On September 10, 2026, Anthropic published its most detailed threat intelligence report to date: Detecting and Countering Misuse of AI. The 154-page document covers malicious activity disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit distillation. Here are the key takeaways.
A Shift From Tool to Orchestrator
The report’s most striking theme is how AI misuse has evolved. Threat actors are no longer simply using Claude as a research assistant — they are deploying it as an autonomous orchestrator. In the cyber operations documented, a hacktivist using stolen API keys, financially motivated individuals, and a state espionage operator each sustained multi-victim campaigns that, even a year ago, would have required multiple skilled human operators. AI has lowered the cost and expertise barrier for large-scale cyber campaigns, surveillance operations, and weapons-related engineering.
Notably, none of the misuse cases involved Anthropic’s newest Claude Fable or Mythos-class models, with one exception in illicit distillation. The documented abuse ran on older models: Claude Haiku, Sonnet, and Opus.
Key Findings by Harm Area
Cyber Operations
Cases included Russian state-sponsored espionage, “smash-and-grab” cyberhacks, and campaigns powered by stolen API keys. The report highlights how AI-assisted intrusions have become cheaper and more scalable — with Claude used in place of human engineers for sustained, multi-victim attack chains.
Influence Operations
Anthropic disrupted nine influence campaigns across six continents, originating from Russia, Iran, Turkey, the Gulf, South Asia, Africa, and Europe. Reach was measured using the Brookings Institution’s Breakout Scale. Several are the most operationally specific disinformation disclosures Anthropic has ever published.
Surveillance
State actors used Claude to build surveillance infrastructure. Cases included a China-based program targeting Uyghurs in Syria and another targeting internal dissidents. Anthropic warns that AI is moving from an experimental tool into the everyday bureaucracy of state surveillance.
Scams and Fraud
The report documents financially motivated actors using Claude for romance scams and other fraud operations at scale, exploiting conversational AI’s ability to maintain realistic and persistent personas across multiple targets.
Biological Misuse
Anthropic identified and blocked five separate attempts by scientists to use Claude for research that could support biological weapons development. One involved a gain-of-function study intended for a military research institute. Anthropic assessed that its older models (Claude Opus 4, Sonnet 4.5) were “well below the threshold where they could meaningfully assist a sophisticated user in carrying out dangerous biological research.”
Conventional Weapons Development
In one of the report’s most alarming cases, a Yemen-based weapons cell (linked to Houthi forces) used Claude “in place of human software engineers,” assigning different model instances specific roles to write missile-guidance and flight-control software. Additional cases documented weapons-related AI use in China and Russia, covering firearms, armed drones, bombs, and other munitions.
Illicit Distillation
Anthropic named seven China-based AI labs — including Alibaba, DeepSeek, Moonshot, Z.ai (Zhipu), and MiniMax — for running industrial-scale covert campaigns to extract Claude’s capabilities and replicate them without authorization. Alibaba’s campaign alone involved more than 151 million exchanges with Claude. China rejected these accusations.
Anthropic’s Countermeasures
Anthropic outlined several defensive measures deployed or strengthened during the reporting period:
- Account bans: All accounts associated with the documented misuse were banned.
- Summarized reasoning and preserved thinking: New safety features in Fable 5.1 make it harder to extract hidden chain-of-thought reasoning.
- Identity verification: Strengthened identity checks for unsupported regions to prevent access from sanctioned jurisdictions.
- API key security guidance: The report emphasizes treating AI API keys like production database credentials, as stolen keys were used for resale, free compute, and attribution laundering.
- Threat intelligence sharing: Anthropic continues publishing detailed case studies to help the broader security community recognize and counter these patterns.
Why This Report Matters
This is the fourth in Anthropic’s series of threat reports (following March, August, and November 2025). What distinguishes this edition is its scope, specificity, and geopolitical weight — naming state actors, specific labs, and providing operational detail rarely seen in voluntary AI safety disclosures. It underscores a rapidly evolving threat landscape where AI is no longer just assisting bad actors but replacing skilled human operators in increasingly dangerous domains.