Anthropic has identified several attempts by actors linked to Russia, China, Iran, and Yemen to misuse its Claude AI models for activities including weapons development, cyber surveillance, and digital attacks. These activities were detected and tracked over the previous eight months as part of the company's ongoing threat intelligence monitoring.
In its latest threat intelligence report, the AI developer detected a range of misuse cases including scams, fraud, biological misuse, and weapons development between December 2025 and August 2026. While the Claude Haiku, Sonnet, and Opus models were primarily involved, only one instance featured the Fable or Mythos models. Anthropic claims its specialized threat intelligence team disrupted every operation detailed in the report. “As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer,” the company stated.
The findings included five cases of biological misuse, notably an effort by state-sponsored virologists to engineer an enhanced version of the mosquito-borne chikungunya virus. Although Anthropic noted these biological cases were often ambiguous and could have involved benign research, the report also detailed efforts by Russian actors to develop software for an autonomous first-person-view kamikaze drone swarm, which utilized Ukrainian combat footage for training purposes.
Furthermore, actors based in northern Yemen utilized Claude in attempts to build software for various types of missiles, though Anthropic noted there is no current evidence that these efforts resulted in a functional operational device. Surveillance remains a significant concern, with actors from China and Iran attempting to monitor and profile individuals; in one instance, a China-linked operation used the AI to track, profile, and recruit Uyghurs within the Syrian Army.
In a separate and notable case, a consultant believed to be working for an intelligence agency in Mali, West Africa, used Claude to develop a system capable of monitoring approximately 25 million mobile phones. While Anthropic banned the account, the surveillance platform had already been deployed locally. The company emphasized that these cases represent its most novel threat activity to date, stating that the report is intended to help other developers and governments recognize emerging patterns to “strengthen collective defences.”