Anthropic says it has disrupted attempts to use its Claude AI models for sensitive biological research, missile guidance, autonomous drone systems and other military applications, showing how frontier AI is beginning to move into areas with direct physical-security implications.
The cases were disclosed in the company’s September 2026 threat-intelligence report, covering misuse detected between December 2025 and August 2026. Anthropic says it banned accounts involved, strengthened safeguards and shared intelligence with authorities or industry partners where appropriate.
The disclosures go beyond familiar AI risks such as phishing or misinformation.
They involve users trying to apply AI to biological research and conventional weapons development — fields where a model’s ability to analyse, code and troubleshoot can potentially accelerate highly sensitive work.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Chikungunya research triggered Anthropic’s biological safety systems
One of the most serious cases surfaced in May 2026.
Anthropic says its safety systems blocked a request connected to a grant proposal involving gain-of-function research on the chikungunya virus. The proposed research focused on changing characteristics linked to transmissibility and immune evasion.
Gain-of-function research involves altering an organism so that it develops or strengthens a biological property.
Such research can have legitimate scientific purposes, including understanding how diseases spread or how viruses might evolve. But it is considered dual-use because similar knowledge could potentially be misused.
Anthropic says the grant sought to identify mutations, introduce them into infectious viral material and study changes in virulence.
The company linked the work to what it described as a state-sponsored military-civilian research programme operating through an AI reseller platform designed to circumvent regional access restrictions.
Anthropic banned associated accounts, worked with partners to dismantle relay infrastructure and shared its findings with other AI companies and government authorities.
However, the actors reportedly returned using new identities and other AI services.
That matters because it shows the problem is not simply whether one company refuses a dangerous request. Users can attempt to route the same work through more permissive models.
What does “biological misuse” actually mean here?
The phrase should not be interpreted as evidence that Claude created a biological weapon.
Anthropic’s own wording is more cautious.
The company says the five biological cases involved activity that could support biological-weapons development, but some research also had plausible legitimate scientific applications.
Another case involved a researcher spending weeks using Claude while planning experiments involving highly pathogenic avian influenza adapting to mammals.
Anthropic says its classifiers limited that researcher to weaker models, reducing the amount of assistance available.
The broader concern is capability.
As frontier AI becomes better at biology, it may help legitimate scientists analyse experiments and accelerate drug or vaccine research. The same improvement can potentially make it easier for users to navigate highly specialised technical problems.
Yemen-based group allegedly used Claude for guided weapons
The conventional-weapons cases were even more operational.
Anthropic says it identified a group in northern Yemen running three weapons-development programmes, including a guided rocket, a multi-stage ballistic missile with a stated range target above 2,000 kilometres, and another missile family containing a hypersonic-glide variant.
The actors used Claude Code for guidance, navigation and control software.
Anthropic says they ran several AI instances simultaneously, assigning one to write code, another to conduct research and another to review the output.
The group conducted a live test of a guided rocket, according to Anthropic.
That test appears to have failed. Within hours, the actors reportedly returned to Claude to analyse what had gone wrong. Anthropic says it has no evidence that the group successfully fielded an operational system.
This distinction is important.
The report demonstrates AI involvement in a real weapons-development workflow, but not proof that AI successfully produced a deployable missile.
Russia-linked actors built autonomous drone-swarm software
A Russia-based operation went further into autonomous drone systems.
Anthropic says suspected freelance actors used Claude Code to build software for a swarm of first-person-view kamikaze drones.
The work included shared swarm memory, coordination between drones, camera-based terminal guidance, control-link geolocation and logic governing attack and return-to-base behaviour.
The systems were largely at simulation or early development stage rather than proven battlefield deployment.
Anthropic’s own technical evaluation nonetheless found that frontier models are increasingly capable of carrying out tasks that previously required scarce military or intelligence expertise.
That is what makes the development significant.
AI is not simply explaining weapons terminology. In some cases, it is helping users write and test the software that controls physical systems.
China-linked cases covered torpedoes and electronic warfare
Anthropic also identified several China-based operations.
One user allegedly employed Claude to draft a technical specification and a proposal of more than 200 pages for an anti-torpedo fire-control system, while also comparing the proposed system with publicly available information on US Navy capabilities.
Another actor used Claude to develop a suite of roughly 16 software modules related to electronic warfare and suppression of enemy air defences.
Anthropic says the software analysed radar systems, missile sites, command posts and communications nodes, ranked potential targets and modelled how jamming assets could be assigned. One scenario was reportedly changed to include 12 targets in Taiwan.
The company assessed that actor as linked to China’s defence research ecosystem, although it did not identify a specific individual.
Across these cases, Anthropic says it banned relevant accounts and introduced new classifiers aimed at detecting weapons-development activity, including work involving high-yield explosives.
The larger concern is becoming clearer.
AI is not removing the need for laboratories, engineering expertise or access to physical hardware. But it can compress parts of the research, coding and review process that previously required larger teams of specialists.
That may lower the time, cost and expertise required to move from an idea to a functioning prototype.
What this means for you: These cases do not mean consumer AI systems are independently building biological weapons or missiles. The immediate issue is whether AI providers and governments can detect dangerous technical use early enough, particularly when users split sensitive work across multiple accounts, models and platforms.
The420 Insight: The most consequential AI safety problem may be less dramatic than a rogue superintelligence. Frontier models are already becoming powerful enough to act as technical force multipliers — helping small groups perform work that once required specialist teams in laboratories, intelligence units or weapons programmes.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics