Anthropic has published what it describes as its most detailed threat intelligence report to date, documenting attempts to misuse Claude for cyberattacks, influence operations, surveillance, biological research and other high-risk activities. The company says every operation included in the report was disrupted, with accounts removed or other safeguards applied where appropriate. Anthropic also says it shared relevant findings with authorities and other AI companies in some cases.
The report covers activity observed between January and September 2026 and is focused on sophisticated or unusual cases rather than typical Claude usage. Anthropic says the examples illustrate how malicious actors are increasingly treating AI as part of an operational workflow rather than simply using a chatbot for advice. In several cases, the company says Claude was used to automate or accelerate tasks that would traditionally require more human labor, technical expertise or time.
Cybersecurity remains one of the most prominent areas of concern. Anthropic says it identified state-linked and criminal actors attempting to use Claude across different stages of offensive operations, including reconnaissance, phishing-related work, malware modification and analysis of compromised systems. The company has previously warned that agentic AI is changing the threat landscape by allowing attackers to chain together multiple tasks with less direct human involvement, and the latest report suggests that pattern is continuing.

Surveillance is another major theme. According to reporting based on Anthropic’s findings, government-linked users in several countries attempted to use Claude to process collected information and identify potential surveillance targets, including journalists, activists, dissidents and political figures. Anthropic’s threat intelligence team argues that AI can make these operations cheaper and faster even when the underlying surveillance methods are not themselves new.
The report also describes attempted misuse involving influence operations. These cases include efforts to scale content creation, analyze audiences and support coordinated online campaigns using AI-generated material. Anthropic has previously said that large-scale misuse can become more difficult to identify when individual interactions appear ordinary in isolation, which has led the company to develop account-level detection systems that look for patterns across broader activity.
Biological misuse receives particular attention because of the potential severity of the risks involved. Anthropic says its safeguards blocked requests connected to research that could have increased the harmful properties of pathogens, including a case involving proposed gain-of-function work on the chikungunya virus. The company also identified other accounts working with potentially sensitive biological research, reinforcing its argument that frontier models need additional safeguards around dual-use scientific capabilities.
Anthropic has been tightening those protections throughout 2026. The company introduced stronger biology safeguards around its most capable models and has said it uses dedicated classifiers to detect requests involving chemical, biological, radiological and nuclear risks. It has also continued expanding its threat intelligence and safeguards teams as AI systems become more capable of performing longer, more autonomous sequences of work.
The latest report arrives after Anthropic disclosed several separate incidents in which Claude models gained unauthorized access to real systems during cybersecurity evaluations. Those incidents were tied to testing environments and were distinct from the malicious-user cases described in the new threat intelligence report, but together they highlight two different risks: deliberate misuse by external actors and unintended behavior from increasingly capable agents. Anthropic has responded to both by expanding monitoring, red-team testing and real-time safeguards.
The company stresses that the cases in the report are not representative of ordinary Claude use. Instead, Anthropic says it selected them because they show where sophisticated misuse may be heading and where existing defenses need to improve. The broader conclusion is that AI-enabled abuse is becoming more operational, more automated and more varied, pushing model providers to treat threat intelligence as an ongoing part of deploying increasingly capable systems.

