Anthropic reveals AI used to test missiles, conduct dangerous biological research in threat report
Anthropic disrupts malicious plots using its Claude program, like attempts to test weapons systems, develop new drone tactics, and conduct dangerous biological research, as debate over AI safety intensifies.
In a publicly released threat report this week, Artificial Intelligence company Anthropic is identified cases of foreign actors – including likely terrorist groups and U.S. adversaries – using its signature Claude system to design and test military weapons, conduct cyberattacks, and attempt dangerous biological research.
The September 2026 “Detecting and countering misuse of AI” report released Thursday pulls back the curtain with several case studies on how the AI company’s Claude system was used maliciously – including for weapons research, scams and fraud, government and private surveillance operations, and influence operations.
The company says it has disrupted the plots, principally by banning the suspected actors from using its products.
Anthropic released the report in parallel to a high-profile resignation of one of its researchers, Jacob Coxon, who has raised concerns about what he thinks is the company prioritizing “endgame” development of self-improving AI.
The 27-year-old British citizen is warning this trajectory could lead to an “out of control” AI that could present survival risks for humanity.
“The people building AI earnestly believe that it could kill us all by the end of the decade. This is not a marketing stunt,” Coxon wrote in a social media post.
Instead of disputing the claims, Anthropic’s top scientist, Evan Hubinger, agreed wholeheartedly with Coxon.
“Jacob is correct here – we really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade,” Hubinger wrote in a post to X.
“I believe Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to.”
In the report, Anthropic’s Threat Intelligence team shared details about how the company detected and disrupted “operations in which threat actors tried to use Claude for malicious activity.”
“The cases we share here aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date," Anthropic said in the report. "We’re publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer.”
The most striking cases in the study involve foreign state or state-affiliated actors and cover how those actors used Claude’s advanced capabilities to test weapons systems in the Middle East, to develop electronic warfare software in China and test code in Russia for a kamikaze drone swarm.
You can read Anthropic’s report at this link and attached below:
Missiles in Yemen
In northern Yemen, a region controlled by the terrorist group Ansar Allah, or more commonly known as the Houthis, Anthropic identified “a cell of threat actors” using Claude to develop three new missiles with advanced capabilities.
The Houthis have used missiles and armed drones to attack commercial shipping in the Red Sea and oil infrastructure in the Kingdom of Saudi Arabia to further the strategic aims of its backers in Tehran.
According to Anthropic, the “cell,” which the company does not explicitly identify with the Houthis, used the AI platform to develop a “guided rocket” with homing guidance capabilities, “a multi-stage ballistic missile” intended to achieve a range of 2,000km, and “a multi-variant missile” that included a “hypersonic glide vehicle variant.”
The actors used Claude Code instead of human software engineers to develop the guidance software that would allow missiles to be steered and stabilized during flight.
“These actors carried out a sustained effort to develop guided weapons, including using Claude to design guidance software," Anthropic said. "We do not have evidence the actors succeeded in fielding an operational device; but they did test-fire a guided rocket. This field test appears to have failed: within hours, the actors returned to Claude to work out why it failed."
Chinese electronic warfare
Anthropic identified “a China-based actor” having used Claude tools “to design, build, and iterate” on Chinese “modules for electronic warfare, using the electromagnetic spectrum to detect, jam or deceive an opponent’s radar and communications, and for suppressing an opponent’s air defenses.”
The software was designed to analyze opponents’ radar systems, surface-to-air missile sites and to assess their vulnerability. The software reportedly conducted assessments on the United States’ premier systems, the Patriot and THAAD missile defense systems. The actor also analyzed targets in Taiwan, including a command bunker, an early warning site, air bases and missile defenses, Anthropic said.
Anthropic’s threat team determined the actor is likely “a China-based defense and military-industrial researcher” linked to Chinese research institutions and the People’s Liberation Army Academy of Military Sciences. Anthropic said it banned the account from its ecosystem.
Drones in Russia
In Russia, Anthropic’s team identified “likely freelance Russia-based threat actors” who tried to use Claude's coding capabilities to build a “first-person-view (FPV) kamikaze drone swarm.”
The actors used Claude to build the core software system, which included the capability for “autonomous lethal engagement” that allowed onboard systems to detect targets and “issue detonation commands without a human in the loop.”
The actors appeared to have designed the software for use in the Ukraine war.
“The actors trained a computer vision classifier on scraped Ukrainian combat footage, splitting the target classes into ‘enemy’ and ‘friendly,’ and allow-listing Russian systems. They also repeatedly used a fixed coordinate in Donetsk Oblast as the demonstration strike point, with front-line cities and corridors in Ukraine as the mission geography,” Anthropic wrote.
According to Anthropic, the actors were freelance – meaning not associated with the Russian government – but determined they likely had ties to a Russian regional university with “a federal research center associated with the Russian Academy of Sciences.”
The researchers also “claimed to have received funding from Russia’s Advanced Research Foundation, National Technology Initiative and the Ministry of Defence.”
Anthropic said that it banned accounts associated with the weapons development.
Biological research, including attempted gain-of-function
Anthropic's threat team flagged five cases in which researchers used Claude to research biological weapons, ranging from viral pathogens to venoms and toxins.
In one case from May, a scientist affiliated with a military research institute asked Claude to help draft a grant application for gain-of-function research on the chikungunya virus, a pathogen carried by mosquitos. Such research, in which an organism or pathogen is genetically altered to give it new or enhanced traits, has been at the center of intense debate on whether the COVID-19 pandemic started through an accidental laboratory leak or jumped from animal to human.
In another, a researcher outside the U.S. used Claude to study how bird flu adapts to mammals and what makes the resulting illness more severe.
“In the examples below, actors circumvented controls we impose to prevent users from unsupported regions accessing our models, and engaged in other efforts to obfuscate the purpose of their research to evade our safeguards,” Anthropic said, calling biological misuse one of the “most serious risks” of AI models. Anthropic said it could not establish whether any of the researchers intended to cause harm, but it blocked the activity, considering the stakes involved.