Artificial intelligence company Anthropic disclosed this week that its Claude AI system was exploited by foreign actors—including suspected terrorist groups and U.S. adversaries—to design and test military weapons, conduct cyberattacks, and attempt dangerous biological research, according to a newly released threat report.
The report highlights growing fears that advanced AI tools are being misused for national security threats, as developers race to keep pace with increasingly sophisticated attempts to circumvent safeguards.
Anthropic’s September 2026 report, Detecting and countering misuse of AI, outlines several cases where its Claude system was used for malicious purposes, including weapons development, fraud, surveillance, and influence operations. The company said it has disrupted these activities primarily by banning the actors involved from its platform.
Missile and Drone Development
One of the most serious cases involved a cell of threat actors in northern Yemen, a region controlled by the Houthis, who used Claude to develop three new missile types. According to Anthropic, the group designed a guided rocket with homing capabilities, a multi-stage ballistic missile with a 2,000km range, and a hypersonic glide vehicle variant. The actors relied on Claude Code to create guidance software, replacing human engineers. While Anthropic found no evidence that operational devices were fielded, it reported that a guided rocket was test-fired, though the test failed and the actors returned to Claude for troubleshooting.
In Russia, Anthropic identified likely freelance actors attempting to use Claude to build software for a first-person-view kamikaze drone swarm. The software was designed for autonomous lethal engagement, allowing drones to detect targets and issue detonation commands without human intervention. The actors used combat footage from Ukraine to train the system and focused on strike points in Donetsk Oblast. Anthropic said these individuals were not directly associated with the Russian government but had ties to a regional university and claimed funding from Russian defense agencies. Accounts linked to these activities were banned.
Chinese Electronic Warfare and Surveillance
Anthropic also reported that a China-based actor used Claude to design and iterate on electronic warfare modules. These modules were intended to analyze and jam opponents’ radar and communications, and to suppress air defenses. The software reportedly assessed vulnerabilities in U.S. missile defense systems, including Patriot and THAAD, and analyzed military targets in Taiwan. Anthropic determined the actor was likely a defense researcher connected to Chinese research institutions and the People’s Liberation Army Academy of Military Sciences. The company banned the associated account.
Biological Research and Gain-of-Function Attempts
The report details five cases where researchers used Claude to pursue biological weapons research, including viral pathogens and toxins. In one instance, a scientist affiliated with a military research institute sought Claude’s help to draft a grant application for gain-of-function research on the chikungunya virus. Another case involved a researcher outside the U.S. using Claude to study bird flu adaptation in mammals. Anthropic said these actors circumvented regional access controls and attempted to hide the true purpose of their research. While the company could not confirm intent to cause harm, it blocked the activities due to the high risks involved.
"The people building AI earnestly believe that it could kill us all by the end of the decade. This is not a marketing stunt."
— Jacob Coxon, former Anthropic researcher
Internal Debate and Company Response
The release of the report coincided with the resignation of Anthropic researcher Jacob Coxon, who warned that the company’s focus on developing self-improving AI could lead to uncontrollable risks. Coxon, a British citizen, publicly stated his concerns about the potential for AI to pose existential threats. Anthropic’s top scientist, Evan Hubinger, agreed with Coxon’s assessment, writing that he believes there is a greater than 10% chance AI could kill all humans within the next decade. Hubinger added that Anthropic does not yet have a clear plan to solve alignment for superintelligent AI.
Anthropic’s threat intelligence team emphasized that the cases described in the report represent the most notable and novel threats identified to date. The company stated, “We’re publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer.”
Anthropic did not provide evidence that any of the malicious actors succeeded in deploying operational weapons or causing harm, but said it remains vigilant and continues to strengthen its safeguards. The company’s report can be read in full at the link provided in its public release.


