Anthropic says malicious actors are no longer using AI only to write code, answer questions or give suggestions. AI is increasingly being used to plan, execute and automate entire operations.

AI is becoming more powerful,but so are the attempts to misuse it. OpenAI rival Anthropic has released its most detailed threat intelligence report. In its report, the Dario Amodei’s AI startup revealed that how people and organisations tried to use its Claude AI models for cyberattacks, surveillance, influence operations, biological misuse and weapons development.
“We’re publishing our most detailed threat intelligence report to date. It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them,” the US-based AI startup wrote on X.
Anthropic said its Threat Intelligence team identified and disrupted these operations over the past eight months. The company said it also used the findings to improve its safety systems and, where appropriate, shared information with governments, authorities and other technology companies.
“These cases are not typical: we’re highlighting some of the most sophisticated misuse we’ve seen. But they’re especially important to discuss, because they show us where AI misuse is headed, where our safeguards work, and where they need to improve,” Anthropic wrote in detailed post on the Elon Musk-owned social media platform.
The report covers activity detected between December 2025 and August 2026.
Claude Used In Cyberattacks
One of the biggest concerns revealed in the report is the growing role of AI in cybercrime. The Claude AI chatbot maker said attackers were no longer using Claude simply to ask questions or generate code. In many cases, AI was used to support large parts of cyber operations, including exploitation, data theft and gaining access to compromised systems.
In one case linked to suspected Russian espionage, attackers used AI to target government, defence and diplomatic organisations.
Anthropic said they used Claude at different stages of the attacks. The campaign targeted Ukrainian government and military organisations, european governments, diplomatic organisations, defence organisations, Think tanks, defence companies and drone manufacturers and suppliers.
Surveillance And Influence Operations
Anthropic also found cases where Claude was used to build surveillance systems and monitor people online.
The report says some government-backed groups used Claude to collect and analyse information about people online, build their profiles and create intelligence reports. In Mali, one group also used Claude to help develop a system for monitoring mobile communications.
The company also uncovered AI-powered influence campaigns. In one case, Claude was used to generate thousands of articles for a network of fake news websites and matching social media accounts across multiple countries.
Anthropic says Iranian actors used Claude to develop surveillance infrastructure, including a malicious Firefox extension designed to harvest user identities from social networks. Another system analysed 155,216 tweets and was connected to a central surveillance platform. According to the company, the actors used AI for coding, engineering and data analysis.
AI And Weapons Development
The report also found that some people tried to use Claude for weapons-related work. Anthropic said it identified six cases involving conventional weapons development, intelligence gathering or procurement. These included attempts involving guided weapons, an anti-torpedo system, autonomous military drones and electronic warfare software.
In one Russia-based case, attackers used Claude to develop software for an autonomous drone swarm.
In another case in Yemen, Claude was used to help develop guidance software for a guided rocket that was later test-fired, although Anthropic said it does not have evidence that an operational weapon was successfully deployed.
Anthropic said it also identified biological misuse and other harmful activity in its investigations. The company said it banned the accounts linked to the operations, improved its detection systems and shared threat intelligence with outside partners when necessary.
“Biological misuse is one of the most serious risks of frontier AI models. It has long been a concern that AI models might one day reach the level of capability where they can help to make existing pathogens more dangerous—or create entirely new ones. Without the correct safeguards, such capabilities could have catastrophic consequences,” said Anthropic.
Anthropic says its older models were clearly below the level where they could meaningfully help sophisticated users with dangerous biological research. But with newer, more capable models, Anthropic says it can no longer make that same assurance.