Anthropic says it has disrupted attempts by threat actors to use its Claude artificial intelligence (AI) models for activities linked to biological weapons research and missile development.
The US-based AI company disclosed this in its September 2026 threat intelligence report, titled ‘Detecting and Countering Misuse of AI’, published on Thursday.
The report examined malicious activity involving Claude between December 2025 and August 2026. The cases covered several areas, including cyber operations, influence campaigns, surveillance, conventional weapons, biological misuse, scams and fraud, and illicit distillation.
“The cases we share here aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date,” Anthropic said.
The company said it disrupted all the operations identified in the report and used information gathered from the incidents to improve its safeguards against potential misuse.
Anthropic said it identified five cases involving scientists who attempted to use Claude for biological research that could potentially contribute to biological weapons development.
In one case, a user tried to use Claude to prepare a grant application for gain-of-function research involving the chikungunya virus.
“The work discussed in the application involved gain-of-function research (that is, research that genetically alters an organism to create a new or enhanced biological property) on the chikungunya virus,” Anthropic said.
“This gain-of-function research was aimed at the virus’ transmissibility and immune evasion properties.”
According to Anthropic, the research could have legitimate purposes, including the development of vaccines or treatments, but could also increase the danger posed by the pathogen.
“Biological misuse is one of the most serious risks of frontier AI models. Without the correct safeguards, such capabilities could have catastrophic consequences,” the company said.
Anthropic said it did not disclose the institutions or countries connected to the biological research cases because it could not establish the users’ intentions with enough certainty.
The company also reported that “threat actors in China, Russia and Yemen used its models for weapons design, intelligence gathering and procurement activities”.
According to the report, a group linked to Yemen attempted to use Claude to obtain assistance with guidance, navigation and control software for ballistic missiles and guided rockets.
Anthropic said the group returned to Claude after a guided-rocket test failed, seeking help to troubleshoot the problem.
The company said it blocked most requests associated with weapons development and banned the accounts involved in the activities.
The report also highlighted other forms of misuse involving Claude, including cyber operations, surveillance, influence campaigns, scams and fraud.
Anthropic said AI is becoming increasingly involved in different stages of cyber operations, ranging from reconnaissance and tool development to data processing and exploitation.
The company said some threat actors deployed multi-agent systems to carry out reconnaissance, exploit targets and exfiltrate data, while human operators continued to determine targets and review stolen information.
Anthropic said it would continue improving its safeguards as threat actors find new ways to exploit increasingly capable AI systems.
Source: Anthropic






