Security & Risk5 minNewsroom

Anthropic reports 9 months of Claude misuse: cyber, bio weapons

Sala de operações de segurança com mapa global de ameaças cibernéticas iluminado em vermelho, analista monitorando cadeias de ataque

Anthropic's intelligence report covers Dec 2025 to Aug 2026, mapping seven abuse categories including state operations and weapons research.

Anthropic released a threat intelligence report on Thursday detailing nine consecutive months of documented abuse of its models. The document, titled "Countering Misuse of AI: September 2026," spans the period from December 2025 to August 2026 and lists seven distinct categories of harm, including research on biological weapons and conventional armaments—two vectors receiving systematic treatment for the first time in a company publication.


Seven categories and the cases behind them


The report organizes incidents into: cyber operations, influence operations, surveillance, fraud and scams, biological weapons research, conventional weapons research, and model distillation. Distillation, often treated as a contractual issue, is framed here as a security risk: malicious actors use outputs from leading market models to train alternatives, reducing their own development costs and potentially circumventing the original provider’s acceptable use policies.


Among the cases described, Anthropic identified a group linked to Russia that used Claude to craft phishing campaigns targeting Ukrainian government officials and to create custom malware. The operation combined large-scale text generation with technical personalization, according to the document. The company frames these cases as "AI-enabled cyber operations": attacks where the model accelerates steps in the offensive cycle without replacing human intelligence in target definition.


The surveillance category documents the use of Claude for building profiles of individuals and analyzing communications. In fraud cases, the model was employed to generate convincing content in multiple languages aimed at financial scams. The category of biological weapons research indicates that actors sought technical assistance from the model in domains previously restricted to credentialed researchers.


What sets this report apart from those published by OpenAI and Google


Since early 2026, Anthropic has published two risk reports, in February and August, and now adds a threat intelligence report with an explicit nine-month temporal scope, formalized categories, and geopolitical attributions. OpenAI and Google publish transparency reports and acceptable use policies, but neither adopts the structured format of threat intelligence that is standard in companies like CrowdStrike, Mandiant, and Recorded Future.


For IT executives evaluating AI providers, the distinction is operational: threat intelligence reports allow mapping of risk vectors within specific corporate architectures; transparency reports describe intentions and policies. Anthropic is essentially adopting the disclosure model of cybersecurity companies and applying it to AI misuse.


Distillation, Alibaba, and the signal for integrators


The distillation category gained additional attention because Anthropic had previously described activity linked to Alibaba in model training campaigns using outputs from Claude. The September report frames this pattern within a formal category of abuse, with direct implications for corporate contracts prohibiting the use of model outputs to train competitors.


For companies integrating AI APIs into proprietary solutions, the presence of distillation as a threat category necessitates a review of logging controls and access policies. It is not enough to know who consumes the model; it is crucial to understand what they do with the outputs, especially when data is retransmitted to internal training systems.


U.S. and Europe: two distinct regulatory contexts


In the United States, where Anthropic operates and hosts most of its commercial instances, the report notes ongoing legislative debate. The company has already testified before congressional committees on security and misinformation; September 2026 adds biological and conventional armaments to the list of vectors Congress will need to address in future regulation.


In the European Union, the impact is more immediate. The AI Office, whose enforcement powers under the AI Act came into effect in August 2026, has the authority to request access to models, demand mitigations, and determine the removal of products from the European market. A report with geopolitical attributions and seven explicit harm categories provides the factual basis regulators need to open investigations with technical backing. For providers of Claude-based solutions to European customers, the document sets a due diligence precedent: Anthropic documents risks with granularity comparable to cybersecurity firms; integrators need to demonstrate that they manage these risks.


The question CISOs and legal directors must now answer is not whether the AI systems they use can be externally abused, but which of the seven categories documented by Anthropic are pertinent to the attack surface of their own organization.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk