Anthropic, the AI company behind the Claude models, has reported disrupting multiple malicious uses of its technology between December 2025 and August 2026, including attempts to develop missile guidance systems, conduct biological research with weapons potential, and orchestrate cyber espionage campaigns. The company published its findings in a 154-page threat intelligence report released on September 10, 2026, detailing six disrupted operations involving state-linked actors in Yemen, China, and Russia.
Anthropic confirmed two primary developments: First, a Yemen-based weapons engineering cell used Claude Code to develop guidance software for missiles, including a multi-stage ballistic missile with a 2,000+ km range and a hypersonic glide vehicle variant. While no operational weapons were fielded, the group conducted a test launch of a guided rocket, which failed. Second, Anthropic blocked attempts by actors in China and Russia to use Claude for biological weapons research, including experiments involving highly contagious viruses like chikungunya and bird flu, as well as efforts to design novel toxins.
Immediate Actions and Official Responses
Anthropic took direct enforcement actions against the identified actors, including terminating accounts, restricting model access, and implementing new safeguards in its latest models. The company emphasized that its interventions were preventive, as none of the misuse cases resulted in completed weapons systems or successful biological experiments. Anthropic stated in its report: “We’re publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer.”
The report also highlighted covert AI misuse techniques, including:
- Multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration in cyberattacks.
- Distillation attacks by Chinese AI labs, where outputs from Claude were used to train rival models without authorization. Anthropic identified seven labs—including Alibaba, Moonshot, DeepSeek, Xiaomi, and Zhipu—as engaging in these activities.
- Biological safety classifiers blocking requests for research on gain-of-function experiments at military-affiliated institutions.
Deeper Dive: Methods, Actors, and Implications
1. Missile Development in Yemen
Anthropic’s report details how a Yemen-based weapons cell used Claude Code to develop guidance, navigation, and control software for missiles. The group:
- Integrated an open-source autopilot with a phone-class flight computer.
- Wrote control and position-estimation software, tuned flight settings, and conducted flight simulations.
- Used multiple Claude instances simultaneously, assigning tasks such as coding, research, and code review to different instances.
- Attempted to circumvent safeguards by concealing their intent, splitting activities across sessions, and using evasion techniques.
While the group tested a guided rocket, the launch failed, and Anthropic found no evidence of a fielded operational weapon. The report notes that the actors were working on multiple missile programs, including a multi-stage ballistic missile with a stated range exceeding 2,000 km.
2. Biological Weapons Research Attempts
Anthropic identified five cases where actors used Claude to plan experiments with dual-use potential, including:
- Research into chikungunya virus transmissibility and immune evasion.
- Studies on orthopoxvirus immune-response genes.
- Design of novel toxins, with actors taking steps to evade safeguards.
- A grant application for funding at a military research institute to study chikungunya, which Anthropic’s safety classifier blocked.
The company stressed that it does not claim the actors intended to develop biological weapons but noted that the research could theoretically be repurposed for harmful applications.
3. Covert AI Distillation by Chinese Labs
Anthropic accused seven China-based AI labs of conducting illicit distillation attacks, where outputs from Claude were used to train rival models. Key findings include:
- Alibaba’s operation was the largest measured, with 151 million exchanges between May and July 2026 from 3,500 fraudulent accounts. The company used Claude’s reasoning processes to train its Qwen models.
- Moonshot routed 23 million customer requests to Claude between May and July, displaying responses to users as if they were from its Kimi models. Anthropic described the network of 5,380 accounts as fraudulent.
- DeepSeek rerouted 12.1 million requests to Claude over 14 days in July, using the responses to train its models.
- Some exchanges included sensitive data, such as CCTV footage from a PLA-affiliated user and information from a Russian government database submitted by a military contractor.
Anthropic described distillation as “an industrial-scale, covert campaign to extract a model’s capabilities and replicate them in another model without authorization.”
4. Cyber Espionage and State-Linked Threats
The report also detailed cyber operations linked to state actors:
- A Russia-based group, consistent with Midnight Blizzard, used AI for phishing, hotel Wi-Fi hijacking, and surveillance targeting military intelligence, diplomatic organizations, and U.S. foreign policy figures.
- Chinese state-linked labs were accused of replicating Claude’s capabilities to improve their own models.
- Anthropic noted that humans remained involved in selecting targets and reviewing exfiltrated data, even as AI executed reconnaissance and exploitation tasks.
Broader Context and Industry Response
The report comes amid growing concerns about AI’s dual-use potential and calls for stricter safeguards. Key reactions include:
- U.S. Senator Bernie Sanders demanded a pause on advanced AI development and a ban on artificial superintelligence, citing the report’s findings.
- President Donald Trump dismissed fears, stating that the U.S. must lead in AI development to avoid falling behind.
- Former Anthropic researcher Jacob Coxon resigned, accusing the company of “racing straight to self-improving superintelligence and gambling with our lives.” His warning drew over 100 million views on social media.
- Anthropic has strengthened its biological safety classifiers and multi-agent framework detection in response to the identified threats.
The company’s report concludes with a call for collaboration between AI developers, governments, and civil society to mitigate risks, stating: “These cases aren’t typical misuse but examples of the most notable and novel threat activity we’ve identified to date.”