“The cases we share here aren't typical misuse, but rather examples of the most notable and novel threat activity we've identified to date,” Anthropic said.
Anthropic said it identified abuse between December 2025 and August 2026 involving spyware vendors, politically motivated actors and state-backed groups. The report includes examples of malicious prompts and code, while urging governments and other AI developers to watch for similar behavior.
Some of the most sensitive cases involved biology. In one example, Claude was asked to assist with a scientific grant application involving gain-of-function research on the chikungunya virus. Anthropic said the proposed work focused on changing the virus in ways related to transmissibility and immune evasion.
The company noted that research of this kind can have legitimate medical applications, including work on treatments and vaccines, while also creating risks if the same techniques are used to make pathogens more dangerous.
Anthropic said its systems blocked the request.
The company also disclosed five cases involving biological research it considered potentially dangerous, including users who bypassed controls while working from regions where Anthropic does not provide access to its models. One researcher spent weeks using Claude to plan avian influenza experiments before the work was restricted.
Anthropic said it could not determine whether those researchers had malicious intentions.
That uncertainty is part of the problem the company is trying to address. Scientific information that could support vaccine development may overlap with information that could also be misused for biological weapons research.
Anthropic said older models such as Claude Opus 4 and Claude Sonnet 4.5 were not capable enough to substantially help sophisticated users conduct dangerous biological work. Safeguards on those systems were therefore aimed mainly at preventing less experienced users from obtaining information that could help recreate known biological weapons.
The company said that confidence has weakened as its models have improved.
“But for today's models — which are capable of assisting in a range of complex scientific research tasks — the evidence is no longer certain, and we cannot make that same assurance,” Anthropic said.
In response, Anthropic said newer systems, including Claude Fable 5, have stronger restrictions covering a wider range of dual-use biological research.
Most of the misuse described in the report did not involve Anthropic’s newest Fable or Mythos-class models. One exception involved what the company characterized as a large-scale model distillation operation designed to copy Claude’s capabilities without permission.
Anthropic also said it identified attempts by China-based AI labs, including Moonshot and DeepSeek, to reproduce Claude through distillation. The company described the activity as an effort to extract the behavior of its models and transfer those capabilities into competing systems.
The report extends well beyond biological research.
Anthropic said it found coordinated influence operations in which groups created hundreds of social media profiles designed to appear as ordinary users, then pushed aligned political messages. It described nine cases linked to activity originating across Russia, Iran, Turkey, the Persian Gulf, South Asia, Africa and Europe.
The company argued that AI providers may be able to spot such campaigns before social platforms do because the activity can become visible while accounts, messages and strategies are still being created.
Other cases included surveillance tools and fraudulent services, including fake dating applications intended to deceive users.
Anthropic said the growing capabilities of AI models have also changed the barrier to entry for cyber abuse. Tasks that once required specialized technical expertise can now be attempted by individuals using AI assistance, forcing developers to improve detection systems alongside the models themselves.
The disclosures arrive shortly after Anthropic researcher Jacob Coxon announced his resignation and warned publicly about the risks of increasingly capable AI systems. Coxon said he believed Anthropic and OpenAI were moving toward self-improving artificial intelligence too quickly and expressed concern about potentially catastrophic consequences.
Anthropic said it blocked the malicious activity described in its report, closed accounts where appropriate, strengthened safeguards and shared relevant findings with government agencies and industry partners.
“We're publishing this work because we believe we have a responsibility to disclose malicious misuse of our services,” the company said. “As models become increasingly capable, their risks will increase, unless AI developers and society's defenders act to make them safer.”
Anthropic said it hopes publishing the cases will help other AI companies identify comparable abuse and give governments and civil society a clearer picture of how emerging threats are developing.
“We hope that the findings in this report will help other developers recognize similar patterns on their own platforms, give governments and civil society a clearer view of how emerging threats take shape, and strengthen collective defenses,” Anthropic said.
This analysis is based on reporting from PBS News.
Image courtesy of AP Photo/Patrick Sison.
This article was generated with AI assistance and reviewed for accuracy and quality.