Artificial intelligence is rapidly becoming more powerful—and a new investigation by AI company Anthropic is showing just how dangerous that power can become when it falls into the wrong hands.
Anthropic said threat actors used its Claude AI models in a series of operations involving weapons development, cyberattacks, surveillance, political influence campaigns, biological research and large-scale fraud.
The findings were detailed in Anthropic’s September 2026 threat-intelligence report, which examined malicious activity detected between December 2025 and August 2026. The company said it identified and disrupted the operations, banned accounts connected to the activity and strengthened its safeguards.
The report covers seven major areas of misuse: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons and illicit attempts to extract or copy AI capabilities.
AI Used to Support Weapons Programs
One of the most alarming findings involved conventional weapons.
According to Anthropic, threat actors in China, Russia and Yemen used Claude for activities connected to weapons development, procurement and military intelligence.
In one case, a China-based actor allegedly used Claude to develop an electronic-warfare system capable of analyzing radar and communications targets, evaluating vulnerabilities and helping determine which targets should be prioritized.
Anthropic said another operation involved software connected to a drone swarm, while other cases involved missile guidance, weapons-control systems and military procurement.
In Yemen, Anthropic said users in Houthi-controlled territory attempted to use Claude while working on advanced missile technology. Associated activity included a guided-rocket test that apparently failed, after which the users returned to Claude to troubleshoot the failure. AP reported that the actors had also created an offline simulation toolkit, meaning some of the work could continue without direct access to Claude.
Anthropic stressed that it did not conclude that every effort resulted in a functioning weapon. In some cases, the company said it disrupted the activity before an operational system was completed.
Spyware and Mass Surveillance
The report also revealed cases in which Claude was allegedly used to build surveillance infrastructure.
Anthropic said a consultant working with Mali’s national security authorities used Claude Code to help develop a mass-interception platform capable of monitoring communications across the country’s mobile networks.
The company said another operation linked to Iranian actors involved tools designed to identify people behind phone numbers, harvest identities and collect information from social-media accounts.
Anthropic said these operations violated its rules prohibiting non-consensual surveillance and activity that violates civil liberties and human rights. Accounts connected to the operations were subsequently banned.
The revelations are particularly significant because the AI was not merely being used to summarize information. In some cases, Anthropic said, Claude was being used to design, code, debug and improve the underlying surveillance systems themselves.
AI-Powered Scams on an Industrial Scale
Fraud was another major area of concern.
Anthropic identified a China-based operation involving more than 20 AI-powered dating applications and approximately 4,700 fake personas.
According to the company, those AI-generated identities interacted with at least 25,000 people. The operation reportedly combined AI-generated conversations with human workers who handled activities that the automated systems could not perform, such as live video interactions.
Anthropic said Claude generated approximately 2.36 million messages over a two-week period in the operation it investigated.
The case demonstrates how generative AI can potentially turn scams that once required large teams of people into highly scalable operations.
AI Is Also Being Used to Manufacture Influence
The threat report goes beyond conventional cybercrime.
Anthropic said it identified an influence operation in which Claude was used to generate original articles and rewrite legitimate news reports into politically slanted versions.
The network reportedly operated fake news websites, used fabricated journalist identities and attempted to improve the sites’ search-engine visibility.
Anthropic said the operation produced at least 8,913 articles in roughly 20 languages, targeting audiences in countries including the United States, Brazil, France and the Democratic Republic of Congo.
The company said much of the material generated little evidence of genuine audience engagement, but the operation demonstrated how AI could automate the production and distribution of political content at scale.
Biological Weapons Concerns
Anthropic also disclosed attempts to use Claude for research that could support biological weapons development.
The company said some scientists attempted to obtain assistance involving biological threats, including modified viruses and toxins.
CBS News reported that Anthropic said it disrupted activity that could have supported biological-weapons development.
Anthropic said these incidents were among the reasons it has continued developing systems designed to detect potentially dangerous requests and identify suspicious patterns of activity.
The Bigger Warning: AI Is Becoming an Engineering Workforce
Perhaps the most significant conclusion in Anthropic’s report is that AI misuse is evolving.
The danger is no longer limited to someone asking a chatbot a single harmful question.
Anthropic said sophisticated actors are increasingly using AI as an automated technical workforce—helping with programming, research, analysis, intelligence gathering and the coordination of complicated operations.
The company’s own testing found that AI models are becoming capable of performing certain intelligence-targeting and weapons-development tasks that historically required scarce, highly trained human specialists.
Reuters likewise reported that Anthropic found Claude being used across weapons development, surveillance, cyber operations and fraud, involving actors or operations associated with several countries.
Anthropic Says Its Safeguards Stopped the Operations
Anthropic emphasized that the cases in its report were not examples of unrestricted access to its systems.
The company said it detected the activity, banned the accounts involved, improved its detection systems and, where appropriate, shared intelligence with governments, law-enforcement agencies and other technology companies.
It also introduced additional classifiers intended to detect attempts involving weapons development and other high-risk activity.
Importantly, Anthropic said the misuse cases it documented primarily involved Claude Haiku, Sonnet and Opus. The company’s newer Fable and Mythos models were not involved in the reported misuse cases, with the exception of one illicit-distillation case.
What This Means for the Future of AI
The latest findings highlight a difficult reality facing the AI industry.
The same technologies that can help programmers, researchers, businesses and ordinary users can also potentially give malicious actors faster access to capabilities that previously required substantial expertise, money and manpower.
Anthropic’s investigation does not mean that AI independently carried out these operations. Humans remained responsible for directing the activities, acquiring resources and attempting to bypass safeguards.
But the report suggests that AI can dramatically increase the speed, scale and technical sophistication of what relatively small groups can attempt.
That is why the debate over AI safety is increasingly moving beyond chatbots and misinformation—and toward a much larger question:
As AI becomes capable of performing more complex work, how much power should it be allowed to place in the hands of people who intend to misuse it?

Leave a Reply