Anthropic: Claude misuse tied to China, Russia and weapons R&D despite access bans

Anthropic alleges China-, Russia- and Iran-linked actors bypassed Claude access controls to support cyber, surveillance and weapons design—highlighting immediate implications for European security.

Share
Illustration of an AI interface overlaid with cyber intrusion and drone silhouette motifs.
Illustration of an AI interface overlaid with cyber intrusion and drone silhouette motifs.

Key facts

  • Anthropic says restricted-country actors accessed Claude via VPNs and fraudulent or stolen accounts, often via intermediaries selling circumvention services.
  • Report claims disruption of Yemen-based weapons development use cases and a Russia-based attempt to build autonomous kamikaze drone capability with Claude.
  • Anthropic cites five 2026 cases of pathogen-related research activity with potential bioweapons relevance, but withholds country and institutional attribution.

3 minute read

Anthropic’s September 2026 threat intelligence report, as summarised by Politico, argues that misuse of advanced but commercially available AI assistants has moved from conjecture to operational reality. The company says it observed criminal hacking groups, Chinese security bureaus, Russia-linked espionage actors and Yemen-based arms manufacturers gaining access to Claude via VPNs and fraudulent or stolen accounts, frequently assisted by intermediaries that monetise circumvention of geofencing and model safety filters. Anthropic claims these users leveraged Claude to automate cyberattacks, generate propaganda at scale, and support large-scale digital surveillance, while also attempting to design advanced military hardware that would previously have required greater specialist capacity.

Several of the most consequential allegations concern weapons R&D and dual-use bioscience. Anthropic says it disrupted a Northern Yemen-based cell using Claude across three weapons programmes, including a guided rocket, a multi-stage ballistic missile and a hypersonic glide missile, and separately identified a Russia-based “freelance” actor seeking to build drones capable of autonomous kamikaze attacks. In bioscience, the firm reports five 2026 cases in which scientists in unspecified foreign countries used Claude to research dangerous pathogens, including drafting a grant application involving gain-of-function research at a military research institute and extended research into highly pathogenic avian influenza adaptations. Anthropic says it is withholding attribution because it could not conclusively distinguish legitimate research from weapons intent, but states the actors bypassed country restrictions and attempted to obfuscate purpose to evade safeguards.

For European defence and security stakeholders, the report’s central relevance is the demonstrated fragility of platform-level access controls when faced with a mature ecosystem of fraud, resale and “AI access brokers”. If accurate, it suggests that AI assistance is already lowering the barrier to entry for offensive cyber operations, scaling influence campaigns timed to elections (Anthropic cites activity linked to elections including Moldova), and accelerating the design iteration cycle for drones and missile subsystems in contested regions adjacent to European interests. The implication is that European resilience planning will need to treat frontier-model misuse as a present-day enabler across cyber defence, counter-UAS, export controls and counter-proliferation, rather than a medium-term risk contingent on the release of the most capable models.

Source: POLITICO