Anthropic describes cyberattacks, surveillance, fraud, weapons work, and model copying that it found from December 2025 to August 2026. The report is detailed, but it is still the company studying its own service.
New to this? Read it in simple words
- Anthropic says it stopped harmful uses of Claude found between December 2025 and August 2026. They include cyberattacks, fraud, surveillance, weapons research and model copying.
- Anthropic says some people used AI to help find targets, build tools and steal data. Humans still chose the targets, but AI let fewer people do more steps.
- The cases show how AI can make harmful work faster. They also show why outside experts should check company reports.
- The report does not show how many cases Anthropic misses. AP says Anthropic cannot promise its more capable models will never help skilled users do harm.
- Cyberattack
- An attempt to break into or damage computers or networks.
- Surveillance
- Watching or tracking people, often in secret.
The report covers seven kinds of harm
Anthropic studied activity it found between December 2025 and August 2026. The company says the users included suspected government-backed groups, criminals, spyware sellers, and political actors. It says it stopped the activity and shared some information with authorities or industry partners.
The cyber cases are the clearest warning. Anthropic says some people used AI to help find targets, build tools, steal data, and change malware when security software found it. Humans still chose the targets and checked the stolen data. The AI helped them work across more steps with fewer people.
The report also describes blocked requests linked to biological research that could have made a virus more harmful. Anthropic says newer models now have stronger limits for sensitive biological questions. AP reported that the company cannot promise that today’s more capable models would never help a skilled user do harm.
Anthropic reports cases across seven harm areas. The company says it stopped the activity and strengthened safeguards.
A case report is not a full measure of the problem
Anthropic says these are unusual and important cases, not normal use of Claude. That is a useful limit. The report does not tell us what share of all harmful activity the company finds, how many cases it misses, or how its results compare with other AI services.
The evidence also comes from the company that built and runs the models. Anthropic gives many technical details, which helps defenders learn. However, readers cannot see all account records, private messages, or detection rules. Some information must stay private for safety, but that makes independent checking harder.
A strong response needs several layers. Providers should block dangerous requests, watch for unusual patterns, and keep records that trained reviewers can study. They should also give users a way to appeal when a safety system blocks harmless work.
The best test is what changes next
Security teams should not treat polished attacks as proof that a large state group is responsible. Anthropic says AI has reduced the gap between highly trained teams and smaller actors. Defenders need to look at the full evidence, not only the quality of the code.
Governments and AI companies can share warning signs without publishing instructions that help attackers. Independent researchers should be able to test the safeguards under strict rules. Public reports should explain both successful blocks and serious failures.
Anthropic’s report is valuable because it names real patterns and admits uncertainty. It is not a complete map of AI misuse. The important question is whether the new controls stop more harm, create fewer unfair blocks, and produce evidence that outside experts can trust.
Sources
Every fact in this story comes from the sources below. Open them to check our work.
- 1
- 2Research · September 10, 2026Anthropic says it blocked misuse of its AI that could have supported biological weapons Associated Press
We used Anthropic’s report for the case types, time period, model limits, and response steps. We used AP to check the main claims and add outside context. We describe the actors as Anthropic’s findings because no court or independent audit has judged every case.