Anthropic has disclosed that it identified and disrupted multiple state-sponsored operations that leveraged its Claude artificial intelligence models for military-grade weapons development, cyber-espionage, and mass surveillance. The findings, detailed in a comprehensive threat intelligence report covering activity between December 2025 and August 2026, highlight the growing challenge of preventing advanced AI from being repurposed for malicious state objectives. The company reported that actors from China, Russia, Iran, and Yemen attempted to exploit the platform for tasks ranging from missile guidance software development to the identification of dissidents abroad.
These revelations arrive at a sensitive time for the San Francisco-based AI lab, which has been navigating a complex relationship with the United States defense establishment. While Anthropic maintains strict usage policies prohibiting the design of weapons, the report demonstrates that state-aligned actors are increasingly employing sophisticated techniques to circumvent these safeguards. By breaking complex tasks into smaller, non-suspicious prompts and using the AI as an orchestration layer for automated workflows, these groups have sought to bypass automated detection systems, forcing the company to refine its monitoring and intervention strategies.
Weapon Systems and Conventional Military Development
Anthropic's report identified six specific cases where its models were used to develop software for conventional weapons, including firearms, missiles, armed drones, and bombs. In one notable instance, actors in northern Yemen attempted to use Claude to write guidance and control code for a long-range ballistic missile and a guided rocket. The operators reportedly assigned specific roles to different instances of the model, effectively using the AI as a substitute for human software engineers to handle complex flight-control logic.
While the company stated it has no evidence that these groups successfully fielded a working weapon, it did confirm that the operators appeared to have conducted an unsuccessful test-fire. Anthropic intervened by banning the accounts involved and sharing intelligence with relevant public and private-sector partners. The company noted that the operators were able to avoid initial detection by obscuring their ultimate goals, demonstrating a level of operational maturity that challenges existing safety guardrails.
Cyber-Espionage and Automated Surveillance
Beyond conventional weaponry, the report detailed how state-linked actors are utilizing AI to scale cyber-espionage and surveillance operations. A Russian-linked group, identified as having hallmarks consistent with the threat actor known as Midnight Blizzard, reportedly used automated AI workflows to manage nearly the entire lifecycle of an espionage campaign. This included phishing, infrastructure setup, and data theft targeting drone manufacturers and diplomatic entities across Europe and Ukraine.
In a separate operation, Chinese actors used Claude to conduct large-scale surveillance targeting diaspora communities, including pro-democracy figures in Hong Kong and Tibetan and Falun Gong groups. In one instance, a Chinese-aligned account with no Arabic language skills used the model to run a multi-day recruitment operation to infiltrate Uyghur targets in Syria, with the AI drafting outreach in the regional dialect and translating replies in real time. Anthropic also identified Iranian state-aligned accounts using the platform to map targets by location, demographics, and political leanings.
Unauthorized Distillation and Data Exploitation
Anthropic also accused Chinese AI firms, specifically Moonshot and Deepseek, of engaging in unauthorized model distillation. This process involves using a more capable model, such as Claude, to train or improve a smaller, less capable model without permission. The report alleged that Moonshot relayed nearly 300,000 customer requests to Anthropic through a network of over 5,000 fraudulent accounts, many of which appeared to be based in Singapore and Japan.
This practice raises significant concerns regarding data privacy and the illicit replication of proprietary AI capabilities. Anthropic noted that some of the rerouted data contained sensitive user information, potentially violating privacy agreements. The company stated it does not know whether these Chinese firms notified their own customers that their requests were being rerouted to a third-party platform, further complicating the ethical and legal landscape surrounding AI resource sharing.
Biological Research and Safety Concerns
In addition to military and cyber threats, Anthropic flagged five case studies involving the use of its models in ways that could support biological weapons development. The research involved highly pathogenic strains of bird flu, the chikungunya virus, and toxins. While the company did not assert that the scientists involved intended to cause harm, it emphasized that the same information used to develop cures or vaccines could be repurposed for catastrophic ends.
Jacob Klein, head of threat intelligence at Anthropic, described the situation as incredibly nuanced, noting that the actors were often working scientists rather than individuals explicitly seeking to build weapons. The company has since incorporated these findings into its safety processes to better detect and disrupt such activities. These incidents have reignited broader debates among lawmakers and researchers regarding the necessity of a temporary pause on advanced AI development, with some calling for international treaties to govern the rise of machine intelligence.
Ongoing Investigations and Regulatory Standing
Anthropic is currently investigating recurring breaches across its systems and has engaged an independent research firm to conduct a comprehensive review. These findings come as the company seeks to restore its standing within the US defense industrial base following a contentious legal battle over its refusal to drop safeguards against autonomous weaponry. Despite a recent court ruling in California that favored the company against the Department of Defense, the firm remains under intense scrutiny.
As the company continues to share threat intelligence with law enforcement and industry partners, the focus remains on closing the gaps that allowed these state-backed actors to exploit its technology. The company has committed to deploying additional monitoring and strengthening its internal safeguards to prevent future misuse, though the rapid advancement of AI capabilities continues to present a significant challenge for developers and regulators alike.