Anthropic published a 154-page report Thursday describing attempts to use its models to design missiles and bombs, create deadly pathogens and track dissidents. The people behind them, the company says, included criminals, state-backed groups, spyware vendors, propagandists and working scientists. Five of the cases involve researchers using Claude for biological work. Anthropic blocked the accounts but named neither the institutions nor the countries, because it could not be sure what the researchers intended.
The company is explicit that this is not a portrait of typical misuse. It selected the most notable and unusual threats it has detected so far, and justifies publishing them as a responsibility to disclose malicious use of its own services.
The five biological cases are the ones Anthropic treats as most serious. In them, it says, researchers bypassed safeguards built to block users in regions the service does not support, and worked to conceal the real purpose of what they were doing. The company calls misuse of biological capability one of the gravest risks frontier models carry, and says that without appropriate limits such capability can lead to catastrophic outcomes.
The case it describes in most detail concerns chikungunya. A scientist used Claude to prepare an application for a state-funded research grant on the virus, which is carried by mosquitoes and, like dengue and malaria, can cause months of severe pain, fever and other debilitating symptoms. Work of this kind can produce vaccines; the same knowledge can be turned toward a biological weapon. Anthropic told The New York Times that this case worried it in particular, because the documents indicated the research was to be carried out at a military scientific institute.
Read closely, the act described is grant-writing assistance. What makes it a bioweapons story is the letterhead of the institution that would have received the money, not anything the model produced. That is not a reason to dismiss it — dual-use research is exactly where intent lives outside the artefact — but it is worth being clear about which part of this is evidence and which part is inference.
The rest of the report is a catalogue of dozens of further examples, and it is in several ways more concrete than the biological section. It covers cyber operations, including Russian espionage and fast smash-and-grab intrusions; surveillance work, including a Chinese program aimed at Uyghurs in Syria and a second aimed at domestic dissidents; propaganda campaigns run in Russia, Malaysia, Iran and Bangladesh; and conventional weapons software built with Claude in Yemen, China and Russia, covering firearms, missiles, armed drones, bombs and other munitions.
Countries get named there. They do not get named in the five cases Anthropic says are the most dangerous.
The report landed two days after the resignation of Anthropic employee Jacob Coxon became a subject of wide media discussion. Coxon said he left because he judged the company's conduct in building the technology insufficiently responsible, and that Anthropic and its rival OpenAI are "racing directly" toward a self-improving superintelligence that could cause human extinction by 2030. Current Anthropic staff publicly backed him.
The timing reads like an answer. A dated, specific, 154-page account of harm happening now is the most useful possible reply to a former colleague saying your company is careless about harm to come: it asserts that the danger is real, that it is already here, and that Anthropic is the one watching it. Both propositions can hold at once. The report simultaneously argues that the models are dangerous and demonstrates that the company can see the danger, which are the two claims a safety-branded lab most needs in the same document.
Many AI specialists take the view that over the next three years the threats in this report are the ones worth worrying about, not the apocalyptic scenario. Heidi Khlaaf, chief AI scientist at the AI Now Institute, called accelerating AI development and fear of catastrophe two sides of the same coin, since both assume a general-purpose superintelligence is coming. In her view the labs are building technology that can be used to break into cybersecurity systems and develop military weapons, and that can lead to deadlier consequences than the debate acknowledges.
Anthropic notes that potential misuse of AI models is usually invisible to the public, investigated inside companies and by academic researchers, governments and international organisations. Its recommendation is that the industry take on risk mitigation together with governments, and build safeguards jointly. It warns that threats will scale with capability unless developers and the bodies responsible for public safety work on making models more reliable.
That ask sits awkwardly against the redactions. Anthropic's five hardest cases arrive without a country, an institution or a date — which is to say, without the details any government or any other lab would need to act on them. The company is at once the only party that saw the evidence and the only party that decided how much of it could be said out loud, and it is asking everyone else to help with a problem it has described only in outline.