Anthropic’s artificial intelligence models have been targeted by criminals, state-sponsored groups, spyware vendors, scientists, and propagandists attempting to design missiles and bombs, create deadly pathogens, and surveil dissidents, according to a threat intelligence report published by the company on Thursday.
Threat Actors Exploit Claude for Weapons and Cyberattacks
According to the 154-page threat intelligence report from Anthropic, malicious actors used its AI models across multiple domains. “The cases we share here aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date,” Anthropic stated in the publication. The company noted that it published the work because of a responsibility to disclose malicious misuse of its services.
The report detailed dozens of threat actor examples. These included Russian espionage and smash-and-grab cyberhacks, alongside surveillance programs such as a China-based operation targeting Uyghurs in Syria and another targeting internal dissidents. Propaganda campaigns spanned Russia, Malaysia, Iran, and Bangladesh. Furthermore, threat actors used the Claude AI model in Yemen, China, and Russia to develop software for conventional weapons, including firearms, missiles, armed drones, bombs, and other munitions.
Did you know? Anthropic’s threat intelligence report spans 154 pages, detailing everything from state-sponsored cyber espionage to biological research circumventions and conventional weapons software development.
Scientists Circumvent Safeguards for Biological Research
Anthropic dedicated specific focus to five case studies involving scientists using its AI models in biological research. According to the report, these researchers circumvented safeguards meant to block users from unsupported regions and actively worked to hide the purpose of their work. “Biological misuse is one of the most serious risks of frontier AI models,” Anthropic wrote. Without correct safeguards, the company warned, such capabilities could trigger catastrophic consequences.
In one biological research example, Anthropic found a scientist using Claude to work on a state-sponsored grant application to study the chikungunya virus. This mosquito-borne disease is similar to dengue and malaria, causing months of severe pain, fever, and debilitating symptoms. While such research can aid in developing vaccines, it can also facilitate the creation of biological weapons. Anthropic informed the New York Times that this case raised deep concerns because the study was slated for a military research institute. Anthropic banned the accounts involved, though it withheld the names of the research institutions and countries due to uncertainty regarding the researchers’ intent.
Internal Resignation Sparks Debate Over Real-World AI Threats
The threat intelligence report arrived just two days after Anthropic employee Jacob Coxon resigned, setting off a media firestorm. Coxon stated he quit because the company was not acting responsibly in creating its technology, claiming that Anthropic and rival OpenAI were racing toward self-improving superintelligence that could cause human extinction by 2030. Current Anthropic employees publicly agreed with his stance.

However, many AI experts argue that real-world threats detailed in intelligence reports remain far more pressing over the next three years than an apocalypse driven by an omnipotent intelligence. “AI accelerationism and AI doomerism are two sides of the same coin: they both enforce the notion that an AGI superbeing will come into existence,” said Heidy Khlaaf, chief AI scientist at the AI Now Institute. Khlaaf pointed out that labs building technology exploitable for cybersecurity and warfare present a much deadlier near-term risk.
Anthropic emphasized that potential real-world misuse usually stays hidden from public view, investigated only internally, by academics, governments, and international organizations. The company asserted that the entire AI industry must collaborate with governments to address these harms and build defenses. “As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer,” Anthropic concluded.
Frequently Asked Questions
What kinds of misuse did Anthropic uncover in its report?
According to Anthropic’s threat intelligence report, bad actors attempted to use AI models to design missiles and bombs, create deadly pathogens, conduct espionage, run propaganda campaigns, and surveil dissidents.

Did Anthropic identify the researchers attempting biological misuse?
Why did employee Jacob Coxon resign from Anthropic?
Jacob Coxon resigned because he stated the company was not acting responsibly in developing technology that he claims is racing toward self-improving superintelligence capable of causing human extinction by 2030.
Stay Informed on AI Safety
Want to track the latest developments in artificial intelligence security and industry regulations? Subscribe to our updates or leave a comment below to share your perspective.
Worth a look