
Someone tried, and Anthropic says it stopped them. The company published a threat intelligence report on September 10 detailing attempts to misuse Claude for biological weapons research, state-linked hacking, and propaganda between December 2025 and August 2026. It says it disrupted every operation described.
Anthropic just published its most detailed public account yet of how it caught them.
Anthropic's report spans seven categories of attempted misuse detected between December 2025 and August 2026:
Biological misuse
Conventional weapons development
Cyber operations
Influence operations
Surveillance
Scams and fraud
Unauthorized model replication
This is Anthropic's third public disclosure of this kind since March 2025. The company says it identified and disrupted every operation described in the report before it caused harm, and that it has since strengthened its safeguards.
We helped organizations choose the right AI platform, integrate, and scale AI solutions that drive real business impact and track measurable results.
Book a Free ConsultationA few examples stood out. Anthropic says it identified a likely freelance, Russia-based actor using its coding tool to test code tied to a drone swarm project. Separately, it banned accounts linked to Chinese state security organs using its AI to support online censorship and dissent suppression. A third operation, tracked as GTG-20006, targeted government ministries, defense and intelligence organizations, and embassies, with particular focus on Ukrainian military drone technology providers.
Jacob Klein, Anthropic's head of threat intelligence, told the New York Times the picture isn't simple; sophisticated actors keep testing the same safeguards in new ways.
The report was published one day after Anthropic researcher Jacob Coxon publicly resigned, writing that neither Anthropic nor OpenAI is "acting responsibly" and that the industry is "racing straight to self-improving superintelligence and gambling with our lives." That resignation fits a broader pattern of safety-focused departures and disclosures this month, including OpenAI's own recent security incident involving its AI agents.
Anthropic, for its part, frames the disclosure as routine vigilance rather than a new problem: "Sophisticated and persistent threat actors continuously test our safeguards and try to circumvent the technical measures we use to detect and prevent misuse," the company wrote.
This report reminds us that any AI system powerful enough to help legitimate research is also powerful enough to attract misuse, and catching it requires active monitoring, not just upfront safeguards. A few takeaways for organizations deploying AI at scale:
Assume your AI vendor's safety systems are being actively tested by bad actors, not just employees
Ask vendors what ongoing misuse detection looks like, not just what's built in at launch
Build your own usage monitoring for AI tools handling sensitive workflows
If your organization needs help thinking through AI security and misuse monitoring, our generative AI services team can help you build the right safeguards from the start.
Anthropic published its third public misuse report on September 10, 2026
It covers seven categories, including biological misuse and state-linked cyber operations
The company says it disrupted every operation described
The report follows a researcher's public resignation over AI safety concerns the day before
We are more than just developers and consultants—we are your partners in navigating the digital landscape. Let us be the engine behind your next big success while you focus on your core vision.
Explore Opportunities!