
Anthropic blocks AI misuse tied to bioweapons, cyberattacks and spyware
Anthropic says it blocked malicious uses of its AI models, including research that could support biological weapons, and has tightened safeguards.
Anthropic has disclosed that it blocked attempts by malicious actors to misuse its artificial intelligence models for activities including cyberattacks, surveillance and research that could have contributed to biological weapons.
In its third report on AI misuse since March 2025, the company said the cases it documented represent the most notable and novel threat activity it has identified so far. The report includes excerpts of malicious code and prompts, and calls on governments and rival developers to detect and prevent similar abuse.
Anthropic said it published the findings out of a responsibility to disclose malicious use of its services, warning that as models grow more capable, their risks will rise unless developers and defenders act to make them safer.
Biological research flagged
Among the blocked cases were attempts by unnamed actors to use the company's models for research that could have led to biological weapons. In one instance, Anthropic said its systems stopped a request for its Claude model to help draft a scientific grant application.
The proposal concerned gain-of-function research on the chikungunya virus — work that genetically alters an organism to create a new or enhanced biological property — aimed at the virus's transmissibility and immune evasion. Chikungunya is a mosquito-borne virus that causes severe pain and fever.
Anthropic said such research could certainly be used to develop better vaccines and treatments, but could also be used to make the pathogen more dangerous.
The company said none of the cases in the report involved its newer, more powerful Claude Fable or Mythos-class models, except for one illicit distillation case it described as an industrial-scale, covert campaign to extract a model's capabilities and replicate them in another model without authorization.
Anthropic said its older 2025 models, including Claude Opus 4 and Claude Sonnet 4.5, were well below the threshold at which they could meaningfully assist a sophisticated user in dangerous biological research, and that safeguards on them were less stringent. For today's models, which can assist with complex scientific tasks, the company said it cannot make the same assurance, and has applied stronger safeguards restricting access to a wide range of dual-use biological research queries.
Influence operations and spyware
Between December 2025 and August 2026, Anthropic said its researchers found misuse by actors ranging from spyware vendors and politically motivated individuals to state-sponsored groups spreading propaganda.
The company also identified groups that created hundreds of social media accounts appearing to belong to ordinary people and then posted material amplifying the same political view over the course of a week. It outlined nine such cases originating in Russia, Iran, Turkey and across the Persian Gulf, South Asia, Africa and Europe.
Anthropic noted that while social media companies can detect influence operations once posts are circulating, its own systems may observe such activity while an operation is still being built.
The report was published a day after one of the company's researchers, Jacob Coxon, announced he was resigning over concerns that Anthropic and its competitors are not acting responsibly in AI development. He warned that the company and its chief rival OpenAI are racing toward self-improving superintelligence, and that some colleagues believe AI could threaten human life by the end of the decade.
Anthropic said it blocked each of the malicious activities it identified, used the experience to strengthen safeguards, and shared information with government authorities and industry partners. The company is planning an initial public offering this fall.