Anthropic blocked multiple attempts by malicious actors to use its AI models for cyberattacks, state-backed propaganda, and biological weapons research, the company disclosed Thursday. The findings, published in its third misuse report since March 2025, arrive as governments worldwide grapple with how to regulate increasingly capable AI systems.
The company said it has applied stronger safeguards to its latest models, restricting access to dual-use biological research queries that could assist in making pathogens more dangerous. "As models become increasingly capable, their risks will increase, unless AI developers and society's defenders act to make them safer," Anthropic said.
Biological weapons research blocked
Between December 2025 and August 2026, Anthropic researchers uncovered misuse ranging from spyware vendors to state-sponsored groups spreading propaganda. One case involved an unnamed actor attempting to use Claude to help write a grant application for gain-of-function research on the chikungunya virus - work aimed at enhancing the virus's transmissibility and immune evasion. While such research could lead to better vaccines, Anthropic said, "it could also be used to make the pathogen more dangerous."
The company acknowledged that older models like Claude Opus 4 and Claude Sonnet 4.5, released in 2025, had less stringent safeguards because they were "well below the threshold where they could meaningfully assist a sophisticated user in carrying out dangerous biological research." Those safeguards focused mainly on preventing novices from accessing information about known bioweapons. For today's more capable models, Anthropic said, "the evidence is no longer certain, and we cannot make that same assurance."
The report noted that none of the identified misuse cases involved the company's newer, more powerful Claude Fable or Mythos-class models, with one exception: an "industrial-scale, covert campaign to extract a model's capabilities and replicate them in another model without authorization."
Influence operations detected during construction
Anthropic also identified nine influence operations originating from Russia, Iran, Turkey, and regions across the Persian Gulf, South Asia, Africa, and Europe. These groups created hundreds of social media accounts designed to look like ordinary people, then posted material amplifying the same political views over the course of a week. The company said it can detect such operations while they are still being built on Claude, before posts spread across social media platforms.
"We're publishing this work because we believe we have a responsibility to disclose malicious misuse of our services," the company said. The report includes snippets of malicious code and AI prompts that Anthropic found, and it urged governments and AI competitors to identify and prevent similar abuse.
Researcher resignation raises stakes
The report landed two days after Anthropic researcher Jacob Coxon announced his resignation, warning that the company and rival OpenAI "are racing straight to self-improving superintelligence and gambling with our lives." Coxon said some colleagues now believe AI could threaten human life by the end of the decade.
John Thickstun, an assistant professor of computer science at Cornell University, said companies like Anthropic and OpenAI are in an uncomfortable position when expected to determine what constitutes safe versus unsafe behavior and make "value judgments at societal scale without any kind of democratic or deliberative oversight."
Anthropic said it has blocked each malicious activity it identified, used the experience to strengthen safeguards, and shared information with government authorities and industry partners. The company is planning an initial public offering this fall.
Why this matters for government, science, and research professionals
This report signals a shift in how AI companies communicate threat intelligence to regulators. Rather than waiting for legislation, Anthropic is publicly documenting specific misuse patterns - including prompt snippets and code - to help government agencies and other developers recognize emerging threats. For policy professionals, the report provides concrete evidence of what dual-use AI risks look like in practice, not just in theory. Those working at the intersection of AI and policy may find structured guidance in programs like AI for Policy Makers. For researchers in the life sciences, the tightening of safeguards on queries related to gain-of-function research means grant-writing workflows that involve AI assistants may face new friction, particularly when proposals touch on pathogen transmissibility or immune evasion. Professionals in these fields should track how AI for Science & Research evolves alongside these restrictions.
Your membership also unlocks: