Claude Misuse Exposes the New Risks of Powerful AI Models

Anthropic said on September 10, 2026, that it blocked attempts to misuse its artificial intelligence models for cyberattacks, surveillance, and biological research that could have led to weapons. The company described the findings in its third report on AI misuse since March 2025.
The activity took place between December 2025 and August 2026 and involved actors ranging from spyware vendors and politically motivated individuals to state-sponsored groups. The report includes snippets of malicious code and AI prompts, offering a look at how people tried to use Claude for harmful work.
“The cases we share here aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date,” Anthropic said.
Biological research raised the hardest questions
One case involved a request for Claude’s help in authoring a grant application connected to gain-of-function research on the chikungunya virus. Anthropic’s systems blocked the request because the work involved genetically altering the virus to create a new or enhanced biological property.
That type of research can support better vaccines and treatments, but it can also make a pathogen more dangerous. Anthropic said the application focused on the virus’s transmissibility and immune evasion properties.
“The work discussed in the application involved gain-of-function research (that is, research that genetically alters an organism to create a new or enhanced biological property) on the chikungunya virus,” the company said. “This gain of function research was aimed at the virus’ transmissibility and immune evasion properties.”
The company’s report makes clear why biological research creates a difficult safety problem for AI developers. The same scientific knowledge can serve medical research or support work that creates more dangerous pathogens. Anthropic said stronger safeguards now restrict access to dual-use biological research queries in recent models such as Claude Fable 5.
Older models, including Claude Opus 4 and Claude Sonnet 4.5 from 2025, were below the threshold where they could meaningfully assist in dangerous biological research. Because of that, their safeguards focused mostly on preventing access to material that could help novices recreate known bioweapons.
Anthropic said that assurance no longer applies to today’s models, which can assist with a range of complex scientific research tasks. “The evidence is no longer certain, and we cannot make that same assurance,” the company said.
Cyberattacks and model theft added to the picture
The biological case was only one part of the report. Anthropic also said it blocked misuse involving cyberattacks and surveillance, with activity linked to spyware vendors, politically motivated individuals, and state-sponsored groups.
Microsoft identified Russian hackers known as Midnight Blizzard using Claude. The cybercriminal group ShinyHunters also used Claude, adding another example of a criminal operation turning to an AI model during malicious activity.
None of the cases involved the newer Claude Fable or Mythos-class models, with one exception. That exception involved an illicit campaign to extract a model’s capabilities and replicate them in another model without authorization.
The distinction between older and newer models matters because Anthropic says its strongest safeguards now target the abilities that create the greatest risk. The company has added protections to recent models to restrict biological research that could be used to make weapons, while also blocking other forms of harmful use.
John Thickstun, an assistant professor of computer science at Cornell University, is among the experts connected to the broader discussion around these risks. The report’s findings place that discussion against concrete cases involving malicious code, AI prompts, cyber operations, and biological research.
Why the report matters beyond Claude
Anthropic’s report also includes a financial detail involving Xinbi Guarantee. The company operated over four years, and most of its $30 billion in sales involved money laundering for crypto scams. That figure shows the scale of criminal activity described alongside the report’s broader concerns about misuse.
Anthropic’s central warning is direct: AI models can support useful scientific and technical work, but the same capabilities can serve harmful goals. The company said, “As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer.”
That puts the focus on two tasks at once: stopping harmful requests and deciding when a model has become capable enough to require stronger controls. Anthropic’s actions show one approach, with safeguards that change as models gain new abilities.
The blocked chikungunya request also shows why simple lists of forbidden topics may not be enough. A request can involve research aimed at vaccines and treatments while also targeting properties that could make a virus more dangerous. Anthropic’s systems stopped the request rather than treating the scientific framing as a reason to allow it.
The report does not describe every interaction with Claude. It highlights cases Anthropic calls the most notable and novel threat activity it has identified. Still, the range is broad: cyberattacks, surveillance, biological research, illicit model replication, and criminal use by groups such as Midnight Blizzard and ShinyHunters.
For Anthropic, the message is that model safety cannot remain fixed. Claude Opus 4 and Claude Sonnet 4.5 had limits that reduced their ability to assist with dangerous biological research, while Claude Fable 5 receives stronger safeguards because newer models can handle more complex scientific tasks.
Based on




