Anthropic Warns AI Models Are Being Used in Cyberattacks, Espionage and Missile Research

Artificial intelligence is no longer being misused only for scams, fake content or automated hacking attempts. Anthropic says increasingly capable AI models are now being integrated into sophisticated cyber operations, surveillance campaigns and weapons-development efforts involving actors linked to China, Russia and Yemen.

In its September 2026 threat-intelligence report, Anthropic revealed that users attempted to employ its Claude AI models for activities ranging from autonomous cyberattacks and intelligence gathering to missile guidance research, drone-swarm development and electronic-warfare planning. The company said it disrupted the identified operations, banned associated accounts and shared relevant information with authorities and industry partners.

The report covers malicious activity detected between December 2025 and August 2026 and represents one of the clearest warnings yet that AI systems are shifting from passive assistants into tools capable of coordinating complex, multi-stage operations.

AI Is Moving From Chatbot Assistance to Autonomous Operations

Anthropic says the most concerning development is not simply that attackers are asking AI questions.

Instead, threat actors are using AI as an orchestration layer capable of dividing a large operation into smaller tasks, assigning them to multiple agents and maintaining information across sessions.

In one cyber operation attributed to Chinese-speaking operators, Claude was reportedly used to coordinate reconnaissance, vulnerability research, malware development, attempted intrusions and intelligence collection against approximately 50 organisations across sectors including government, finance, healthcare, energy, manufacturing and technology.

The operators reportedly used multiple AI agents working in parallel. One agent could focus on reconnaissance, another on vulnerability analysis and another on maintaining collection infrastructure.

This is a major change from the traditional model of a hacker manually conducting each stage of an attack.

Chinese Operators Allegedly Built AI-Assisted Espionage Workflows

Anthropic identified a China-based group that allegedly used Claude to develop a coordinated intelligence-gathering operation.

The company said the group used persistent campaign records, shared tools and parallel workstreams to maintain continuity between sessions. The operation reportedly included foreign-network reconnaissance, exploit research, malware development and the collection of publicly available military and government information.

Anthropic also said the operators used “agent swarms”, in which a lead AI agent delegated tasks to several sub-agents operating simultaneously.

Although humans remained involved in setting targets and reviewing results, the AI systems reportedly handled a substantial portion of the repetitive technical work.

This is particularly concerning because automation can reduce the amount of specialist labour required to maintain a cyber campaign and allow operations to continue even when human operators are not actively present.

Russian-Linked Actors Used AI in Drone-Swarm Research

The report also describes a separate group of Russian-speaking actors who used Claude in the development of software related to autonomous drone swarms.

Anthropic said the group trained a computer-vision system using battlefield footage and created software intended to classify targets and support autonomous engagement. The company assessed that the group appeared to be a small freelance team rather than a confirmed Russian state organisation, although the actors claimed connections to Russian defence-related funding programmes that Anthropic could not independently verify.

The report does not establish that the group successfully deployed an operational autonomous weapons system. However, Anthropic said the actors loaded code onto real development boards and carried out simulation and hardware-in-the-loop testing.

The case illustrates how AI may accelerate the software side of military research even when the physical hardware remains difficult and expensive to develop.

Yemen-Based Cell Attempted Missile Guidance Development

One of the most serious cases involved a weapons-development cell based in northern Yemen.

Anthropic said the group was working on several guided-weapons programmes and used Claude Code to assist with guidance, navigation and control software. The company said the actors attempted to conceal their actual objectives by splitting their requests across multiple sessions and disguising the purpose of the software.

According to Anthropic, the group conducted a live guided-rocket test that appeared to fail. Within hours, the users returned to Claude to analyse the failure.

Anthropic said it found no evidence that the actors successfully fielded an operational weapon, but the group had already created an offline simulation toolkit that could continue functioning without access to Claude.

The report is especially significant because it suggests that AI assistance was not limited to theoretical discussion. The actors were reportedly attempting to connect software development, simulation and physical testing into a broader engineering workflow.

China-Based Researcher Used AI for Electronic-Warfare Planning

Another case involved a China-based actor who reportedly used Claude to create a Chinese-language software suite related to electronic warfare and air-defence suppression.

Anthropic said the system was designed to analyse radar and communications systems, assess vulnerabilities, model jamming effectiveness and help prioritise targets in simulated scenarios.

The company assessed that the actor was likely connected to Chinese defence or military-industrial research institutions, although it did not describe the person as a formally identified government operator.

This case demonstrates how AI misuse can extend beyond conventional cyberattacks. A model may also be used to build analytical tools that support military planning, intelligence assessment and battlefield decision-making.

Surveillance Operations Also Raise Human-Rights Concerns

Anthropic’s report includes several examples of AI being used for surveillance and profiling.

The company said actors connected to China, Iran and other locations used Claude to process large amounts of online communications, create profiles of individuals and evaluate people for possible targeting.

In one case, AI was reportedly used to analyse material collected from more than 100 WhatsApp groups and dozens of Telegram channels. The resulting profiles allegedly included information about financial pressure, family relationships and ideological views.

Anthropic said some operations focused on journalists, dissidents and diaspora communities.

Such uses raise concerns not only about cybersecurity but also about privacy, freedom of expression and the ability of governments or contractors to scale surveillance operations using AI.

AI Is Lowering the Cost of Complex Cyber Operations

Traditional cyber operations often require teams of specialists, including vulnerability researchers, programmers, infrastructure administrators and intelligence analysts.

Anthropic’s findings suggest that AI can reduce the amount of human effort required to coordinate those roles.

An attacker may still need to choose targets and approve important actions, but AI can assist with repetitive research, code generation, documentation, data processing and task coordination.

This does not mean AI can independently conduct every cyber operation successfully. Many activities still require specialised knowledge, access to infrastructure and real-world decision-making.

However, even partial automation can increase the speed and scale of malicious campaigns.

Anthropic Says Its Safeguards Were Circumvented

The company said its safeguards blocked many harmful requests, but not all of them.

Threat actors reportedly attempted to evade protections by hiding their true objectives, dividing work into separate conversations, using coded descriptions and routing traffic through intermediaries or virtual private servers.

This creates a difficult challenge for AI developers.

A single request may appear harmless when viewed in isolation. A request for software debugging, mathematical modelling or image classification might become suspicious only when combined with dozens of related sessions.

Anthropic said it has introduced new behavioural detections designed to identify patterns associated with weapons development, cyber exploitation and coordinated misuse.

Account Bans Are Not Enough on Their Own

Anthropic said it banned the accounts connected to the operations and shared intelligence with public- and private-sector partners.

But the company also acknowledged a major limitation: by the time suspicious activity is detected, users may already have copied code, built offline tools or transferred the results to systems outside the AI provider’s control.

That is why account suspension alone cannot completely eliminate the risk.

Once an AI-assisted workflow has been exported, it may continue functioning without access to the original model. This is particularly relevant when users employ AI to create software, simulations or data-processing systems that can later be run independently.

The Report Does Not Mean AI Has Created Fully Autonomous Weapons

Anthropic’s findings should not be interpreted as proof that AI systems are independently building and deploying advanced weapons without human involvement.

The cases described still involved human operators, physical equipment, development environments and testing processes.

The significance is that AI appears to be helping actors accelerate specific parts of complex programmes, including software engineering, simulation, intelligence collection and operational planning.

That distinction is important. AI is not necessarily replacing entire military or cyber organisations, but it may be reducing the time, cost and expertise needed to carry out selected tasks.

Why This Matters Beyond Anthropic

The report has implications for the entire AI industry.

Most advanced AI models are general-purpose systems. The same coding, research and analytical capabilities that benefit legitimate users can potentially be redirected toward harmful activity.

A model does not need to be specifically designed as a cyber or military tool to become useful in those contexts.

The challenge is therefore not simply blocking individual dangerous questions. It involves monitoring patterns of behaviour, detecting coordinated activity, restricting suspicious accounts and working with governments, cybersecurity companies and other AI developers.

Anthropic said it hopes the report will help other developers recognise similar patterns and strengthen collective defences.

AI Safety Is Becoming a Real-World Security Issue

The latest report shows that AI safety is no longer limited to questions about misinformation, bias or inaccurate answers.

It now includes practical concerns about:

  1. automated cyber operations
  2. intelligence collection
  3. surveillance
  4. military software
  5. weapons research
  6. fraud networks
  7. large-scale influence campaigns

The more capable AI systems become, the more valuable they may be to both legitimate organisations and malicious actors.

Anthropic’s findings suggest that the central security question is no longer whether AI will be misused, but how quickly developers and governments can detect misuse before it becomes operationally significant.

The company says it disrupted the cases described in the report. But the existence of offline tools, copied code and multi-platform access means that stopping one account or one model provider may not be enough.

The emerging challenge is broader: preventing powerful AI capabilities from becoming an invisible force multiplier for cybercriminals, intelligence operators and weapons developers.