Anthropic exposes global threat networks misusing Claude in landmark 154-page report
AI safety pioneer Anthropic has published a comprehensive 154-page threat intelligence report detailing unprecedented efforts by state-sponsored actors, cybercriminals, spyware developers, and covert propagandists to bypass system guardrails and leverage its Claude AI models for weapons design, cyber espionage, and surveillance.

The disclosure marks one of the most granular public audits of frontier model misuse ever released by an AI developer, highlighting real-world threat vectors spanning biological research, autonomous weapon design, state surveillance, and "propaganda-as-a-service" campaigns.
Gain-of-Function Bio-Research and Autonomous Weapons Design
The report outlines high-risk attempts by external actors to exploit Anthropic's reasoning capabilities for dangerous physical and biological applications:
Dual-Use Biological Research: Systems detected and blocked multiple attempts by scientists, including researchers linked to military institutes, to circumvent geographic blocks and use Claude for gain-of-function research. In one notable instance, a user attempted to draft a state-sponsored grant proposal aimed at enhancing the transmissibility and immune evasion properties of the chikungunya virus.
Hypersonic Missiles and Guided Rockets: A group operating in northern Yemen used Claude Code across segmented chat threads to draft software for guided rockets, long-range missile schematics, and hypersonic glide vehicle designs, prompting system intervention.
Autonomous "Kamikaze" Drone Swarms: A freelance developer group in Russia utilized Claude to assist in coding autonomous targeting software for strike drones programmed to select targets and detonate in Ukraine's Donetsk region without human operator intervention.
State Surveillance, Cyber Ops, and Automated Disinformation
Beyond physical weaponry, the report cataloged extensive digital misuse targeting telecommunications networks, government bodies, and international political discourse:
Mass Mobile Network Surveillance: A tech consultant working alongside state intelligence in Mali leveraged Claude Code to build "Lakana 360," a system capable of monitoring approximately 25 million mobile SIM cards, tracking calls, texts, and voice prints while detecting encrypted VPN connections.
Propaganda-as-a-Service: Anthropic uncovered a French agency (LKM Company) using Claude to mass-produce nearly 9,000 political articles across 70 synthetic news outlets in 20 languages. Paired with automated social media personas, the agency deployed coordinated influence campaigns across the U.S., Europe, and Africa.
Illicit Model Distillation: The investigation uncovered an industrial-scale campaign aimed at illicitly extracting capabilities from Anthropic’s flagship models to replicate them in unauthorized third-party architectures.
Safeguard Upgrades and Escalating Industry Safety Debates
Anthropic noted that most attempted breaches targeted older foundation models like Claude Sonnet 4.5 and Opus 4, whose safety filters focused primarily on preventing novice-level weapon assembly rather than high-level scientific queries. In response, the company has deployed stricter dual-use research filters across its latest Claude Fable 5 and Mythos-class architectures.
The release comes amid heightened scrutiny for the San Francisco startup following the public resignation of researcher Jacob Coxon, who warned of existential risks stemming from rapid commercial AI development. In its report, Anthropic argued that public transparency and cross-industry threat sharing are necessary steps to defend against accelerating frontier risks.












