Anthropic has identified and shut down multiple efforts to exploit its artificial intelligence models for activities that could facilitate biological weapons development, the company disclosed in a threat intelligence report published on 10 September 2026.
The disclosure marks the latest warning from AI companies about misuse of their systems, following similar findings from competitors. reported that the company broke up attempts to use Claude for biological weapons work and documented involvement in a suspected Russia-linked cyber espionage campaign against Ukraine.
The findings have intensified debate over AI safety. US Senator Bernie Sanders has called for a temporary halt to advanced AI development and a permanent ban on artificial superintelligence, while President Donald Trump has expressed concern about falling behind in the technology race, saying on Thursday he feared the consequences "if we don't win AI."
What misuse did Anthropic detect?
Between December 2025 and August 2026, Anthropic disrupted malicious activity spanning seven distinct categories: biological weapons development, conventional weapons creation, cyber operations, influence campaigns, surveillance systems, financial fraud, and model distillation—the process of training smaller AI systems using larger ones.
The biological weapons concern represents perhaps the most alarming category. The report documented five examples of scientists using Anthropic's models in ways that could support biological weapons development. According to CNN, Anthropic found about 35 distinct research initiatives showing potentially alarming activity after reviewing a month of activity, with case studies including potential gain-of-function work on avian influenza, plus novel venoms and toxins.
One particularly concerning case involved a researcher in an unsupported region using virtual private server infrastructure to access Claude while planning avian influenza mammalian-adaptation experiments over a period of weeks, according to reporting on the findings.
The misuse affected Claude Haiku, Sonnet, and Opus models, though not Claude Fable or the more powerful Mythos-class models, except in one distillation case. The company also reported six instances where Claude was used to develop software for conventional weapons, including firearms, missiles, armed drones, bombs, and their targeting and control systems.
Why is biological misuse particularly concerning?
Anthropic characterizes biological weapons development as "one of the most serious risks of frontier AI models." The company noted that without proper safeguards, such capabilities "could have catastrophic consequences."
Jacob Klein, Anthropic's head of threat intelligence, told the New York Times that the situation presents a fundamental paradox: "The same information that can be used to develop a biological weapon could also be used to develop, for example, a vaccine or a cure for a disease." He emphasized the complexity of the challenge, noting that misuse attempts are rarely straightforward. "You are not seeing someone in a comic book kind of way say, 'Hey, I want to build a biological weapon to kill everybody,'" Klein said.
The company's August 2026 risk report indicated that the odds of a concerted attempt to build a bioweapon capable of damage beyond COVID-19 may fall in the 1–10% range for each threat actor, though the firm currently believes the catastrophic-risk contribution from its own AI models in this category remains low, with acknowledged high uncertainty.
What other misuse patterns emerged?
Beyond biological threats, Anthropic's report revealed widespread exploitation by state-sponsored actors, criminal groups, and propaganda institutions. The company named hacking group ShinyHunters and China-based laboratories among those misusing its technology.
A hacking group whose activity is consistent with Russia-based Midnight Blizzard allegedly used Claude to build a system that automatically detected when its malware triggered security defences and rewrote code until it evaded detection. Anthropic also reported that its models were used in a Russia-linked cyber espionage campaign and by an Iranian propaganda institution.
The eight-month period covered by the report also documented cases involving fake dating applications, hotel Wi-Fi scams, and surveillance systems designed to identify political dissidents. Additionally, Anthropic accused Chinese AI firms of attempting to replicate Claude's capabilities.
How does this compare to other AI companies?
Anthropic is not alone in documenting such misuse. Google disclosed on 10 September that a person had attempted to use its Gemini AI tool to "complete, step-by-step technical guide for synthesizing weaponised biological agents." Multiple AI firms now publish regular threat intelligence reports documenting similar patterns of misuse.
This represents part of an ongoing pattern for Anthropic, which has previously published threat intelligence reports covering misuse across cyber and influence operations.
What is the broader context for AI safety concerns?
Anthropic's findings arrive amid intensifying warnings from AI researchers about existential risks. On 6 September, OpenAI chief scientist Jakub Pachocki published an article calling for the industry to implement "voluntary slowdowns" until safeguards are established. "I am concerned no one is prepared for the consequences of a continued rapid rise in machine intelligence," Pachocki stated, adding that OpenAI will continue developing safeguards but broader interventions are necessary.
A top safety researcher at Anthropic previously warned that AI is advancing so rapidly he believes there is a greater than 10% chance it "could kill all humans" within the next decade.
These warnings prompted an open letter to UK Prime Minister Andy Burnham calling for a new multinational treaty governing safe AI development and urging governments to collaborate on superintelligence safeguards.
What policy responses have emerged?
In the United States, Senator Bernie Sanders has introduced legislation to ban AI superintelligence and temporarily pause advanced AI development. Speaking on 12 September on BBC's Newsnight, Sanders emphasized the stakes: "When scientists tell you there is a chance, a chance that it could have a cataclysmic impact on humanity, you've got be a moron not to say, slow it down."
President Trump has taken a contrasting position, rejecting such concerns and prioritizing competitive advantage in AI development.
What happens next?
Anthropic stated it has incorporated its findings into internal processes "to better prevent, detect, and disrupt these activities in the future" and has shared intelligence with authorities and industry partners where appropriate. The September 2026 report is expected to prompt follow-up scrutiny from regulators and AI policymakers in the coming days and weeks.
Key Facts
- Anthropic disrupted misuse of its Claude models across seven harm categories between December 2025 and August 2026, including five documented cases of biological weapons development support
- The company found approximately 35 distinct research initiatives with potentially alarming activity, including gain-of-function work on avian influenza and novel toxins
- Misuse involved state-sponsored groups, criminal organizations, propaganda institutions, and politically motivated individuals across cyber operations, surveillance, fraud, and weapons development
- Anthropic's August 2026 risk assessment estimated the odds of a concerted bioweapon attempt capable of damage beyond COVID-19 at 1–10% per threat actor
- The report coincides with calls from AI researchers and US lawmakers for development pauses and superintelligence bans, contrasting with the Trump administration's focus on competitive AI advancement







