than 151 million exchanges through over 3,500 fraudulent accounts.
Moonshot AI, which developed the Kimi K3 model, allegedly redirected around 300,000 customer requests to Claude over a 10-day period without users being aware. DeepSeek reportedly employed a comparable replay method involving 12.1 million exchanges over 14 days.
In response, Anthropic banned accounts, investigated proxy networks operating through resellers, improved its systems for identifying extraction attempts, summarised internal reasoning within outputs, introduced a “preserved thinking” capability and required identity verification from accounts displaying signs of abuse.
Anthropic said that across all seven categories of harm it had identified, it removed accounts, strengthened its safety measures and, when necessary, shared information with authorities, researchers, industry partners and affected parties. The company said it released the report because misuse is expected to increase as AI models become more capable, making it essential for developers and security teams to improve protections. It added that the findings could help other AI platforms identify comparable patterns and strengthen their collective defences.
