Anthropic report details blocked bioweapons research and state cyberattacks
A threat intelligence report from Anthropic reveals that scientists and state-backed hackers attempted to use Claude models for bioweapons planning, missile software, and cyber espionage.
Biological research and dual-use dilemmas
Anthropic published a threat intelligence report on 10 September 2026, detailing multiple blocked attempts to use its Claude models for biological weapons research between December 2025 and August 2026. The company identified five case studies involving biological misuse across its Claude Haiku, Sonnet, and Opus systems. In one May 2026 incident, a researcher linked to a military institute used Claude to draft a grant proposal aimed at genetically modifying the mosquito-borne Chikungunya virus to make it more harmful to animals through gain-of-function research. Another case involved a researcher bypassing geographic restrictions to plan experiments adapting avian influenza to mammals, while a third project catalogued animal venom compounds. Anthropic explained that distinguishing legitimate medical studies, such as vaccine development, from biological weapons research remains difficult because dual-use projects often share identical laboratory steps.
The fact that a military institution is doing gain-of-function research is inherently concerning. We do not face a comic book character who declares: 'I am going to create a biological weapon to kill everyone.' The situation is very complex.
Conventional weapons and state espionage
Beyond biological concerns, Anthropic documented six incidents where operators used Claude to develop software for conventional armaments, guidance mechanisms, and control systems. The company detected three cases originating in China, two in Russia, and one in Yemen, covering software intended for firearms, missiles, armed drones, and explosive devices. Jacob Klein, head of threat intelligence at Anthropic, noted that rapid capability improvements enabled these applications.
A year ago, if you wanted to optimize a drone or a missile's software, the models simply were not as effective as they are today.
The report also tracked a Russian-linked cyber espionage operation that used Claude to automate multi-stage campaigns against Ukrainian military, diplomatic, and government personnel. The hacking group compromised hotel Wi-Fi networks, conducted phishing attacks, hijacked WhatsApp accounts, and used AI to rewrite malicious code whenever security tools detected it. In addition, state-linked actors in Iran and China deployed the models for political surveillance and disinformation campaigns disguised as independent reporting.
| China | 3 |
|---|---|
| Russia | 2 |
| Yemen | 1 |
Model distillation and industry responses
The report disclosed that seven Chinese laboratories conducted illicit distillation attacks targeting Claude models since February 2026, attempting to extract capabilities from larger teacher models to train smaller student systems at lower cost. Anthropic noted that none of the operational misuse cases involved its Claude Fable or Mythos-class models, with the exception of distillation attempts targeting Claude Fable 5. The company stated that scientists and state-backed actors routinely bypassed geographic restrictions to access systems that remain officially unavailable in China, Russia, and North Korea.
Today we might not foresee them and, once released, no longer be able to stop them.
The publication coincided with internal turbulence and wider industry disclosures. Anthropic engineer Jacob Coxon resigned earlier in the week, stating that the race toward artificial superintelligence could destroy humanity before the decade ends. Meanwhile, Google revealed on 8 September 2026 that an individual attempted to use its Gemini chatbot to obtain a step-by-step technical guide for synthesizing weaponized biological agents. In Washington, US Senator Bernie Sanders called for a pause on advanced AI development and a ban on superintelligence, while US President Donald Trump addressed competitive pressures with foreign adversaries on 10 September 2026.
If we don't win on AI, we are going to be in a very bad position.
| 2026-02 | Anthropic first publicizes illicit distillation attacks from Chinese laboratories |
|---|---|
| 2026-05 | Researcher linked to a military institute uses Claude to draft Chikungunya gain-of-function proposal |
| 2026-09-08 | Google reports Gemini prompt requesting instructions for synthesizing biological weapons |
| 2026-09-10 | Anthropic releases threat intelligence report detailing eight months of system misuse |
Sources
- Anthropic blocca l'uso dell'IA per ricerche su armi biologiche - Future Tech
ANSA.it · Sep 11 - Anthropic предотвратила попытки связанных с Россией хакеров использовать ИИ для создания оружия
RFI · Sep 11 - Anthropic Claims It Stopped Suspected Bioweapons Research Conducted With Claude
Gizmodo · Sep 11 - Anthropic detecta usos de IA ligados a armas biológicas
Deutsche Welle · Sep 11 - Anthropic afirma que ha frustrado posibles intentos de usar su IA para fabricar armas biológicas
El Periódico · Sep 11 - Anthropic révèle avoir bloqué des tentatives de fabrication d'armes biologiques grâce à ses modèles
Courrier international · Sep 11 - Anthropic diz ter barrado tentativa de uso de IA para fazer armas biológicas
BBC · Sep 11 - KI-Entwickler Anthropic blockiert Biowaffen-Recherchen
tagesschau.de · Sep 11