New Delhi: What do Iranians, Houthis, Russians, Bangladeshis and scientists have in common? All of them use Claude to research, mostly on how to build weapons, both conventional and biological.
Anthropic in its latest 154-page report highlighted at least five cases involving scientists who used its AI models for researching material that could potentially help develop biological weapons. Some of these researchers, it said, bypassed Anthropic’s safeguards designed to block users from “unsupported regions” and attempted to conceal the purpose of their work.
The cases span the period from December 2025 through August 2026. In all cases, Claude Haiku, Sonnet, and Opus models were used. The report classifies the users as Generative Threat Groups (GTGs), Anthropic’s internal designators for actors observed to be abusing AI. It said that throughout this year it foiled several attempts by leading scientists to use their LLM models for research that could potentially help develop biological weapons.
Referring to one such case, Anthropic said it detected activity involving research of chikungunya virus. Such research, it said, could contribute to vaccine development, but also potentially be misused to develop mutations to the virus. The company told The New York Times that this case was particularly concerning because the research was performed at a military research institute.
“Biological misuse is one of the most serious risks of frontier AI models,” Anthropic said, warning that, without proper safeguards, such capabilities could have catastrophic consequences.
Anthropic said it banned the accounts involved but did not identify the researchers, institutions or countries, citing uncertainty about their intentions.
Also Read: ‘This isn’t a marketing stunt. AI could kill all humans.’ Anthropic researcher quits, sounds alarm
Cognitive warfare using AI
The company also reported other cases of its AI being used for cyber operations, surveillance and propaganda. These included alleged Russian espionage and cyberattacks, a China-based surveillance programme targeting Uyghurs in Syria and dissidents, and propaganda campaigns in Russia, Malaysia, Iran and Bangladesh.
In the case of alleged Russian espionage, Anthropic identified GTG-20006 as an cyberattack actor who increased their speed of evading detections by automating operations using AI and ran operations attacking military intelligence targets in Ukrainian and European governments, as well as diplomatic and defence organisations and individuals connected to US foreign policy.
In rural Bangladesh, there was an ‘automated disinformation network’ that used Claude to generate fabricated Bengali-language news in Bangladesh.
Then there were three Iranian state-aligned accounts that were found to be using Claude to set up influence operations campaigns. “The people behind them were planning and prepping content to support what they called a “soft war” or “cognitive warfare” program,” the report says.
Claude was also reportedly used in Yemen, China and Russia to develop software related to conventional weapons, including firearms, missiles, armed drones and bombs.
“A majority of the operations described in this report were enabled by AI via direct execution or orchestration. The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration. Humans remained in the loop by setting the targets of attacks and reviewing exfiltration,” the report said.
(Edited by Amrtansh Arora)
Also Read: Anthropic lets enterprise clients keep data on own servers with new Claude models under EU rules
