Anthropic published its September 2026 threat intelligence report on September 10, documenting malicious use of its Claude models across seven areas of harm, based on activity the company disrupted between December 2025 and August 2026. The report describes a shift from conventional AI-assisted activity toward more sophisticated operations in which threat actors use AI to automate and scale tasks including cyber operations, surveillance, influence campaigns, fraud and sensitive biological research. Anthropic said the cases demonstrate that AI misuse is becoming increasingly operational rather than limited to experimentation or simple prompt-based abuse.
The report details several significant cases involving state-linked and criminal actors. Anthropic said a suspected Russia-linked operation used Claude to support cyber-espionage activity, while Chinese-linked actors allegedly used Claude through intermediary accounts in attempts to distill or replicate the capabilities of its models. Other cases involved surveillance of dissidents, influence operations and efforts to use AI in biological and weapons-related research. The company also highlighted the growing use of AI agents capable of carrying out multi-stage tasks with limited human intervention, including reconnaissance, information gathering and other activities that previously required significant manual effort.
For defenders, the report highlights a growing AI-enabled threat multiplier rather than a single new attack technique. Threat actors can use capable models to reduce the expertise, time and resources required to conduct complex operations, while autonomous agents could allow attacks to operate at greater scale and speed. Organisations should therefore treat AI access and AI-enabled workflows as part of the broader attack surface, with controls around sensitive data, credentials, external AI services and autonomous agents. Security teams should also monitor for unusual AI-assisted activity, strengthen identity controls around AI platforms, and ensure that employees and developers do not provide sensitive corporate information or privileged access to unapproved AI systems. Anthropic’s findings reinforce that the security impact of advanced AI is already being observed in real-world operations, rather than remaining purely theoretical.