Anthropic says users tried to employ Claude for weapons, pathogens and surveillance
The company says it disabled the identified operations, but its threat report shows how general-purpose AI is lowering barriers across military, biological and intelligence activity.
A broader catalogue of attempted misuse
Anthropic says criminals, state-linked groups, researchers, spyware operators and propagandists attempted to use its Claude models for activities ranging from cyberattacks to conventional-weapons development and biological research. The company’s new threat-intelligence report describes efforts involving missile and drone software, surveillance of dissidents, influence campaigns and research that could have both legitimate scientific and dangerous military applications.
The company said it detected and disabled every operation included in the report. It did not identify the institutions or countries behind several biological cases and said the intent of some researchers remained uncertain. That qualification matters: assistance with a study of a virus such as chikungunya could contribute to vaccines, but similar knowledge and laboratory planning could be redirected toward harmful pathogen work. The report therefore documents risk indicators rather than proving that a biological weapon was completed.
Weapons, espionage and influence operations
The cases described by Anthropic included attempts in Yemen, China and Russia to develop software associated with firearms, missiles, armed drones, explosives and other munitions. The report also identified Russian cyberespionage activity, rapid criminal hacking, China-linked monitoring of Uyghurs in Syria, surveillance of domestic dissidents and propaganda work connected with Russia, Malaysia, Iran and Bangladesh. These examples show one model being applied across several established security threats rather than creating an entirely new category of conflict.
The central change is speed and accessibility. A general-purpose assistant can help users organise technical information, draft code, translate material and iterate through complex tasks. The US National Security Agency previously warned that adversaries were already using AI to increase the speed, scale and sophistication of offensive cyber operations, including spear-phishing, deepfakes and support for nation-state hackers. Anthropic’s cases provide a company-level snapshot of that broader pattern.
What the report does not settle
The findings come from Anthropic’s internal visibility into its own service. They do not measure misuse conducted through open models, rival platforms or systems operated entirely outside monitored commercial infrastructure. They also depend on the company’s detection methods and judgments about which activity was suspicious. That makes independent assessment important, particularly where Anthropic withholds identities to protect investigations or cannot determine intent.
The immediate policy question is whether voluntary monitoring and account bans are sufficient as models gain more capable coding and scientific functions. Governments and developers will need mechanisms for confidential incident sharing, independent evaluation and rapid coordination when risks cross borders. The report strengthens the case for treating AI security as an operational national-security problem now, while maintaining a clear distinction between attempted misuse, demonstrated capability and a successfully completed attack.