Anthropic Reveals How AI Tool Claude Is Being Misused for Weapons, Surveillance and Espionage

Share Us

283
Anthropic Reveals How AI Tool Claude Is Being Misused for Weapons, Surveillance and Espionage
12 Sep 2026
min read

News Synopsis

Anthropic has detailed several major misuse attempts involving Claude, including biological research, weapons development, surveillance, cyberattacks, influence campaigns and efforts by rival AI companies to extract model capabilities.

Anthropic Reveals How Claude Is Being Misused for Weapons, Surveillance and Espionage

Anthropic Publishes Detailed Claude Misuse Report

Artificial intelligence company Anthropic has disclosed a series of serious attempts to misuse its Claude AI models for activities ranging from biological research and weapons development to surveillance, cyber operations and influence campaigns.

The company said the incidents occurred between December 2025 and August 2026 and represented some of the most significant and unusual threats it had identified.

The cases involved suspected state-backed organisations, criminals, propaganda networks, spyware-related actors and politically motivated groups.

AI Misuse Raises Concerns Over Biological Research

Anthropic identified several cases involving biological research that raised concerns because legitimate scientific work can overlap with potentially dangerous applications.

The company documented five biological misuse cases. In one instance, a researcher sought assistance with a grant proposal involving gain-of-function research on chikungunya virus. The proposed work involved modifying the virus through repeated infections in live animals.

Anthropic said its safety systems blocked the request, although the user subsequently attempted to bypass the restriction through an external service.

In another incident, a user reportedly obtained assistance in preparing research related to orthopoxviruses. Anthropic also identified state-linked projects involving toxins and venom redesign.

The company said many of the biological research activities it detected appeared legitimate, making it difficult to determine intent in every case. It therefore relied on measures including account restrictions, model downgrades and stronger refusals.

Claude Misused for Weapons Development

Anthropic also reported attempts to use Claude for developing technology associated with conventional weapons.

The company identified cases involving users in China, Russia and Yemen who allegedly sought assistance with missiles, armed drones, electronic warfare systems and other military applications.

One case involved a Yemeni group that reportedly used Claude Code during the development of software for guided rockets and other advanced weapons concepts.

In Russia, Anthropic identified activity connected to the development of an autonomous drone swarm. The reported system was designed to identify targets using computer vision and operate with limited human involvement.

A China-linked account was also accused of using Claude to develop an electronic warfare and air-defence suppression system and later applying simulations to real-world targets.

China and Iran Linked to AI-Powered Surveillance

Surveillance was another major area of concern. Anthropic reported nine cases involving attempts to use Claude for mass monitoring and profiling.

One suspected China-linked operation allegedly used information from WhatsApp and Telegram conversations to profile Uyghur communities and journalists. Claude was reportedly used for translation, analysis and simulated interactions.

The company also identified surveillance activity involving Catholic, Tibetan Buddhist, Taiwanese Presbyterian and Falun Gong communities.

In Iran, Anthropic said linked groups used multiple Claude accounts to profile thousands of individuals and analyse large volumes of social-media posts to identify opposition-related accounts.

The company emphasised that non-consensual surveillance and profiling violate its usage policies.

Claude Used in Cyber Espionage Operations

Anthropic said increasingly capable AI models can automate portions of sophisticated cyber operations.

In one case, a Russian-speaking actor allegedly used Claude during attacks against Ukrainian and European government, defence and diplomatic organisations, as well as drone manufacturers.

The activity reportedly involved reconnaissance, malware development and the theft of sensitive information.

Anthropic also described systems that could monitor whether malware had been detected and automatically modify malicious code in an attempt to evade security tools.

Another China-linked operation reportedly used multiple AI workflows for firmware analysis, open-source intelligence gathering and scheduled information collection, affecting organisations across several countries.

AI Used to Produce Propaganda and Influence Content

Anthropic also identified at least nine influence operations connected to countries including Russia, China, Iran, Bangladesh and Kenya. The company said Claude was used both to plan campaigns and generate misleading or politically motivated content.

Some operations reportedly involved state-linked media organisations. Other activity included producing propaganda material, creating forged documents and preparing administrative paperwork.

Anthropic said AI-generated content could achieve significant reach when distributed through established television, radio or other media channels.

Financial Crimes and Fake Dating Profiles

The report also covered financially motivated misuse. Anthropic said some operators connected to cybercrime networks used Claude while examining large numbers of Android application packages for exposed credentials and other sensitive information.

The company also detected a network of dating applications that presented AI-generated personas as real people. According to Anthropic, thousands of AI personas interacted with tens of thousands of genuine users, with the operators attempting to conceal the automated nature of the conversations.

The accounts and organisations associated with the activity were subsequently banned.

Rival AI Companies Accused of Model Distillation

Anthropic also reported cases involving competing AI companies and networks allegedly attempting to use Claude responses to improve their own models, a practice the company described as illicit distillation.

The report named organisations including Alibaba, Moonshot AI, DeepSeek, Zhipu, Xiaomi, SenseTime and MiniMax.

Anthropic said some campaigns generated millions of exchanges through large numbers of accounts. It responded by blocking accounts, investigating reseller networks, strengthening detection systems and introducing additional identity-verification measures.

Anthropic Strengthens AI Safety Measures

Across the reported cases, Anthropic said it removed abusive accounts and improved its safeguards. The company also shared relevant information with authorities, researchers, industry partners and affected organisations when appropriate.

The company said publishing the findings could help other AI developers recognise similar patterns and improve their own defences.

Conclusion

Anthropic’s report highlights how increasingly capable AI systems can be exploited across multiple areas, from biological research and weapons development to surveillance, cybercrime and propaganda. The findings underscore the need for stronger safeguards, threat detection and cooperation among AI companies, governments and security researchers as AI capabilities continue to advance.