Amid intensifying debate about the threats and responsible use of artificial intelligence, Anthropic, the US research company behind the Claude family of large language models and other artificial intelligence products, has published several cases of misuse of its systems, warning of growing risks as artificial intelligence models become more capable.
In a 154-page report published on Thursday (September 10, 2026), the firm disclosed several malicious activities detected and disrupted between December 2025 and August 2026 that had significant impacts in seven key areas: fraud and deception, cyber operations, illicit trafficking, influence operations, surveillance operations, conventional weapons and misuse of biological materials. Those behind the discovered abuses included suspected state-sponsored groups, financially motivated criminals, state propaganda outlets, and politically motivated individuals.
While the capabilities of artificial intelligence systems to target cyber operations, spread disinformation, and provide surveillance have been debated since their inception, the extent of biological abuse is a relatively new phenomenon. In a report titled “Detecting and Countering the Misuse of AI,” Anthropic called biological abuse “one of the most serious risks” of advanced AI, which could have “catastrophic consequences” without proper safeguards.
The report, coincidentally, comes the day after Jacob Coxon, an artificial intelligence researcher at Anthropic, left his post, saying that artificial intelligence companies are “playing with our lives” and that the people creating artificial intelligence “genuinely believe that it could kill us all by the end of the decade.”
What threats are highlighted in the report?
The Anthropic report provides examples of the most notable and emerging malicious activities, ranging from fake dating apps designed to deceive users to sophisticated surveillance systems designed to monitor dissidents identified and stopped by the Threat Intelligence team.
According to Anthropic, most of the operations mentioned in the report were directly performed or orchestrated by AI. The use of AI included multi-agent structures for reconnaissance, filtering and exploitation of data instead of simple question-and-answer chatbots. People were involved in setting goals and verifying the facts of the leak, the report says.

The development of artificial intelligence models has bridged the gap separating well-resourced state-sponsored actors and individual operators, says the Anthropic report. He noted that just a year ago, most emergencies would have required several skilled operators with specialized knowledge.
The first case mentioned in the report is “Russian espionage,” where operators, including Russian speakers, automated actions using AI to evade detection and bypass cyber defenses. They carried out operations directed against Ukrainian military intelligence targets and European governments, and their actions were “consistent with Russian state espionage.”
The report also detailed targeted propaganda and disinformation campaigns in which operators used Claude to create networks of social media profiles and entire news sites to publish misleading content. Nine cases were cited as examples of such “influence operations” by organizations including state media from Russia, Iran, Turkey, as well as the Gulf, South Asia, Africa and Europe that targeted audiences on six continents.
He noted the proximity of several of these campaigns to elections in the target region, saying Russian state media produced fabricated claims about the Moldovan president ahead of the September 2025 vote, and a pro-government operator in Kenya prepared fake mass social media posts ahead of Kenya’s upcoming general elections.

Anthropic said it identified and removed four accounts in which individual actors used Claude as a news production unit to distribute content through Russian state media. Content created by Claude was published and broadcast through Russian state media, including Sputnik Moldova and RIA Novosti for Moldovan audiences, Sputnik en Español for Latin American audiences and Sputnik Africa for African audiences.
Activities in the Indian subcontinent
Coming to the Indian subcontinent, Anthropic said it had curtailed operations promoting the Awami League in Bangladesh, the party of former Prime Minister Sheikh Hasina. The report cites a “single actor” who created at least 1,500 headlines, 300 false narratives and 1,500 images (Claude does not yet have an image creation function) using custom software connected to a large language model aimed at an internal audience.
It says some content is also in line with pro-India geopolitical interests. However, the report found no evidence of any government direction or funding for these efforts.

The report also said Anthropic disrupted several operations based in China, including a “public opinion monitoring” and dissident surveillance operation, a surveillance and recruitment operation against Uyghurs in Syria, a religious intelligence operation targeting Catholic, Tibetan Buddhist and Taiwanese Christian communities, and a public and state security “stability and transnational surveillance” campaign. repression.”
What does the report say about biological abuse?
Anthropic stressed that the possibility that AI models will reach a stage where they can make existing pathogens more dangerous or even create entirely new ones has long been a concern. Anthropic said it wants AI models to be useful for scientific research and predicted that AI will change biology.
However, he also acknowledged the “dual use” of biological capabilities of artificial intelligence systems, and advances have made it difficult to distinguish between beneficial and harmful targets.
While earlier models clearly showed that they were not advanced enough to provide meaningful assistance in dangerous biological research, Anthropic said that is no longer clear with current models that are capable of taking part in complex research activities. The report presents five cases of Anthropic models being used to support biological weapons development.
In May of this year, Anthropic blocked Claude’s request for help writing a grant application for scientific funding for work involving research that genetically alters an organism to create improved biological capabilities against the chikungunya virus. The study in question was aimed at studying the transmissibility of the virus and its immune evasion properties.
While the report did not specify where the request came from, it said information in the request suggested the research was conducted by civilians but was expected to be conducted at a military facility.
That same month, Anthropic noted “outside the US” research using Claude in a study of highly pathogenic avian influenza (avian influenza), which focused on the adaptation of the virus to mammals and the mechanism by which it causes severe disease outside the respiratory tract.
The third case involved a grant proposal written for covert access to a frontier model for research into the orthopox virus, which can disable the immune response of host organisms. The remaining two cases were related to investigations into new non-infectious poisons and toxins.
While all of this activity was stopped by Anthropic, it also noted that there was only equivocal evidence of dangerous biological uses of AI. The department said the activity was stopped out of an “abundance of caution” and added that strict safeguards against such activity had been put in place.
It said the cases do not indicate the imminence of biological threats, but demonstrate significant dual-use research efforts involving state actors.