Anthropic disclosed a report documenting the use of its models, including Claude Haiku, Sonnet, Opus, and Claude Code, in abusive activities ranging from developing software related to conventional weapons to espionage, fraud, and political influence operations. The report covers the period between December 2025 and August 2026 and indicates the involvement of entities suspected of being linked to states, criminals seeking financial gain, and government propaganda organizations.
Using Claude in Weapons Programs
Anthropic said its threat intelligence team investigated several entities that used Claude to develop software for weapons design or to support intelligence gathering and supply chains associated with weapons programs. The company said three of these entities were in China, two in Russia, and one in Yemen.
In a case linked to a group operating in northern Yemen, the company detected the use of Claude Code in three weapons-development programs, including guided missiles and other missiles. The uses included developing guidance, navigation, and balancing software, as well as conducting simulations and tests, but the report said it found no evidence that the group had succeeded in developing an operational weapon. Anthropic also said it disabled the relevant accounts and shared the information it had gathered with public- and private-sector organizations.
In another case, a China-based party used Claude to develop parts of the launch-control software for an anti-torpedo system, prepare testing plans, and compare the system with U.S. anti-torpedo and anti-submarine defense software. The company assessed that the activity was linked to a manufacturer in China’s defense sector.
From Espionage to Surveillance and Influence
The report included examples of Russian espionage operations that primarily targeted military intelligence in the governments of Ukraine and European countries, as well as reconnaissance attempts against government networks in the Middle East, Europe, and Southeast Asia attributed to entities believed to be based in China. Anthropic also detected the use of Claude in extortion attacks and financially motivated cybercrime.
In June 2026, the company banned an account that used Claude to create a platform monitoring, analyzing, and classifying user activity on social media in Iran and the Gulf region. The investigation concluded that the account was operated by, or on behalf of, an entity called S2T Unlocking Cyberspace, while open-source research indicated that it was linked to an Israeli-Singaporean intelligence provider. The report also detected a Chinese tool for monitoring public opinion and preparing government briefings that classified dissidents, activists, ethnic minorities, the Chinese diaspora, and foreign media as threats to political stability.
Model Imitation and Synthetic Content Networks
Anthropic said a Chinese application studio created, with Claude’s assistance, a network of more than 20 dating applications, with more than 4,700 artificial intelligence personas that spoke with at least 25,000 people over two weeks. The company also recorded what it described as its largest illicit distillation attack to date, in which entities linked to Alibaba used more than 3,500 fake accounts to conduct approximately 3 million operations per day in an effort to copy the capabilities of its models without authorization.
The company also said that Moonshot AI and DeepSeek, according to the investigation, routed user requests to Claude without informing them, while conversations from users of Xiaomi MiMo models were transferred to Claude as part of activity the report described as illicit distillation.
Why Does This Matter?
The cases show that the risks are not limited to producing harmful text, but also include integrating models into software, testing, intelligence operations, and propaganda infrastructures. At the same time, the report remains a presentation of Anthropic’s findings and investigations, rather than an independent assessment of each case; some of the events also concern uses that have not been proven to have produced a practical weapon. The material therefore leaves open questions about mechanisms for verifying companies’ claims, the limits of their ability to detect undisclosed uses, and how information sharing with public and private entities should be coordinated.