
This photograph shows a figurine in front of the logo of the AI assistant "Claude" built by the US artificial intelligence safety and research company Anthropic during a photo session in Paris on February 13, 2026. Joel Saget/AFP via Getty Images
Anthropic published its most detailed accounting yet of Claude AI misuse on Thursday, disclosing that newer versions of its models can no longer be assumed to fall safely below the threshold for meaningful bioweapons assistance — and that a group of Russia-linked freelancers used Claude Code to build a fully autonomous drone swarm capable of selecting human targets and issuing detonation commands without any human in the loop.
The report, titled Detecting and Countering Misuse of AI: September 2026, covers activity Anthropic disrupted between December 2025 and August 2026 across seven categories of harm. The company identified and blocked five separate attempts by scientists to use Claude for research that could support biological weapons development — including a gain-of-function study intended for a military research institute — alongside a documented Russian state-nexus espionage campaign, nine influence operations spanning six continents, and multiple cases of conventional weapons software development in China, Russia, and Yemen.
This is Anthropic's fourth publicly released threat intelligence report since March 2025.
The most consequential finding in Thursday's report is not a specific attack but a structural admission.
"Older models were well below the threshold where they could meaningfully assist in bioweapons development," Anthropic stated in the report. "This is no longer a certainty with newer models."
That sentence represents the first time a major AI company has said, in a public report, that it can no longer rely on a capability gap between its latest models and the level of technical expertise needed to meaningfully assist someone seeking to develop biological weapons. Anthropic said it has responded by implementing stricter safeguards on Claude Fable 5 and subsequent models, specifically restricting access to what the company calls "a wide range of dual-use biological research queries."
The five biological case studies documented in the report all involved requests whose stated purpose was legitimate — scientific research — but whose methods carried weapons-relevant risk. One case from May 2026 involved a scientist affiliated with a military research institute who asked Claude to help draft a grant application for gain-of-function research on chikungunya virus, a mosquito-borne pathogen that causes severe fever and debilitating joint pain for which no licensed treatment exists. The proposed research would have engineered mutations to increase the virus's transmissibility and capacity to evade immune responses through successive live-animal infections — a methodology researchers use to study how pathogens might naturally evolve, and one that biosafety advocates have long argued carries unacceptable dual-use risk. Anthropic said it blocked the request and referred the case to law enforcement.
A second case involved a researcher who spent weeks using Claude on avian influenza work focused on mammalian adaptation and airborne transmissibility. Anthropic said its classifiers detected the activity and confined the researcher to its least capable model class — Claude Sonnet 4 and Haiku 4.5 — limiting what the researcher could obtain. The remaining three biological cases involved orthopoxviruses, venom-related compounds, and biological toxins. In none of the five cases, Anthropic acknowledged, could it conclusively determine whether the researchers intended harm.
That ambiguity is definitional, not incidental. Gain-of-function research is a recognized category of dual-use research of concern (DURC) precisely because the same laboratory techniques that allow scientists to understand how a pathogen might evolve naturally are also the techniques that could, in the wrong hands, produce a more dangerous version deliberately.
What the report signals is that AI is now capable enough to help close the knowledge gap that previously made this work accessible only to trained virologists at properly equipped facilities — and that Anthropic is no longer certain its most powerful systems cannot provide that uplift.
Gain-of-function research — studies that genetically alter an organism to give it new or enhanced properties — became one of the most contested areas in biology after landmark H5N1 ferret transmissibility studies by researchers Ron Fouchier and Yoshihiro Kawaoka showed that the virus could be made transmissible between ferrets, raising alarms about both the research and its publication. The U.S. government imposed a moratorium on certain types of gain-of-function research from 2014 to 2017, then established the P3CO Framework for pandemic oversight (Potential Pandemic Pathogen Care and Oversight) to govern it going forward.
The case documented in Anthropic's report — chikungunya virus, immune evasion, live-animal serial passage — falls precisely in the zone that regulatory bodies have been debating for a decade: research that could yield vaccine insights, or could yield a more dangerous pathogen, depending on who conducts it, where, and with what safeguards. The fact that a grant application for this work was routed through a platform serving dozens of life-sciences researchers, many connected to civilian and military institutions, underscores that the threat environment Anthropic is describing is not lone-actor in character. It is embedded in the ordinary infrastructure of international science.
The biological cases attracted the most attention in Thursday's report, but the conventional weapons section contains a finding with different, and in some respects more immediate, implications.
Anthropic disclosed that Russia-based freelancers, whom the report describes as likely motivated by financial or ideological factors rather than state direction, used Claude Code to build software for a complete autonomous first-person-view drone swarm system named DronDoc (also referenced in the report as Serafim). The system included shared swarm memory, terminal guidance, onboard attack and return-to-base logic, and low-level chip architecture. Most significantly: the onboard model was designed to select targets — including a target class explicitly labeled "person" — and issue detonation commands with no human in the loop.
This is not a prototype in a controlled laboratory environment. The report indicates the drone guidance system was test-fired in connection with the Yemen case, which involved Houthi-affiliated actors and guidance and navigation control software for rockets and missiles.
International humanitarian law discussions define lethal autonomous weapons systems (LAWS) as systems capable of selecting and engaging targets without real-time human authorization. The DronDoc/Serafim system, as described in Anthropic's report, meets that definition. It was built by a non-state actor, using a commercially available AI coding assistant, apparently in less than a development cycle that would previously have required specialized embedded-systems engineering teams. That fact is relevant regardless of whether the system performed as intended.
Anthropic said it disrupted the activity and banned the accounts involved. The report includes six conventional weapons cases total: three in China, two in Russia, and one in Yemen.
The cyber operations section of Thursday's report documents a sustained Russian state-nexus espionage campaign Anthropic tracked as GTG-20006, whose tradecraft and targeting Anthropic said are consistent with publicly documented reporting on the actor known as Midnight Blizzard SVR-linked group.
The campaign targeted Ukrainian and European government ministries, military intelligence bodies, diplomatic missions, think tanks, and defense-industrial companies, with a recurring focus on drone technology and supply chains. Anthropic found more than 20 distinct organizations in the actor's operational planning and confirmed intrusions.
What made the operation architecturally significant was not its targeting — Russian espionage against Ukraine and European institutions is a documented persistent threat — but its malware management. GTG-20006 built AI-driven workflows that automatically monitored whether deployed implants had been detected by security products, then modified and redeployed the malware to evade those detections, without human intervention, cycling through evasion iterations until the tools were undetected again.
The implication Anthropic draws is precise: defenders who previously could slow an attacker's operational tempo by publishing new detection signatures have lost a meaningful cost-imposition mechanism. The attacker can now close the loop — adapting evasion faster than the defender can build and deploy countermeasures.
Across confirmed intrusions, GTG-20006 bulk-exported email records from at least eight organizations, including a national prosecutor's office, a military education institute, and a regional intergovernmental body. The actor exfiltrated more than 300,000 national identity records and the commercial registry data of more than 500,000 companies from a North African government technology authority. The actor also stole a complete proprietary software development kit for a military drone vision system, spending several days reverse-engineering its architecture, hardware bill of materials, supplier dependencies, and details of an unannounced product.
Additionally, the actor compromised at least three hotel-network vendors, using manipulated DNS records to intercept guests' device traffic, then delivered malware to hotel guests whose profiles matched Ukrainian diplomatic and military targets. Microsoft documented this technique in a July 31, 2026 report it called CaptiveCrunch hotel malware campaign.
Midnight Blizzard is a Russian state-nexus APT group extensively documented by Microsoft, Mandiant, and other threat intelligence firms. The group has been linked to Russia's Foreign Intelligence Service (SVR) and has been active since at least 2018. Its targets have historically included government agencies, technology companies, and international organizations in the United States, Europe, and Ukraine.
Anthropic's internal designation for the actor is GTG-20006. The report attributes one of the operators to a Russian speaker using the handle "JackPoterz."
Beyond the cyber and biological cases, Thursday's report documents nine influence operations originating in Russia, Iran, Turkey, and across the Gulf, South Asia, Africa, and Europe.
Russian state media entities, the report found, used Claude as a content production layer, with output piped directly into editorial pipelines at Sputnik Moldova, RIA Novosti, Sputnik en Español, and RT's English-language newsroom. One case involved a former Sputnik Moldova editor-in-chief who used Claude to generate fabricated articles that were amplified across a network of Moldovan and Russian outlets to manufacture what Anthropic called "false verification loops" — making the same fabricated claim appear to come from multiple independent sources.
A commercial influence-as-a-service operation based in France ran approximately 70 fabricated news websites in roughly 20 languages, shifting its political stance based on whoever was paying at the time. A separate operation, traced to an Istanbul-based technology company called BBS Bilisim Teknolojileri, ran approximately 1,000 fake social media accounts targeting the Malaysian electorate constituency by constituency, using actual census and voter data, and generated fabricated intelligence dossiers against named opposition politicians.
Iranian state propaganda institutions — the Islamic Culture and Communications Organization, the Islamic Propaganda Office of Khorasan Razavi, and the Bina Cultural Observatory — each ran separate operations building doctrine manuals, persona systems, and disinformation content under what Iranian institutional documents described as a framework of "Jihad al-Tabyin," or explanatory jihad.
A pattern running across the report's cyber cases was the emergence of the AI supply chain itself as a primary criminal objective.
A cluster of cybercriminals Anthropic linked to the ShinyHunters collective ran mass-automated credential harvesting operations, scanning 1.8 million Android application packages for exposed API keys and routing them to Telegram channels organized by credential type. In one intrusion, the actor exfiltrated more than a terabyte of data — including hundreds of thousands of national identifiers and millions of payment card records — from a technology provider, then staged the stolen material publicly to pressure the victim into paying a ransom. At an airline, the attackers accessed systems holding tens of millions of passenger records. Against a separate software-as-a-service provider, the group used a stolen foothold to extract data belonging to roughly 200 of the provider's downstream customer organizations in approximately 34 hours. AI agents performed nearly all of the work.
A separate actor (GTG-50020) attacked roughly 30 AI companies in about four days using similar prompt-injection and credential-theft techniques, with an explicit ambition — which Anthropic says was never realized — to access a pre-release Claude model.
Chinese-speaking operators at a Chinese university in Hunan (GTG-10007) maintained autonomous vulnerability research workflows that produced more than a dozen possible zero-day findings in major security products during a single month. These operators ran parallel workstreams around the clock — the collection fleet ran on a pre-set schedule with no human in the loop.
Jacob Klein, Anthropic's Head of Threat Intelligence, has described the company's position as one of continuous evolution: building and refining safeguards based on what each investigation reveals, then sharing findings with government authorities and industry partners. According to his RSA Conference profile, Klein previously built Coinbase's Trust and Safety organization and served as a Strategic Threat Intelligence Manager at Google.
In every case documented in Thursday's report, Anthropic said it disrupted the activity, banned accounts, applied what it learned to strengthen safeguards, and shared intelligence with authorities and industry partners where appropriate. The company framed the report as part of a transparency commitment.
What the report cannot disclose is the full scope of what it missed. Anthropic can document what its systems caught — the five biological cases, the 20+ GTG-20006 targets, the 70 influence sites. It cannot say how many similar attempts succeeded before detection, how many occurred on platforms it does not control, or how many were conducted in ways that did not trigger any of its monitoring systems.
There is also a structural question the report raises but cannot answer: Anthropic is the only institution currently positioned to investigate Anthropic's threat intelligence. No independent body has standing to audit its methodology, assess what the company chose not to publish, or evaluate whether its safeguard improvements are adequate. As the Eastern Herald observed in its own analysis of Thursday's report, "that combination of transparency and opacity is not unique to Anthropic. It is, at this stage, the defining condition of AI threat intelligence as a field."
Anthropic stated in the report that it hopes the findings will help other developers recognize similar patterns, give governments and civil society a clearer view of how threats take shape, and strengthen collective defenses. Whether those settings produce binding oversight mechanisms, voluntary commitments, or neither is a question Thursday's report cannot answer.
"As models become increasingly capable," the report states, "their risks will increase, unless AI developers and society's defenders act to make them safer."
Anthropic's report said that older Claude models were "well below the threshold where they could meaningfully assist in bioweapons development," and that "this is no longer a certainty with newer models." This means Anthropic can no longer rely on the assumption that its most capable AI systems are too limited to provide useful technical guidance to someone trying to develop a biological weapon. The company said it has responded by adding stronger restrictions on dual-use biological research queries in Claude Fable 5 and subsequent models. It is the first public statement by a major AI company that its frontier models have approached this capability boundary.
Gain-of-function research alters a pathogen or organism to give it new or enhanced properties — for example, making a virus more transmissible or better at evading immune responses. The field is legitimately used in pandemic preparedness research, but the same techniques can also make pathogens more dangerous. The United States government established oversight frameworks (including the P3CO Framework) specifically because this research is dual-use: the knowledge needed to study how a virus might naturally evolve is also the knowledge that could, in theory, be used to engineer a more harmful version deliberately. The chikungunya case in Anthropic's report — involving serial animal passage to enhance transmissibility and immune evasion, connected to a military research institute — fell directly into this contested zone.
DronDoc (also called Serafim in the report) is an autonomous first-person-view drone swarm system built with Claude Code by Russia-linked freelancers. It includes shared swarm memory, guidance and attack logic, and — most significantly — an onboard AI model that can independently select targets, including a target class labeled "person," and issue detonation commands without human involvement. International discussions on lethal autonomous weapons systems (LAWS) have debated exactly this capability: a weapon that can select and engage human targets without real-time human authorization. What the report documents is a non-state actor constructing such a system using a commercially available AI coding tool in a single development cycle.
Both things are simultaneously true, as the Eastern Herald noted in its analysis of the report. Anthropic disrupted all five biological cases, identified the Russian espionage campaign, and blocked multiple autonomous weapons development attempts — evidence that its safety monitoring has real-world effect. At the same time, the report can only document what the company caught. It cannot say how many attempts succeeded before detection, how many occurred through other platforms, or whether the safeguards it has added to newer models are sufficient. No independent body currently has the authority to evaluate that question. The report is simultaneously evidence that safety monitoring matters and a reminder that self-reported threat intelligence has inherent limits.
