Anthropic, the American company behind the Claude AI chatbot, has disclosed that state-linked groups in Russia, China, Iran and Yemen attempted to misuse its models for weapons research, cyberattacks and disinformation campaigns. The findings come from a threat intelligence report published on September 10, 2026, covering misuse activity the company detected and disrupted between December 2025 and August 2026. Anthropic said it banned the accounts involved and used the cases to strengthen its safety systems
- Anthropic’s report covers seven harm categories: cyber operations, influence operations, surveillance, conventional weapons development, biological misuse, scams and fraud, and illicit “distillation” of its models.
- Operators based in China, Russia and Yemen reportedly used Claude AI to help develop software for weapons design, and to support intelligence gathering and procurement linked to weapons programs.
- A Russian-speaking group, tracked as GTG-20006 and consistent with the state-linked actor known as Midnight Blizzard, used Claude AI to help malware evade detection while targeting Ukrainian and European government, diplomatic and defence bodies.
- Two individuals in Hunan, China, allegedly ran automated “agent swarms” against roughly 50 organisations, including a Southeast Asian government agency.
- Anthropic said seven China-based AI firms, including Alibaba, Moonshot and DeepSeek, ran large-scale campaigns to extract Claude’s capabilities for training rival models.
- Iranian state bodies, including an office linked to the Ministry of Culture, reportedly used Claude AI to plan influence campaigns.
- None of the disclosed misuse cases involved Anthropic’s newest models, Claude Fable and Claude Mythos, the company said.
What Anthropic’s Threat Report Found
Anthropic said the misuse cases mark a shift in how state-linked and criminal groups are using generative AI — not simply for writing assistance, but to run entire stages of an operation. In its report, the company said it identified “new categories of threat actors” attempting to use Claude AI to develop software for conventional weapons, including firearms, missiles, armed drones and their targeting systems. Separately, the report described attempts to use the model in research that could support biological weapons work, though Anthropic did not name the institutions, countries or specific agents involved, citing the sensitivity of the information.
The company said all flagged accounts were suspended and that the case details were fed back into its safety, enforcement and threat-intelligence systems to catch similar attempts earlier in future.
State-Linked Cyber Espionage and Propaganda Cases
Among the most detailed cases was a campaign Anthropic attributed, in line with existing public reporting, to the Russian state-linked group Midnight Blizzard. According to the report, the group used Claude AI to test whether its malware had been flagged by security software, then automatically rewrote the code to slip past those defences while targeting government, diplomatic and defence organisations in Ukraine and Europe.
Anthropic also said individuals linked to Russian state media used Claude AI to draft articles, television captions and headlines, some of which reportedly aired on Sputnik and RT, reaching audiences in Moldova, Latin America and Africa. A separate case involved an automated fake-news operation in Bangladesh. In Iran, state institutions — including a body under the Ministry of Culture and a propaganda office in Mashhad — reportedly used the model to build out full influence-campaign plans.
Chinese AI Labs Accused of Copying Claude
The report also raised concerns over “distillation” — using an AI model’s outputs to train a competing one. Anthropic said it disrupted efforts by seven China-based labs, naming Alibaba, Moonshot, DeepSeek and Xiaomi, that it said ran large-scale operations to extract Claude’s capabilities. None of the named companies had responded publicly to the allegations at the time of the report’s release.
Anthropic’s report underlines a growing global concern: that advanced AI systems are increasingly being targeted by state-linked groups and cybercriminals for espionage, weapons research and disinformation. For Pakistani readers following the region’s fast-growing AI adoption, the disclosure is a reminder that AI safety and misuse detection are becoming central issues in global technology and security policy, even as companies like Anthropic say their safeguards successfully caught and disrupted these specific attempts