Amid heightened debates about threats from and responsible use: A practical reader guide

Amid heightened debates about threats from and responsible use: A practical reader guide

Amid heightened debates about threats from and responsible use of artificial intelligence, Anthropic, the research-based U.S. company behind the Claude family of large language models and other AI products, has released several cases of misuse of its systems, warning of growing risks as AI models become more capable.

The actors behind the detected misuse included suspected state-sponsored groups, financially motivated criminals, state propaganda institutions and politically motivated individuals. spread misinformation, and enable surveillance have been discussed since their inception, the scope of biological misuse is a relatively new development While the capabilities of AI systems to target cyber operations. In a 154-page report published on Thursday (September 10, 2026), the firm released information about several malicious activities detected and disrupted between December 2025 and August 2026, which had serious implications across seven key areas: scams and fraud, cyber operations, illicit distillation, influence operations, surveillance operations, conventional weapons and biological misuse.

In the report titled “Detecting and countering misuse of AI”, Anthropic referred to biological misuse as “one of the most serious risks” of frontier AI, which could have “catastrophic consequences” without the correct safeguards. The report, coincidentally, comes a day after Jacob Coxon , an AI researcher at Anthropic, quit his post, saying that AI companies were “gambling with our lives” and that the people building AI “earnestly believe that it could kill us all by the end of the decade”.

However, the report found no evidence of any state direction or funding behind these. Anthropic highlighted that the possibility of AI models reaching a stage where they can help make existing pathogens more dangerous, or even create entirely new ones, has been a concern for a long time. The report furnished five cases of actors using Anthropic’s models in ways that could support development of biological weapons. In May this year, Anthropic blocked a request for Claude’s assistance in authoring a grant application for scientific funding for work that involved research that genetically alters an organism to create enhanced biological capabilities against the chikungunya virus. The research in question was aimed at the virus’s transmissibility and immune-evasion properties. The third case involved a grant application authored for covert frontier model access for research on the orthopox virus, which could disable the immune response of host organisms. The remaining two cases involved investigations into non-transmissible novel venoms and toxins. it also noted that there was only ambiguous evidence of dangerous biological uses of AI While all of these activities were disrupted by Anthropic.

Coming to the Indian subcontinent, Anthropic said it dismantled operations promoting the Awami League in Bangladesh, the party of former Prime Minister Sheikh Hasina. The report mentioned a “single actor” who generated at least 1,500 headlines, 300 false narratives, and 1,500 image prompts (Claude does not have an image generation feature yet) through a custom software programme connected to a large language model targeting a domestic audience. It said some content also aligned with pro-Indian geopolitical interests. The report also said that Anthropic disrupted several operations based in China, including a “public opinion monitoring” and dissident surveillance operation, a surveillance and recruitment operation targeting Uyghurs in Syria, a religious affairs intelligence operation targeting Catholic, Tibetan Buddhist, and Taiwanese Christian communities, and a public and state security campaign of “stability-maintenance surveillance and transnational repression”. Anthropic has said it wants AI models to be useful for scientific research and has predicted that AI will transform Biology. However, it has also acknowledged the “dual use” of biological capabilities of AI systems, and advancements would make it difficult to distinguish between beneficial and harmful purposes. Anthropic said that with the current models, which are capable of taking part in complex research activities, this was no longer evident While earlier models clearly showed that they were not advanced enough to meaningfully assist dangerous biological research. it said the information within the request suggested that the research was pursued by civilians but was intended to be carried out at a military facility While the report did not specify where the request originated from. In the same month, Anthropic noted research “outside the U.S.” using Claude in a study on highly pathogenic avian influenza (bird flu), which focused on the virus’s adaptation to mammals and the mechanism by which it causes severe disease beyond the respiratory tract. It said these activities were disrupted out of “abundance of caution” and added that it has introduced strong safeguards against such activities. It said these cases were not evidence of the imminence of biological threats, but showed significant dual-use research efforts associated with state actors.

It noted the proximity of several of these campaigns to elections in the target location, saying that Russian state media produced fabricated claims about Moldova’s President before the September 2025 vote, and a pro-government operator in Kenya prepared fake grassroots social media posts ahead of Kenya’s coming general election. The use of AI involved multi-agent frameworks for reconnaissance, data filtration, and exploitation instead of simple questions and responses from chatbots. It noted that just a year ago, the majority of the disrupted cases would have required several skilled operators with specialised knowledge. The report also detailed targeted propaganda and misinformation campaigns in which operators used Claude to build networks of social media profiles and entire news sites to publish deceptive content. Content generated by Claude was published and broadcast through Russian state-aligned media outlets, including Sputnik Moldova and RIA Novosti for Moldovan audiences, Sputnik en Español for Latin American audiences, and Sputnik Africa for African audiences.

Anthropic, in the report, furnished examples of the most notable and novel malicious activities, ranging from fake dating apps designed to defraud users to sophisticated surveillance systems designed to monitor dissidents, identified and disrupted by its “Threat Intelligence” team. A majority of the operations mentioned in the report, Anthropic said, were directly executed or orchestrated by AI. Humans were involved in setting up targets and reviewing exfiltration, it said. The advance of AI models has done away with the gap separating well-resourced state-sponsored actors and individual operators, Anthropic said in the report. The first case mentioned in the report is of “Russian espionage” in which operators, a Russian speaker among them, automated activities using AI to evade detection and bypass cyber defences. They ran operations attacking Ukrainian military-intelligence targets and European governments, with activities being “consistent with Russian state-nexus espionage”. It furnished nine cases as examples of such “influence operations” by entities, including state media originating from Russia, Iran, Turkiye, and across the Gulf, South Asia, Africa, and Europe, which targeted audiences in six continents. Anthropic said it identified and removed four accounts in which individual actors used Claude as a news production desk to distribute content via Russian state-media outlets.