Anthropic Reveals Growing Scale of AI Misuse
Anthropic has published its most detailed threat intelligence report to date, documenting attempts to misuse Claude for cyberattacks, influence operations, surveillance, biological research and conventional weapons development. The company said it disrupted every operation described in the report and used information from the investigations to improve its safeguards.
The report covers malicious activity identified between December 2025 and August 2026 across seven areas, including cyber operations, influence campaigns, surveillance, scams and fraud, biological misuse, weapons development and attempts to extract or replicate AI capabilities. Anthropic said it also shared intelligence with authorities and other technology companies where appropriate.
One of the most important findings concerns the changing role of AI in cyber operations. Anthropic said attackers are increasingly moving beyond using Claude as a simple chatbot and are instead incorporating AI into multi-agent systems capable of reconnaissance, exploitation, data processing and exfiltration.
In some cases, the human operator remained responsible for selecting targets and reviewing results. In others, AI agents performed large portions of the operational process with limited supervision, including running reconnaissance and collection tasks in parallel. Anthropic said this can reduce the expertise, time and labor required to conduct sophisticated campaigns.
That shift could change the economics of cybercrime. Operations that previously required teams of specialized experts can potentially be attempted by smaller groups using AI to fill gaps in technical knowledge. Anthropic said the result is a widening range of actors capable of conducting campaigns that previously would have been associated with more highly resourced organizations.
The company also documented influence operations in which Claude was used to create fake personas, produce political content and operate networks of fabricated websites and social media accounts. One operation generated at least 8,913 articles in about 20 languages, although Anthropic said most of the material received little observable engagement from genuine audiences.
AI Security Is Becoming an Ongoing Arms Race
Surveillance was another major category in the report. Anthropic identified cases involving state-aligned actors and commercial surveillance operators using Claude to develop software, analyze information, profile people and support intelligence-gathering activities. The company said it banned the accounts involved and strengthened detection systems based on the techniques it observed.
The report also describes attempts to use Claude in conventional weapons development. Anthropic said threat actors used the model to support software and firmware related to guided rockets, drones, electronic warfare and other military systems, while separate actors used Claude for weapons-related intelligence and procurement research.
Anthropic’s Frontier Red Team also conducted new evaluations of AI capabilities in tactical intelligence and conventional weapons tasks. The company said some models could perform tasks that historically required scarce, highly trained human expertise, reinforcing the need for safeguards around these capabilities.
Biological misuse represents another area of concern. Anthropic said newer models are capable of assisting with increasingly complex scientific research, making it harder to guarantee that they cannot meaningfully assist sophisticated users with dangerous biological work. As a result, the company has introduced stronger restrictions around certain dual-use biological research queries.
Related: Anthropic Researcher Resigns, Warns AI Race Could Put Humanity at Risk
At the same time, Anthropic’s report offers an important qualification: these cases are not representative of ordinary Claude usage. The company described them as some of the most sophisticated misuse it has encountered, selected because they reveal where AI-enabled threats are heading and where existing defenses need improvement.
The report also shows why blocking individual prompts may not be enough. Threat actors can divide projects across multiple sessions, use different accounts and attempt to conceal their ultimate objectives. Anthropic said some operators built persistent workflows in which AI agents maintained campaign information and continued tasks across sessions.
This creates a difficult security problem for AI companies. As models become more capable, the same improvements that make them useful for software development, research and automation can also make them more useful to malicious actors. Security systems therefore need to detect not only individual requests but patterns of behavior and the broader operational context.
Anthropic says its response has included banning accounts, improving automated detection, developing new classifiers and sharing threat intelligence with external partners. The company has also emphasized that its investigations provide a useful vantage point because AI providers can sometimes identify malicious activity while an operation is still being built rather than after the damage is complete.
For the wider AI industry, the report highlights a growing race between model capabilities and security controls. The more autonomous AI systems become, the greater the potential benefit for legitimate users, but also the greater the potential scale and speed of misuse.
Anthropic’s findings ultimately suggest that AI safety is no longer only about preventing a model from producing a dangerous answer. The bigger challenge is controlling how increasingly capable models are incorporated into larger automated systems, particularly when users attempt to turn them into persistent operational agents.
The company said it is publishing the findings so other AI developers, governments and researchers can recognize similar activity on their own platforms. If AI-enabled attacks continue becoming cheaper and more autonomous, sharing threat intelligence may become as important to AI security as improving the models themselves.















