Artificial-intelligence safety is moving into a more operational phase. For years, much of the debate centered on hypothetical scenarios: what might happen if highly capable models ended up in the wrong hands? Anthropic’s latest threat-intelligence report changes the question. According to the company, between December 2025 and August 2026 malicious actors attempted to use Claude in cyber operations, influence campaigns, surveillance, scams, conventional-weapons work, model distillation and potentially dangerous biological requests. Anthropic says it identified and disrupted these activities and, in some cases, shared intelligence with authorities and industry partners. The central issue is no longer whether AI can be misused. Misuse already exists. The harder question is whether detection, restrictions and incident response can scale as fast as the capabilities.
What the report contains
Anthropic groups its cases into seven harm areas and describes an evolution in how models are used. Attackers do not necessarily ask a chatbot to conduct an entire operation in one conversation. More often they break work into tasks that can look legitimate in isolation: writing code, analyzing vulnerabilities, translating text, gathering information, generating persuasive copy or automating procedures. This makes safety difficult because many capabilities that help defenders are identical to those that attackers value. The same skill that lets a security team discover a flaw can help someone exploit it. This dual-use nature cannot be solved simply by banning every technical request. Controls have to reason about context, sequences and access to external tools.
The biological case is the most sensitive signal
The Associated Press highlighted a case in which a user allegedly sought help with a gain-of-function research proposal involving chikungunya virus and objectives that could have increased transmissibility and immune evasion. Anthropic says it blocked activity of this kind and strengthened safeguards in newer models. Two opposite errors should be avoided. The first is complacency: as models improve in biology, lowering informational barriers can become materially relevant. The second is assuming that every advanced scientific request proves a model can independently build a biological weapon. Information, laboratory access, materials, experimental expertise and operational success are separate things. Serious policy has to preserve that distinction while still responding to emerging capability.
Cybersecurity accelerates both attackers and defenders
In cyber operations, AI is already much closer to everyday use. Models can help interpret code, generate scripts, search for vulnerabilities, analyze logs and automate repetitive work. Defenders gain speed; attackers can lower the cost of some stages of an operation. Anthropic’s report helps explain why labs are investing in behavioral monitoring rather than relying only on filters applied to individual prompts. A user can distribute an operation across multiple sessions and combine outputs that appear harmless on their own. Detecting the pattern can require looking at sequences, connected tools and operational context, which in turn raises legitimate questions about privacy and surveillance of users.
Surveillance changes scale
Another part of the report concerns AI-assisted surveillance. Here, the risk does not depend on one spectacular capability but on the economics of automation. Summarizing huge message archives, classifying profiles, extracting relationships among people and turning messy data into operational reports can make previously expensive monitoring dramatically cheaper. That matters for governments, spyware vendors, corporations and civil society. A general-purpose model can become a force multiplier when placed on top of databases, intercepted material or open-source intelligence. Safety therefore has to consider not only what a model knows, but what tools and datasets it can reach.
Influence operations move the bottleneck
Generating thousands of posts is no longer technically difficult. The harder part of an influence operation is distribution, credibility and access to accounts that look authentic. Anthropic describes cases in which AI was used to produce and adapt political or persuasive content. That does not mean every AI-generated campaign works. Propaganda still needs networks, audiences and narratives that resonate. But the cost of experimentation collapses. Operators can test many languages, tones and variants at a speed that was previously unrealistic. Platforms and governments therefore need defenses that combine content detection with network analysis and signals of coordinated behavior.
Transparency is useful but not enough
Publishing periodic misuse reports is valuable. It lets researchers, regulators and competitors see how the threat is shifting and creates reputational pressure on model providers. Yet these reports are produced by the same companies that build and sell the systems, so they cannot be the only layer of verification. Independent audits, common incident classifications and reporting channels for serious cases are increasingly necessary. Without comparable metrics it is difficult to know whether one provider reports more abuse because it has more exposure, because its monitoring is better, or because its protections are less effective. Transparency needs standardization to become genuinely informative.
The false-positive problem
As safeguards become more aggressive, the risk of blocking legitimate research, journalism, system administration and education grows. A biologist can have valid reasons to discuss pathogen properties; a penetration tester may need to write code that resembles an exploit. The answer cannot be a blind refusal of everything technically sensitive. Labs are therefore experimenting with differentiated access, identity verification, logging and trusted-researcher programs. This creates a difficult balance: experts need enough access to do valuable work, while attackers may claim benign intentions. Good security policy needs appeal mechanisms and evidence-based thresholds rather than simple keyword bans.
Security becomes a product feature
Safety and security were once treated as compliance layers that could be added after training. The cases in this report suggest the opposite. As models are embedded in agents with access to browsers, terminals, databases and external services, controls have to be designed into the architecture. Granular permissions, confirmations for sensitive actions, sandboxing, trajectory monitoring and rapid access revocation become part of the product experience. Asking how intelligent a model is no longer tells us enough. We also need to ask what it can actually do, which credentials it holds and what supervision applies when it acts.
This is an industry problem
Anthropic calls for more collaboration between companies and governments. That matters because malicious users can move across providers. If one service blocks a technique, another may fail to recognize it. At the same time, a centralized blacklist without safeguards could harm legitimate users. The industry needs mechanisms resembling those developed in cybersecurity: shared technical indicators, disclosure procedures, incident taxonomies and ways to challenge incorrect decisions. AI compresses the timeline. Practices that took decades to mature in software security now need to be built in a few years.
BreakingTech’s view
The value of Anthropic’s report is not that it proves Claude is inherently dangerous or inherently safe. It makes a new attack surface visible. More capable models are general tools, so they can amplify both useful and harmful work. A credible response cannot rely on safety marketing or indiscriminate bans. It must measure incidents, examine connected tools, differentiate access and make laboratory decisions auditable. The most important shift is cultural: stop treating AI misuse as a hypothetical future scenario and start managing it as an operational security problem with procedures, accountability and measurable controls.
Sources and verification
BreakingTech cross-checked Anthropic’s “Detecting and countering misuse of AI: September 2026” report with reporting by the Associated Press. Cases are described as activities detected and reported by Anthropic; where operational capability cannot be independently verified, we avoid extending the company’s claims beyond what the available evidence supports.



