Anthropic says that over the past year it identified users in several countries trying to employ its Claude AI models for potentially harmful ends, including military applications and other malicious uses. The company emphasized that in the cases it examined the two most advanced models, Fable and Mythos, were not used.
What was targeted
-
Drone swarms: Anthropic describes an attempt linked to actors associated with Russia — though not state actors, according to the company — to develop software for controlling autonomous FPV kamikaze drone swarms using Claude. The attackers reportedly planned to train the system on Ukrainian combat footage.
-
Rockets: Actors operating in northern Yemen under Houthi control used Claude to develop software for various types of rockets.
Anthropic stressed it has no evidence that any of these efforts produced an operational weapon system.
Biological research and dual-use risks
The company detailed five incidents in which Claude’s use could have contributed to biological-weapons-related work. Those incidents include virologists with state affiliations who may have been working on an enhanced form of chikungunya, a mosquito-borne virus that can cause severe illness. One highlighted request sought Claude’s help drafting a grant application to fund research at a military research institute. Anthropic classified the biological cases as "ambiguous," noting that the same queries could also reflect legitimate, benign scientific research.
Surveillance applications
Anthropic found attempts by users linked to Chinese and Iranian state actors to develop surveillance systems with Claude. In a China-linked operation, the model was reportedly used within the Syrian military to track, profile and recruit Uyghurs. An Iranian unit worked on surveillance software disguised as a tool for tracking prayer times.
A Mali case: Anthropic uncovered a consultant in Mali who likely collaborated with a state intelligence agency and built, with Claude’s assistance, a system capable of surveilling roughly 25 million mobile phones. The system could produce an intelligence dossier for a given phone number without a court order. Anthropic suspended the consultant’s account, but by then the Claude-based platform was deployed locally, and the company no longer had full control of it.
Cybercriminals and state-linked hackers
The report also describes how AI is accelerating attacks across a spectrum from state-backed hacking groups to cybercriminals. While Anthropic did not identify any new vulnerabilities threatening critical infrastructure, it examined activity from several known groups.
-
Midnight Blizzard: The group Microsoft attributes to Russian intelligence used Claude to automate operations, including automating the development of malicious software and crafting spear-phishing emails targeting military intelligence and defense-related targets.
-
ShinyHunters: Anthropic found members of this extortion group used AI to search for leaked credentials and then attempted data theft from affected organizations.
Anthropic characterized these as among the most significant and novel misuse cases it has identified, rather than routine abuses of Claude.
Consequences and regulatory friction
Tensions between Anthropic and U.S. defense authorities have increased: the Pentagon suspended collaboration with Anthropic after the company declined to permit use of Claude for mass surveillance or to operate autonomous weapon systems.
Anthropic is also preparing for an initial public offering. The company expects to begin IPO marketing in mid-October, with a prospectus potentially becoming public at the end of September. The contemplated offering could value Anthropic at up to $2 trillion, which would place it among the world’s most valuable technology companies.
Conclusion
Anthropic’s report highlights how advanced language models and generative AI tools can be repurposed for military, surveillance and biological applications, even when developers try to restrict misuse. The company found multiple concerning attempts across countries and actor types, but reports no confirmed case so far of an operational weapon system emerging from the investigated uses. The findings underscore the need for stronger safety measures and deepen the political and ethical debates between AI providers and regulators.



