Anthropic Warns: China, Russia and Iran-Linked Actors Tried Using AI for Spying and Weapons Development

A newly released threat intelligence report reveals how state-linked groups attempted to weaponize Claude for espionage, surveillance, propaganda, and even military hardware development — and what Anthropic did to stop them.


Key Takeaways

  • Anthropic published a detailed Threat Intelligence report on September 10, 2026, covering misuse cases detected between December 2025 and August 2026.
  • The report ties disrupted activity to actors linked to China, Russia, Iran, Yemen, Mali, and other regions.
  • Disclosed cases span state surveillance of dissidents, cyberespionage, propaganda operations, conventional weapons development, and attempted biological research.
  • Anthropic said it banned the accounts involved and used the findings to strengthen its safeguards, enforcement systems, and threat-detection processes.
  • The report also names Chinese AI labs accused of using Claude to improve their own competing models through a technique known as “distillation.”

What Anthropic Actually Disclosed

Anthropic’s latest report is arguably its most detailed public accounting yet of how bad actors have tried — and largely failed — to turn a commercial AI system into a tool for state-level harm. The findings span several categories of misuse, each detailed with specific case studies the company says it identified and shut down.

1. Alleged Chinese Military and Weapons-Related Use

One of the most striking findings involves a China-based actor who reportedly used Claude across multiple parallel workstreams tied to defense research, including work connected to an anti-torpedo fire-control system reportedly intended for naval use. Anthropic said this activity was identified and cut off before the accounts could continue operating on its platform.

2. A Chinese Cyberespionage Campaign Run Largely by AI

Anthropic disclosed what it describes as a landmark case: a cyberespionage operation that used AI to autonomously direct large portions of a hacking campaign, rather than simply assisting human operators step-by-step. The company traced part of this activity to individuals in Hunan, China, allegedly running coordinated “agent swarms” against roughly fifty organizations across government and corporate networks in multiple regions. Anthropic characterized this as one of the first documented instances of a state-linked actor using AI to largely automate an offensive cyber operation.

3. Russian-Linked Espionage Against Ukraine and European Targets

The report describes a Russian-speaking operator — which Anthropic said aligns with previously identified groups tracked by the security community — running an espionage campaign against Ukrainian and European government, defense, and diplomatic organizations, including drone manufacturers. According to Anthropic, the operation used AI to test whether its malware could evade security detection tools, then automatically rebuild the malware to bypass them.

4. Iranian Surveillance of Dissidents and Minority Communities

Anthropic said it disrupted a state-aligned surveillance effort linked to Iran that allegedly profiled thousands of individuals over roughly a year, cross-referencing social media activity to identify opposition voices and dissenting accounts. The report notes that these campaigns, along with similar ones tied to China, specifically targeted communities long subject to state monitoring — including pro-democracy activists, religious minorities, and diaspora groups critical of their home governments.

5. Propaganda and Influence Operations

Beyond espionage, Anthropic said it disrupted at least nine influence operations connected to multiple countries, including Russia, China, Iran, and others. These campaigns allegedly used Claude to help plan messaging strategy and generate content for propaganda networks, including state-linked media operations.

6. Attempted Biological Research Misuse

The report also describes efforts by unnamed actors to use Claude for biological research that raised serious safety concerns. Anthropic said it did not disclose the specific institutions, countries, or biological agents involved, citing the sensitivity of the details, but confirmed the activity was identified and shut down before it could proceed further.

7. Allegations Against Chinese AI Labs

Separately from state-security concerns, Anthropic accused certain Chinese AI developers — reportedly including well-known Chinese labs — of using Claude in a way that violated its usage terms: generating large volumes of outputs in order to train, or “distill,” their own competing models. This practice has been a recurring point of tension in the AI industry, as it can allow competitors to shortcut the enormous cost of training frontier models by learning from an existing one’s outputs.


Why This Report Matters

AI Is Lowering the Barrier to Sophisticated Operations

Anthropic’s central warning is not simply that bad actors tried to misuse its technology — it’s how much capability a relatively small group could access as a result. Tasks that once required teams of skilled specialists — malware refinement, large-scale surveillance analysis, coordinated propaganda writing — can now be substantially automated by a handful of individuals working with an AI assistant.

A Shift From “AI as Assistant” to “AI as Operator”

Several of the disclosed cases represent a notable shift: rather than a human directing an AI step-by-step, the AI itself was reportedly used to autonomously execute large segments of an operation, with a human acting more as a supervisor than a hands-on operator. Security researchers have flagged this shift as one of the more consequential trends to watch as AI systems become more capable of independent, multi-step action.

Increasing Pressure for Regulation

The disclosures arrive amid growing scrutiny of frontier AI companies from lawmakers and regulators, who are increasingly focused on how these systems can be misused for national-security-relevant purposes. Reports like this one are likely to fuel further debate over what safeguards, monitoring, and export-style controls should apply to advanced AI models going forward.


How Anthropic Responded

According to the report, Anthropic’s response followed a consistent pattern across the disclosed cases:

  1. Detection — Identifying anomalous or suspicious usage patterns through its Threat Intelligence team.
  2. Investigation — Tracing the activity to specific accounts, operators, or campaigns where possible.
  3. Disruption — Banning the accounts and access associated with the misuse.
  4. Systemic Reinforcement — Feeding findings back into Claude’s safety classifiers, enforcement systems, and monitoring infrastructure to catch similar attempts in the future.

Anthropic has generally avoided identifying every institution or actor by name, citing both the sensitivity of ongoing threats and the limits of attribution in cyber and intelligence contexts.


Frequently Asked Questions

Does this mean Claude was successfully used to build weapons or conduct successful attacks?
Anthropic’s report describes attempts and, in some cases, partial progress before the activity was detected and shut down — not fully successful weapons programs. The company frames these disclosures as evidence of active misuse attempts and the effectiveness of its detection systems in stopping them.

Which countries were named in the report?
The report ties disrupted activity to actors linked to China, Russia, and Iran most prominently, with additional cases connected to Yemen, Mali, and West Africa more broadly.

Did Anthropic name every actor or organization involved?
No. Anthropic withheld many specific institutional and individual details, citing the sensitivity of the underlying threats and ongoing security considerations.

What is “distillation,” and why does it matter here?
Distillation refers to using one AI model’s outputs to train a separate, often competing, model. Anthropic alleges some Chinese developers used Claude this way, in violation of its usage policies, potentially shortcutting the cost of building rival AI systems.

What should businesses and policymakers take away from this?
The report reinforces that AI misuse detection needs to be treated as an ongoing, evolving discipline — not a one-time safeguard — as both the sophistication of threat actors and the capabilities of AI systems continue to advance in parallel.


The Bigger Picture

This report lands at a moment when the AI industry is under intensifying pressure to demonstrate that safety commitments extend beyond marketing language into actual, enforced practice. Whether or not every technical detail can be independently verified, the pattern is now unmistakable: state-linked and state-aligned actors are actively probing frontier AI systems for use in espionage, surveillance, propaganda, and weapons-related research — and AI companies are increasingly being forced into the role of front-line defenders against that misuse.

For governments, security researchers, and the public alike, reports like this one are likely to become a regular fixture of the AI landscape — an ongoing scoreboard of who is trying to misuse these systems, and how effectively that misuse is being caught.


This article is based on Anthropic’s published Threat Intelligence report and subsequent news coverage as of September 11, 2026. As details of an active, evolving security matter, further findings, corrections, or independent verification may emerge over time.

Read more trending news here

Leave a Reply

Your email address will not be published. Required fields are marked *