Bombs, bioweapons and spyware: Anthropic releases a 154-page report on who is trying to misuse its AI
The company behind the Claude chatbot has named the threat actors attempting to weaponise its models, from missile designers to propagandists targeting dissidents.

Key points
- Anthropic published a 154-page threat intelligence report on Thursday detailing misuse of its AI models.
- Criminals, state-sponsored groups, spyware vendors, scientists and propagandists all appear among the identified bad actors.
- Attempted misuses include designing missiles and bombs, creating deadly pathogens, and surveilling political dissidents.
- Anthropic says the cases in the report are the most notable threat activity it has found, not everyday misuse.
- The report arrived two days after a former Anthropic employee resigned, citing concerns about the company's development pace.
Anthropics's Claude is one of the most capable AI assistants available to the public. Behind the scenes, people have been trying to turn it into something far darker.
On Thursday, Anthropic published what it describes as a threat intelligence report, a document companies release to share what security threats they have detected and how, so that others can prepare. At 154 pages, it is an unusually detailed look at who is knocking on the door and what they want.
Who is actually trying to misuse this?
The short answer: a wide range of bad actors. Anthropic identifies criminals, state-sponsored hacking groups, commercial spyware vendors, scientists working outside ethical guardrails, and propagandists among those caught attempting to misuse its models.
The attempted attacks cover serious ground. Some people tried to get Claude to help design missiles and bombs. Others pushed for help creating deadly pathogens, which are disease-causing microbes that could be weaponised. A third group used the AI to build tools for surveilling dissidents, meaning people who criticise their governments.
"The cases we share here aren't typical misuse, but rather examples of the most notable and novel threat activity we've identified to date," Anthropic wrote in the report.
Why publish this at all?
Anthropics's stated reason is accountability. "We're publishing this work because we believe we have a responsibility to disclose malicious misuse of our services," the company wrote.
That matters for the broader AI industry. When a company names the threat categories it is seeing, security researchers, policymakers and other AI developers get a clearer picture of real-world risk. The Guardian first reported the publication of the document.
The timing adds context. Two days before the report dropped, a former Anthropic employee named Jacob Coxon resigned publicly, saying the company was moving too fast on model development in ways he believed could cause catastrophic harm by 2030. Anthropic has not publicly responded to those claims.
What should ordinary people watch for?
Most readers will never encounter weapons designers or state hackers. But the tactics described in this kind of report do filter down into everyday scams.
Four things worth keeping in mind:
- AI-written messages are now polished enough to pass as human. Sloppy spelling is no longer a reliable warning sign in phishing emails or fake texts.
- Surveillance tools built with AI can be extremely targeted. If you are an activist, journalist or anyone who criticises a government publicly, be alert to unsolicited contact asking you to click links or install apps.
- Disinformation campaigns use AI to generate believable fake profiles and posts at scale. Check unfamiliar sources before sharing breaking news.
- If an AI tool ever tries to walk you through acquiring controlled substances, chemicals or weapons components, that is a red flag the tool has been compromised or the interaction is a scam.
Anthropics's willingness to name the threat categories is a step forward. Reading what the company found is a reasonable place to start understanding what AI-era threats actually look like.



