Safety

AI-generated text

Anthropic report details state and criminal misuse of Claude for weapons, surveillance and biological research

Anthropic published a 154-page report documenting multiple cases where its Claude models were exploited by criminals, state-affiliated groups, spyware developers, researchers and propagandists to plan rockets and bombs, develop lethal pathogens, and surveil dissenting populations.

Anthropic report details state and criminal misuse of Claude for weapons, surveillance and biological research

Anthropic, an artificial intelligence company, published a 154-page report detailing multiple instances in which criminals, state-affiliated groups, spyware developers, researchers and propagandists attempted to exploit the company's Claude language models. The documented misuses include efforts to design rockets and bombs, produce lethal pathogens, and surveil dissenting populations.

What the 154-page report documents

Anthropic presents five in-depth case studies. In some of these, researchers used Claude for biological research while circumventing safety controls and concealing the projects' true purposes. The company describes biological misuse as one of the most severe risks posed by advanced AI and warns that without appropriate protections it could have catastrophic consequences.

One particularly concerning case involved a researcher using Claude on a state-funded proposal to study the chikungunya virus; Anthropic says the project was linked to a military research institute. The report notes that such research can be applied both to vaccine development and to the creation of biological weapons.

Types of misuse and geographic scope

The document catalogs a range of abuse types, from cyberattacks and espionage to surveillance operations, propaganda campaigns and weapon development. Specific examples in the report include:

  • a series of Russian espionage and cyberattacks;
  • a China-linked program targeting Uyghurs living in Syria;
  • propaganda operations in Russia, Malaysia, Iran and Bangladesh;
  • users in Yemen, China and Russia employing Claude to assist with software for conventional weapons such as firearms, rockets, weaponized drones and bombs.

Anthropic emphasizes that these instances are not routine misuse but represent the most serious and novel threats they have observed.

Timing and internal dissent

The report was published just two days after Jacob Coxon, a former Anthropic employee, publicly resigned. Coxon said he left because he believed the company was not acting responsibly in developing the technology; he has stated that Anthropic and rival OpenAI are speeding toward self-improving superintelligence, which he warned could lead to human extinction by 2030. Following his resignation, several current Anthropic employees publicly expressed sympathy with some of his concerns.

Expert comments and a call for cooperation

Many AI experts cited in or responding to the report argue that the near-term threats detailed — cyberattacks, weaponization and surveillance — pose more immediate and concrete dangers than speculative doomsday scenarios involving an all-powerful AI.

Heidy Khlaaf, lead researcher at the AI Now Institute, is quoted noting that technologies created in AI labs that can enable cyberattacks and weapon production are inherently highly dangerous.

Anthropic uses the report to urge the entire industry to work with governments and other stakeholders to defend against misuse and to mitigate biological and other serious risks.

Conclusions

The 154-page report provides a comprehensive view of how modern language models can be repurposed by state and non-state actors for harmful ends. Its central message is that responsible development requires regulation, investigation and cross-sector cooperation to reduce the risk of similar abuses.