Anthropic published on September 10 the most detailed account it has yet offered of how its models are being abused, and how it says it is stopping them. The September threat-intelligence report covers activity detected and blocked between December 2025 and August 2026, sorted into seven categories that read like a taxonomy of everything a frontier model can be turned toward.
The seven buckets are cyberattacks, influence operations, surveillance, fraud, biological misuse, conventional-weapons development, and model distillation. The breadth is itself the point: Anthropic is arguing that the misuse problem is not a single story but a set of them, each with its own methods and its own network of operators.
The biological section is the one the company has not disclosed before. Anthropic said researchers affiliated with a foreign government used Claude to advance virus research, the kind of dual-use work that sits closest to the line the industry has drawn around what models should assist with.
The weapons section is less subtle. One group, according to the report, ran multiple Claude instances as a stand-in engineering team to develop a drone swarm. The detail is striking because it suggests the models are not being used as a search engine or a drafting tool but as the missing labor inside a larger project.
On the cyber side, Anthropic flagged an operation against Ukrainian government, military, and diplomatic targets whose tactics matched those of Midnight Blizzard, the Russian group Microsoft has attributed to Russia’s intelligence service. Phishing, hotel Wi-Fi hijacking, and WhatsApp takeover were all in the toolkit, and the report said AI was woven through each step.
The role the models played is a pattern the company keeps returning to. Monitors found the attackers were acting as supervisors more than operators, directing the AI through each phase rather than doing the work themselves. That distinction, between a tool and a manager, is what makes the misuse difficult to attribute and to stop.
Iranian activity rounded out the state-linked cases. Anthropic said Iranian-linked users employed Claude to target naval bases, to organize information on Americans at scale, and to run social-media accounts, a mix of espionage and influence work conducted through a commercial product.
Anthropic said every operation in the report has been blocked. The claim is the standard one for this kind of disclosure, but it carries weight here because the report names tactics, account networks, and indicators rather than describing the problem in general terms.
Publishing the list is itself a decision. By putting its adversaries’ methods and infrastructure into a public document, Anthropic is turning who uses its models and how into part of the product, a layer of accountability that a company selling to governments and enterprises can point to.
The disclosure lands at a sensitive moment for the company. Anthropic is preparing an initial public offering that could value it near $1 trillion, and its reputation for safety is central to that story. A detailed misuse report is both evidence for the pitch and a document competitors and regulators will now hold it to.
The report also feeds a running industry debate about speed. Days before the publication, current and former employees of Anthropic and OpenAI had gone public with calls to slow the development of advanced systems, and a document showing what the current generation can already be used for gives their argument a concrete reference.
Analysts said the timing is not coincidental. A company asking investors to price in a future of superintelligent systems is simultaneously showing the market what a much weaker system is already doing in the wrong hands, and the gap between the two is the risk the industry keeps asking the public to accept.
What the report does not do is estimate the harm that slipped through. It documents what was caught, not what was missed, and the seven categories are a floor rather than a ceiling on the misuse the models are capable of.
Model distillation, the seventh category, is a different kind of problem. It covers competitors extracting a smaller model’s capabilities from Claude, a form of misuse that copies the product rather than abusing it. Anthropic included it to signal that unauthorized use of its models, not only harmful use, is now part of what it tracks.
The report continues a practice Anthropic has built over two years. The company publishes regular accounts of the misuse and disruption it detects, and each installment has grown more specific, moving from broad warnings to named tactics and infrastructure. The September edition is the fullest version of that trajectory.
State-linked misuse is the thread connecting the categories. Across the biological, weapons, cyber, and influence cases, the operators with the most resources were tied to governments, and Anthropic’s account suggests the model frontier is now a standing target for intelligence work rather than an occasional one.
The honest read is that the report is a sales document and a warning at once. Anthropic wants credit for the vigilance and wants the public to trust its judgment, and the same pages that build that case make clear why the vigilance is necessary in the first place.


