Anthropic catches Claude aiding bioweapons research, state surveillance
RNA Media illustration for representation.
New Delhi: Anthropic, the American company behind the Claude family of artificial intelligence models, has disclosed that its systems were exploited both to advance biological research with possible weapons applications and to power state-backed surveillance operations against dissidents and minorities abroad. The revelations appear in the company’s latest threat intelligence report, published on Thursday, and mark one of the most detailed public accounts yet of how governments and individual researchers are testing the limits of frontier AI.
The report catalogues misuse across seven areas – cyber operations, influence campaigns, surveillance, scams, biological research, conventional weapons, and unauthorized model distillation – identified and disrupted between December 2025 and August 2026. Two strands carry the most serious implications for international security: attempts to use Claude for research bordering on gain-of-function work, and its use by state-linked actors in China, Iran, and Mali to automate espionage against diaspora communities and political opponents.
Biological misuse: Five concering case studies
Anthropic said in the report that it regards biological misuse as one of the most serious risks its models pose, and it detailed five case studies of concerning activity uncovered during the review period. Several involved researchers based outside the United States who appeared to circumvent regional access controls and disguise the purpose of their queries to get past the company’s safeguards.
In one instance, dated May 2026, a user linked to a military-affiliated institute sought help drafting a grant application for gain-of-function research on the chikungunya virus, a mosquito-borne pathogen. The proposal reportedly aimed to identify mutations that could make the virus more transmissible and better able to evade the immune system as it passed through live animals.
A separate case involved a researcher outside the US who spent several weeks using Claude to study highly pathogenic avian influenza, focusing on how the virus adapts to mammals and what makes it more severe. Anthropic said its classifiers had automatically confined this activity to its weaker model tier, limiting the assistance to study design and data analysis rather than more sensitive technical detail.
Anthropic also flagged a case linked to a state-associated infectious-disease laboratory, where Claude Opus 5 was used to draft, from start to finish, a grant application concerning orthopoxviruses in roughly an hour. This viral family includes variola, the pathogen behind smallpox, and mpox. Two further cases concerned venom peptides and toxin redesign, work that can support antivenom development but could equally be turned toward more dangerous ends.
The company was careful to add a caveat that possessing biological expertise, laboratory access, and animal models does not, on its own, indicate hostile intent. It said explicitly that it was not asserting the researchers involved intended to cause harm, and it withheld their identities, nationalities, and institutional affiliations to avoid exposing working scientists to reprisal or misidentification.
That caution sits alongside a blunter warning elsewhere in the report – that sophisticated attacks no longer require sophisticated attackers, because AI has narrowed the gap in skills and resources that once separated well-funded state programmes from individual operators. Susan Monarez, a microbiologist and former American public health official who reviewed the findings before publication, told the New York Times that advanced models could help malicious actors conceal dangerous work behind seemingly legitimate scientific goals.
Anthropic said its newer models, including Claude Fable 5, carry tighter safeguards restricting a wide range of dual-use biological queries, and that none of the disclosed misuse cases involved its most capable Fable or Mythos-class systems. The company added that it had shared its findings with relevant authorities and, where appropriate, with other AI developers.
The disclosure lands amid a wider reckoning within the AI industry over how quickly to deploy increasingly capable systems. In July 2026, close to 1,400 employees across AI companies signed an open letter urging Washington to regulate the technology more firmly, and OpenAI’s chief scientist, Jakub Pachocki, warned only this week that AI capabilities are outpacing researchers’ ability to monitor and control them reliably. Regulation, for now, remains largely a matter of self-policing by the companies themselves.
State-backed surveillance in China, Iran and Mali
The second major thread in the report concerns state-sponsored surveillance, an area Anthropic said is being reshaped by AI in ways that lower the cost and effort of spying on citizens. The company said it detected and disrupted several such operations between January and July 2026, tracing them to actors linked to the governments of China, Iran, and Mali.
These campaigns, Anthropic said, targeted the same diaspora and dissident communities that these governments have historically pursued: pro-democracy figures from Hong Kong, Tibetan and Falun Gong practitioners across Asia, and Iranian minority groups and regime opponents living abroad. In China, the company found a religious affairs intelligence office that had reduced its monitoring operation from several teams of human analysts to a single official using Claude, now producing thousands of investigations a month.
A separate Chinese operation, which Anthropic linked with high confidence to actors aligned with Beijing, used Claude to track, profile, and attempt to recruit Uyghur individuals in Syria. The model handled real-time translation of responses and even role-played as a domain expert to check the credibility of the material being gathered, while other Chinese officials reportedly used it to automate routine intelligence reports and query surveillance databases.
In Mali, Anthropic said a single consultant working for the national security establishment used Claude as the primary engineering resource behind Lakana 360, a mass-interception platform capable of monitoring roughly 25 million SIM cards across all three of the country’s mobile networks. The system compiles dossiers on individuals, and Anthropic noted that a warrant requirement for generating those dossiers had reportedly been dropped at the operator’s request.
Iranian state-linked actors, meanwhile, used Claude to build a malicious browser extension for Firefox that harvested users’ identities from social media, and separately developed a method to identify individuals through their social media accounts. Anthropic said it had also banned an account, detected in June 2026, that had used Claude to build a commercial surveillance platform aimed at monitoring people across Iran and the Persian Gulf.
Anthropic’s head of threat intelligence, Jacob Klein, told Axios that AI was not changing who governments choose to target, but was making the process considerably cheaper and faster. He said individual state employees or contractors could now automate work that would once have required entire teams of analysts, compressing years of institutional capability into one operator and a chat window.
Notably, none of the surveillance cases in the report involved Anthropic’s most advanced systems. Everyone was carried out using the older Claude Haiku, Sonnet, or Opus tiers, rather than the newer Fable or Mythos-class models – a detail that suggests even widely available, less capable models carry meaningful surveillance potential once put to determined use.
The report also accused two Chinese AI developers, Moonshot AI and DeepSeek, of covertly routing user queries through Claude while extracting the resulting data to train their own models, a practice the industry calls distillation. A separate campaign, which Anthropic attributed to Alibaba, reportedly involved more than 3,500 fraudulent accounts generating up to three million exchanges a day at its peak, aimed specifically at extracting Claude’s reasoning capability.
Anthropic said it had banned every account associated with the surveillance and distillation cases identified in the report and had shared relevant findings with governments, law enforcement agencies, and other technology companies where appropriate. It framed the disclosures as part of a broader push for transparency, arguing that detailed case studies, rather than vague warnings, give researchers, policymakers, and rival AI firms better tools to catch similar misuse of their own systems.
Together, the two threads of the report – biological research skirting the edge of legitimate science, and surveillance systems built by a single consultant with a chatbot – illustrate a pattern common to frontier AI. The same capability that promises real public good can, in the wrong hands, be repurposed with unsettling ease.
That duality is likely to remain at the centre of the debate over how AI companies, and the governments that regulate them, choose to proceed.
