New Delhi: Anthropic has revealed a series of cases in which governments, state-linked groups, cybercriminals and other threat actors allegedly attempted to misuse its Claude artificial intelligence models for activities including espionage, mass surveillance, biological research, weapons development, cyber operations, influence campaigns and fraud.

The disclosures are part of Anthropic’s latest Threat Intelligence Report, which covers malicious activity identified and disrupted between December 2025 and August 2026. The company said its investigators identified and disrupted operations across seven broad areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and illicit model distillation.

Anthropic said the incidents do not represent typical use of Claude. Instead, they are among the most notable and novel cases identified by its threat intelligence team. The company said it banned accounts linked to the activity, strengthened its detection systems and, where appropriate, shared information with authorities and other technology companies.

The report highlights a growing concern for the artificial intelligence industry: increasingly capable AI models are no longer being used only to assist individual users. In some cases, threat actors are attempting to use them as an automated workforce capable of carrying out complex tasks at a much larger scale.

Anthropic identifies seven categories of AI misuse

Anthropic’s report covers activity across seven major categories.

These include cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and attempts to illicitly extract or reproduce AI model capabilities.

The company said the cases involved different types of actors, ranging from suspected state-sponsored groups and financially motivated criminals to commercial spyware vendors and politically motivated individuals.

Claude models from the Haiku, Sonnet and Opus families were involved in the cases described in the report. Anthropic said none of the reported misuse cases involved its Fable or Mythos-class models, apart from one illicit distillation case.

The findings indicate that malicious actors are increasingly interested in AI not simply as a conversational tool but as a way to automate parts of complicated operations.

This distinction is important. Traditional cyber or intelligence operations can require teams of programmers, researchers and analysts. AI agents can potentially allow a much smaller number of people to coordinate several tasks simultaneously.

Anthropic said this development was visible across multiple investigations.

AI allegedly used for mass surveillance

One of the most concerning areas highlighted by Anthropic is surveillance.

The company said it identified several operations between January and July 2026 in which state-aligned actors, state-linked contractors and commercial spyware vendors used Claude to build, operate or facilitate surveillance systems.

The reported cases involved actors linked to China, Iran and West Africa, as well as companies operating in the commercial surveillance-for-hire sector.

In one case described by Anthropic, a consultant working for Malian national security authorities allegedly used Claude to help engineer a mass-interception platform capable of monitoring communications across the country’s mobile operators.

Anthropic said the platform was designed to collect telecommunications information and generate intelligence dossiers. The company stressed that Claude was being used primarily as an engineering tool for the underlying surveillance system rather than simply analysing information already collected.

The report also describes alleged Iranian activity involving surveillance infrastructure and tools intended to identify individuals.

Anthropic said its policies prohibit non-consensual surveillance and profiling, as well as activities that violate civil liberties and human rights. It said the accounts associated with these operations were banned.

Espionage operations increasingly use AI agents

Another major finding concerns espionage.

Anthropic said it identified an operation in which threat actors used what it described as agent swarms. In this arrangement, a lead AI agent could divide a larger intelligence task into smaller assignments and distribute them among multiple AI agents working in parallel.

The operation also maintained persistent campaign information, allowing activity to continue across separate sessions. According to Anthropic, information such as target lists, harvested credentials and the status of ongoing activity could be retained for future work.

The company said the actors also built an intelligence-collection platform capable of automatically gathering publicly available information relevant to state intelligence priorities.

This development is significant because it shows how AI can potentially change the economics of intelligence gathering.

Tasks that once required researchers to manually monitor large numbers of sources can increasingly be automated. AI can sort information, identify patterns and produce summaries, allowing human operators to concentrate on decisions and higher-level objectives.

Anthropic said it disrupted the activity and banned the accounts involved.

Biological misuse raises new safety concerns

Anthropic also disclosed cases involving attempts to use AI for biological research with potential misuse implications.

The company said its earlier biological safety measures were designed largely around preventing AI from providing assistance that could help inexperienced users recreate known biological weapons. However, as modern AI systems become more capable of assisting with sophisticated scientific research, Anthropic said the risk landscape is becoming more complicated.

The company said it has therefore introduced stronger safeguards in newer models, including restrictions covering a wider range of dual-use biological research queries.

Anthropic also cautioned that capability evaluations do not by themselves demonstrate that a biological weapon will be created in the real world.

However, the company said evidence from academic research, government reports and other investigations has made it necessary to take the potential risk seriously.

The biological findings therefore represent one part of a wider debate over how AI developers should balance useful scientific assistance with safeguards against dangerous applications.

Claude was also targeted for weapons development

Anthropic’s report describes another category involving conventional weapons.

The company said it identified multiple threat actors who allegedly used Claude to support weapons-related development, intelligence gathering or procurement activities.

The cases involved actors in China, Russia and Yemen, according to the report. Anthropic said the activity included attempts to use AI for software associated with guided weapons, drones and other military systems.

The company also said some actors attempted to hide their intentions from its safeguards by disguising the purpose of their work or dividing tasks across multiple sessions.

Anthropic has subsequently introduced additional classifiers designed to detect and block activity related to high-yield explosives and weapons development.

A separate India Today report, citing Anthropic’s findings, said Iran-aligned Houthi actors in Yemen may have used Claude Code in attempts to develop software for several weapons programmes. Anthropic’s report said one guided-rocket field test appeared to have failed, although the company did not establish that an operational weapon had ultimately been deployed as a result of the activity.

AI is becoming an engineering workforce

One of the most important conclusions from Anthropic’s report is that AI is increasingly being used as a substitute for parts of an engineering workforce.

In some of the cases investigated, a small number of operators were reportedly able to use AI to perform tasks that would previously have required programmers, analysts or researchers.

This does not mean AI independently carried out every operation. Human operators remained involved in directing the activity, selecting objectives and managing the wider operation.

However, AI can reduce the amount of specialised human labour required to execute certain tasks.

Anthropic’s findings suggest that this shift is particularly important for cybersecurity, surveillance and intelligence operations, where large quantities of information must be processed quickly.

The company’s own research into AI capabilities found that modern models can perform certain tasks in military and intelligence domains that historically required scarce, highly trained human expertise.

That capability creates a difficult security challenge because the same skills can have legitimate applications in areas such as cybersecurity research, software development and scientific work.

Safeguards are becoming a central part of AI development

Anthropic said it has responded to the incidents by banning accounts, improving detection systems and sharing relevant intelligence with partners and authorities.

The company also said it has developed behavioural detections based on the techniques observed during its investigations.

The objective is not simply to block individual prompts. Instead, AI companies are increasingly trying to identify broader patterns of behaviour that could indicate malicious activity.

This is becoming particularly important as AI agents become capable of performing multiple tasks and interacting with external systems.

Anthropic’s September report said sophisticated threat actors continuously test safeguards and attempt to circumvent technical measures designed to prevent misuse.

The company therefore argues that safety measures need to evolve alongside model capabilities.

The challenge extends beyond one AI company

Anthropic’s findings also highlight why AI misuse cannot be addressed by a single company alone.

The report said some actors used infrastructure designed to access and rotate between multiple AI models. In one case involving biological research, Anthropic said the threat actor deliberately used multiple AI providers for separate roles.

This means that banning an account from one platform may not necessarily end an operation.

AI companies, cybersecurity firms, governments and researchers may therefore need to share information about emerging misuse patterns.

Anthropic said it shared indicators and intelligence with industry partners and authorities in cases where activity extended beyond its own platform.

Such cooperation could become increasingly important as AI tools become more widely available.

What the report means for the future of AI

Anthropic’s latest report does not suggest that Claude itself autonomously decided to conduct espionage, surveillance or weapons development. The incidents described involve people and organisations deliberately attempting to use an AI system for activities prohibited under the company’s policies.

The significance lies in the scale and sophistication of those attempts.

AI models can help people write software, analyse information, conduct research and automate repetitive work. Those same capabilities can be redirected towards harmful objectives.

As models become more capable and increasingly agentic, the potential impact of misuse could grow.

Anthropic’s report therefore provides another warning that AI safety cannot be treated only as a question of what a model says in a conversation. Developers must also consider how AI systems are connected to tools, databases, code environments and other digital infrastructure.

For companies developing frontier AI models, the challenge will be to preserve legitimate uses while making it increasingly difficult for malicious actors to turn those capabilities into scalable harmful operations.