The 154-page document, following three earlier releases since March 2025, covers eight months of internal investigation, from December 2025 to August 2026. Among the most troubling cases are five separate attempts to misuse Claude for research that could facilitate the development of biological weapons. But the report goes well beyond this single area, also describing attempts to design missiles, military espionage operations, and surveillance campaigns targeting minorities.
Five suspicious lines of research tied to biological weapons
Anthropic says it identified and blocked five attempts by researchers to use Claude for work that could facilitate the development of biological weapons. One case, dated May 2026, involves a scientist affiliated with a military research institute who allegedly asked for help drafting a grant application for gain-of-function research on chikungunya virus, a mosquito-borne pathogen for which no licensed treatment exists. Another case concerns a research program aimed at adapting a highly pathogenic strain of avian influenza for transmission among mammals, a scenario epidemiologists have long warned about. In this latter case, Claude reportedly refused to continue with the most sensitive part of the research, prompting the operators to turn to a different AI model to carry on their work.
Anthropic notes that it cannot always distinguish legitimate scientific research from a genuinely dangerous project, but says it banned the accounts involved in each case as a precaution. The company also states that older versions of its models did not offer a sufficient level of assistance to pose a real risk in this area, which led it to strengthen its safeguards as its models grew more capable.
A ballistic missile developed in Yemen with Claude’s help
The report also documents six cases tied to conventional weapons development, a category of threat Anthropic says it is observing for the first time: three in China, two in Russia, and one in Yemen. The most detailed case involves a cell based in northern Yemen that allegedly ran three programs at once: a guided rocket built on a commodity phone-class flight computer, a multi-stage ballistic missile with a stated range goal above 2,000 kilometers, and a missile family that included a hypersonic glide vehicle variant. The operators reportedly used Claude Code, Anthropic’s programming tool, in place of human engineers to write the guidance, navigation, and control software, integrate an autopilot, and run flight simulations. A test launch of the guided rocket reportedly took place and appears to have failed; the operators allegedly returned to Claude within hours to analyze the failure. Anthropic states it found no evidence the operators succeeded in fielding an operational weapon, while acknowledging that its safeguards blocked only some of their requests.
China targets Taiwan, Russia builds drone swarms
In China, an actor Anthropic links to a defense industry manufacturer allegedly used Claude to draft a technical specification of more than two hundred pages for an anti-torpedo warfare system, aimed at securing certification. A second, more concerning Chinese case involves the construction of a software suite for electronic warfare and air-defense suppression, which modeled radar jamming and ranked targets by priority. Partway through the project, the default scenario was reportedly changed to target sites in Taiwan, including a command bunker, an early-warning radar site, and Patriot and Tien Kung missile batteries. A third Chinese case concerns intelligence-gathering on directed-energy weapons.
On the Russian side, a team likely operating independently of the state allegedly used Claude Code to develop a fully autonomous FPV kamikaze drone swarm, whose onboard model was reportedly trained to recognize several target categories, including a “person” class, and to issue engagement commands without human validation, using combat footage scraped from the war in Ukraine.
Tracking Uyghurs in Syria
The report also details a surveillance operation attributed to an actor aligned with the Chinese government, tracked under the designation GTG-14010. According to Anthropic, this actor, who had no Arabic language skills, used Claude to identify, across more than a hundred WhatsApp groups and dozens of Telegram channels, Uyghur individuals present in Syria, including members of armed formations recently integrated into the new Syrian national army. The model reportedly helped draft outreach messages in Syrian Arabic targeting people assessed as financially or personally vulnerable, translated their replies in real time, and played the role of an expert reviewer checking the credibility of the operation, all with the aim of obtaining information in exchange for payment on these units. Beijing has long regarded certain Uyghur armed groups as a direct security threat.
Iran targets the US Navy
The report further documents a case involving an actor linked to Iran, who allegedly used Claude to compile “targeting handbooks” aimed at US naval forces deployed in the Middle East, cross-referencing transponder identifiers, commercial satellite imagery, and lists of public websites exposing US naval movements, enriched with a roster of personnel identified from captions on public military photographs. Anthropic says it banned the account and shared its findings with US government authorities.
A few figures summarize the scale of the report:
- Eight months of activity covered, from December 2025 to August 2026
- Six separate operations tied to conventional weapons development, spanning China, Russia, and Yemen
- Five documented attempts at biological misuse
- Nine influence operations identified, originating from Russia, Iran, Turkey, and elsewhere, reaching audiences across six continents
Washington and Beijing resume an AI dialogue
This climate of tension led, in mid-September, to a first diplomatic gesture. US Treasury Secretary Scott Bessent announced on September 21 that Washington and Beijing had formalized a framework called the “USA-China AI Dialogues,” following a twelve-hour negotiating session with Chinese Vice Premier He Lifeng. The two delegations agreed to reconvene in Shenzhen within two months. It marks the first bilateral dialogue devoted exclusively to artificial intelligence since Donald Trump’s re-election, and it notably covers information-sharing on AI-driven cyberattacks, a topic directly informed by reports such as Anthropic’s.
The limits of after-the-fact regulation
What this report highlights, beyond the individual cases, is the structural difficulty of governing misuse of artificial intelligence. In nearly every case cited, detection came only after the malicious activity had already produced concrete results. Banning an account, once the violation is identified, offers no guarantee that the underlying project will stop. This gap between the speed of misuse and the slowness of detection has, for months, fed a broader debate over the need for international regulation of artificial intelligence.
FAQ
Is Anthropic’s report public?
Yes, it is available on Anthropic’s website, along with technical indicators of compromise intended for cybersecurity professionals.
Were these biological weapons actually built?
No. The report documents research and planning phases that were blocked before producing any concrete outcome; no biological agent was developed.
Has Anthropic confirmed the identity of all the groups involved?
Rarely in full. The company attributes activity to geographic regions and, in some cases, to actor profiles, without always naming the specific organizations responsible.
Why does Anthropic publish this kind of report?
The company says it wants to give visibility to misuse patterns to help other AI developers and public authorities recognize similar activity on their own platforms.