Anthropic says it has disrupted a series of attempts to use its Claude artificial-intelligence models for potentially dangerous activities, including biological research that could contribute to weapons development, sophisticated cyberattacks, surveillance and political influence operations.
The findings provide one of the clearest real-world examples yet of a concern AI researchers have warned about for years: as artificial-intelligence systems become more capable, they can provide powerful scientific and technical assistance not only to legitimate researchers but also to people pursuing harmful objectives.
Anthropic documented the incidents in its latest threat-intelligence report, covering malicious activity detected between December 2025 and August 2026.
Among the most serious findings were five cases involving scientists using Claude in ways that Anthropic said could potentially support biological-weapons development.
One case involved a request for assistance preparing a scientific grant proposal involving gain-of-function research on the chikungunya virus. The proposed research focused on characteristics including transmissibility and immune evasion.
Such research can have legitimate scientific purposes, including understanding diseases and developing treatments or vaccines. But it is considered “dual use” because similar knowledge could potentially be exploited to make pathogens more dangerous.
Anthropic blocked the activity.
Another case involved a researcher who circumvented geographic restrictions and used Claude over several weeks to plan experiments involving adaptation of avian influenza to mammals. Anthropic eventually identified the activity and banned the accounts involved.
The company stressed that the cases do not demonstrate that Claude successfully created a biological weapon. Instead, they illustrate how increasingly sophisticated AI models can potentially help researchers navigate complicated scientific tasks that previously required greater levels of specialized expertise.
That distinction is important.
Anthropic said its older models were not considered capable enough to substantially help sophisticated researchers conduct dangerous biological work. But improvements in newer AI systems have changed the company’s assessment.
As a result, Anthropic says it has introduced stronger restrictions covering a broader range of dual-use biological research.
Biology was only one part of the report.
Anthropic also discovered suspected state-linked hackers using Claude to support cyber operations. One group displayed techniques consistent with a Russia-linked threat actor previously associated by U.S. authorities with Russian intelligence.
According to Anthropic, AI was incorporated into multiple stages of cyber operations targeting Ukrainian government, military and diplomatic organizations. The technology was reportedly used for tasks including phishing, malware development and modifying malicious software when security systems detected it.
The significance is not simply that hackers are asking chatbots for programming advice.
Anthropic says some attackers are increasingly using AI agents to automate substantial portions of operations, allowing humans to supervise systems capable of performing numerous technical tasks themselves.
The company also identified attempts to use Claude for conventional weapons development, including software related to missiles, armed drones and targeting systems. Activity connected to actors operating in Russia, China and Yemen appeared among the cases Anthropic investigated.
Other misuse involved surveillance and political influence campaigns.
Anthropic discovered operations creating hundreds of social-media accounts designed to resemble ordinary users and distribute coordinated political messaging. Because AI companies can sometimes observe campaigns while content is still being generated, they could potentially identify influence operations before those campaigns spread widely across social networks.
The report exposes a fundamental dilemma facing the AI industry.
The same capabilities that make advanced models valuable—scientific reasoning, programming, automation, research and problem solving—can potentially make them useful to malicious actors.
AI companies are therefore attempting to distinguish legitimate scientific and technical work from activity that could create serious security risks.
Critics argue that such decisions should not rest exclusively with private technology companies. Determining which scientific research is acceptable, what constitutes dangerous dual-use activity and when access should be restricted involves societal and regulatory questions that extend beyond corporate safety policies.
Anthropic argues that transparency and cooperation among AI companies, governments and security researchers will become increasingly important as models grow more powerful.
The incidents it disclosed are unusual rather than representative of ordinary Claude usage. But they provide evidence that the threat is moving beyond hypothetical scenarios.
The central concern is no longer simply whether advanced AI could eventually help malicious actors. Anthropic’s findings indicate that people are already attempting to use these systems for biological research, cyber espionage, weapons-related work and influence campaigns.
The emerging challenge is whether safeguards, governments and security institutions can evolve as quickly as the technology—and the people attempting to exploit it.





