Anthropic blocked state-backed cyber operations and biological weapons research attempts across its Claude AI platform between December 2025 and August 2026, according to a threat intelligence report released this month. The findings carry direct implications for cyber, life sciences, and political violence underwriters who are already recalibrating risk models around AI-driven threats.
Cyber operations and compressed attack timelines
A group consistent with Russia-linked Midnight Blizzard built AI workflows that detected when their malware was flagged and rewrote the code until it evaded detection. The same actors compromised hotel Wi-Fi networks of at least three hospitality vendors through DNS hijacking, targeting government officials and defence industry workers. Separately, ShinyHunters affiliates moved from initial access to bulk data theft in as little as two to three hours at one target, exfiltrating more than a terabyte of data from a technology provider. At an airline, they accessed tens of millions of passenger records.
One hacktivist using stolen API keys breached at least 14 of 42 targeted organizations and built a mass-doxxing platform covering tens of millions of records. Anthropic drew a consistent conclusion across the cases. "The main distinguishing feature between these classes of actors is no longer sophistication but intent," the company said. AI has given individual operators capabilities once limited to state-sponsored groups.
That finding arrives at an awkward moment for the cyber market. Moody's flagged cyber as one of the most pressing corporate exposures on its Insurance Emerging Risk Radar this week, warning AI is compressing attack timelines. Lockton's data found average premiums fell around 11% in 2025 even as incident frequency climbed. The Anthropic report provides primary-source evidence that attacker costs are falling while the threat environment is not improving - a divergence that now rests on documented case studies rather than projections alone. Underwriters advising on cyber placements will need to account for the combination. For analysts tracking these shifts, AI for Cybersecurity Analysts covers threat detection and security operations in this changing environment.
Life sciences and the dual-use problem
Anthropic documented five cases of users attempting biological research that could support weapons development. Cases included a grant application for gain-of-function research on chikungunya virus transmissibility and work on avian influenza mammalian adaptation. The company blocked all five and withheld the names of institutions involved. It acknowledged it could not always determine whether the research was legitimate or malicious - the same queries that could support weapons can also support vaccines and treatments.
That dual-use ambiguity is not new to life sciences underwriters already adapting to AI-driven diagnostics and novel drug development. What has changed is practical reach. Frontier models can now assist with advanced biological research at scale. Questions about what a life sciences liability policy covers when AI is the research tool are ones the sector will need to address.
Weapons development by non-state actors
Anthropic documented six cases of Claude being used for software linked to firearms, missiles, armed drones and bombs. Cases were tied to users in China, Russia, and Yemen. The report did not identify the Yemeni group by name, but the context points to an Iran-backed non-state actor. Political violence underwriters have had limited primary-source evidence on AI-assisted weapons development by non-state groups. The Anthropic report provides some. The practical question is whether AI shortens the weapons development cycle for non-state actors, and whether current pricing assumptions reflect that possibility.
Why this matters for insurance professionals
The Anthropic cases make it harder to treat AI-driven risk as a future concern. Cyber underwriters face documented evidence that attacker costs are dropping while premium rates have been softening - a mismatch that will surface in loss ratios if the trend holds. Life sciences carriers need to clarify where AI-assisted research falls within policy language, particularly around dual-use exclusions. Political violence underwriters now have primary-source material showing non-state actors using frontier models for weapons development, which should inform both pricing and accumulation modelling. None of these are hypotheticals anymore. For a broader view of how AI intersects with underwriting and risk assessment, AI for Insurance offers training resources across these applications.
Your membership also unlocks: