Anthropic announced Thursday that it has thwarted attempts by people with malicious intent to use its artificial intelligence for activities such as cyberattacks, surveillance and research that could have led to biological weapons.
According to Anthropic, As AI models become more powerful, complex cyberattacks no longer require sophisticated skills, and even individuals acting alone can generate threats that would not have been possible just a year ago. The company said it has incorporated stricter safety measures into its latest models to restrict biological research that could also be used to make weapons.
“The cases we share here are not typical examples of misuse, but rather examples of the most prominent and novel threat activities we have identified to date”Anthropic said in its third report since March 2025, outlining the misuse of AI. The report includes fragments of the malicious code and AI instructions that Anthropic says it has detected, and urges governments and competing AI companies to identify and prevent similar abuses.
“We publish this work because we believe we have a responsibility to expose malicious uses of our services. As models gain in capability, their risks will increase unless AI developers and societal advocates take steps to make them safer,” the company said.
The extensive report from the AI startup, which plans to go public this fall, was published two days after one of its researchers announced his resignation out of concern that Anthropic and its competitors are not acting responsibly in the development of AI. The researcher echoed concerns expressed both inside and outside the sector about the possibility of technology bypassing human control.
Claude was asked to collaborate to make a virus more harmful
Between December 2025 and August 2026, Anthropic researchers detected misuse by a variety of actors, from spyware vendors and “politically motivated individuals” to state-sponsored groups spreading propaganda.
Among the findings of the company’s report are cases of unidentified people attempting to use its models for research that could have led to biological weapons. In one instance, Anthropic claimed that its systems blocked a request from Claude for help writing a grant application for scientific funding.
“The work referenced in the application consisted of gain-of-function research (i.e., research that genetically alters an organism to create a new or improved biological property) on the chikungunya virus. This gain-of-function research focused on the transmissibility and immune evasion properties of the virus,” the report states.
Chikungunya is a mosquito-borne virus that causes debilitating symptoms such as severe pain and fever. The request consisted of a grant proposal for research aimed at enhancing mutations in order to make the virus increasingly harmful. While such research could “certainly” be used to develop better vaccines and treatments, according to Anthropic, “it could also be used to make the pathogen more dangerous.”
Anthropic says it cannot guarantee its models will not cause any harm
None of the cases Anthropic included in its report were found to use its latest, most powerful “Claude Fable” or “Mythos” class models, with the exception of one case of “illicit distillation” that Anthropic described as “an industrial-scale covert campaign to extract the capabilities of one model and replicate them in another model without authorization.”
Anthropic said its previous models, such as the 2025 Claude Opus 4 and Claude Sonnet 4.5, “were well below the threshold at which they could significantly assist an expert user in conducting hazardous biological research.”
“As a consequence, the security measures applied to these models were less strict and focused primarily on preventing access to content that could help beginners recreate known biological weapons,” the report states. “However, for current models, which are capable of assisting in a wide range of complex scientific research tasks, the evidence is no longer conclusive and we cannot offer that same guarantee.”
For this reason, Anthropic has implemented “tighter security measures that restrict access to a wide range of dual-use biological research queries” in its most recent models, such as the Claude Fable 5, the report states.
As companies incorporate increasingly powerful artificial intelligence models, experts have urged governments to regulate this technology, rather than relying on the sector itself to regulate itself.
John Thickstun, an associate professor of computer science at Cornell University, said this is an uncomfortable situation for companies like Anthropic and OpenAI, as they are expected to determine which behaviors are safe and which are not, and to make “value judgments on a societal scale without any democratic or deliberative oversight.”
The report arises following a serious warning from a researcher
Anthropic also discovered groups that created hundreds of social media accounts that appear to belong to ordinary people, and then posted content spreading the same political opinion over the course of a week. The company detailed nine cases of this type that it detected, coming from Russia, Iran, Turkey and the entire Persian Gulf region, South Asia, Africa and Europe.
Although social media companies can detect influence operations on their platforms once the posts are already circulating, “at Claude we can detect them while the operation is still developing.”
Anthropic published this report after one of its researchers, Jacob Coxon, announce his resignation fearing that the company and its main rival, OpenAI, “are rushing towards a superintelligence capable of improving itself and are playing with our lives.” In his post, Coxon warned that some of his colleagues now believe that AI could pose a threat to human life by the end of this decade.
However, Anthropic has stated that it has blocked each and every malicious activity it has identified, has used the experience to strengthen security measures and has shared information with government authorities and industry partners.