Anthropic report details AI misuse by criminals and scientists
Anthropic report details AI misuse by criminals and scientists

Anthropic has published a threat intelligence report detailing how criminals, state-sponsored groups, spyware vendors, scientists, and propagandists have attempted to use its AI models to design missiles and bombs, create deadly pathogens, and surveil dissidents.

The 154-page report, released on Thursday, highlights cases of misuse that the company says are the most notable and novel threats it has identified to date. Anthropic stated it has a responsibility to disclose malicious misuse of its services.

Biological research misuse cases

The company detailed five case studies of scientists using its AI models in biological research, where researchers circumvented safeguards meant to prevent users from accessing unsupported regions and worked to hide the purpose of their work. Anthropic banned these accounts but did not reveal the names of the research institutions or countries involved, citing uncertainty about the researchers' intent.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

One example involved a scientist using Claude to work on a state-sponsored grant application to study the chikungunya virus, a mosquito-borne disease similar to dengue and malaria. Anthropic told the New York Times this case was especially concerning because the study was to be conducted at a military research institute.

Other threat actor activities

The report also detailed dozens of other examples, including cyber operations such as Russian espionage and smash-and-grab cyberhacks, surveillance operations targeting Uyghurs in Syria and internal dissidents, propaganda campaigns in Russia, Malaysia, Iran, and Bangladesh, and the use of Claude to develop software for conventional weapons in Yemen, China, and Russia.

Anthropic noted that biological misuse is one of the most serious risks of frontier AI models, stating that without correct safeguards, such capabilities could have catastrophic consequences.

Context and expert concerns

The report comes two days after former Anthropic employee Jacob Coxon resigned, stating the company and its rival OpenAI were racing toward self-improving superintelligence that could cause human extinction by 2030. Current employees posted public agreements with him.

Many AI experts say real-world threats, like those in the report, are more concerning in the near term than an apocalyptic scenario. Heidy Khlaaf, chief AI scientist at the AI Now Institute, said AI accelerationism and doomerism both enforce the notion of an AGI superbeing, but labs creating technology for cybersecurity exploitation and weapons could be more deadly.

Anthropic stated that potential real-world misuse is often investigated internally and by academics, governments, and international organizations, and called for the entire AI industry to work with governments to address harms and create defenses.

Pickt after-article banner — collaborative shopping lists app with family illustration