
Anthropic’s September 2026 threat report reads like a Tom Clancy plot, except the operations are real. Chinese defence researchers built electronic-warfare modules and modelled strikes on Taiwanese air defences, Iranian security agencies profiled dissidents and scouted U.S. naval targets, a handful of operators ran agent swarms against roughly 50 organizations, and seven Chinese AI labs allegedly siphoned Claude’s capabilities through fraudulent accounts. None of it proves Claude built a working weapon, and all the evidence comes from Anthropic’s own selected cases. The credible conclusion is narrower and more unsettling: AI is collapsing the cost of surveillance, propaganda, cyber operations and military research, giving small teams capabilities that used to require large institutions.
Reading Anthropic’s latest threat report, I kept thinking that its case studies could provide the plot for a modern Tom Clancy novel. Chinese researchers model an attack on Taiwan’s air defences. Iranian operatives track American warships. Russian developers build autonomous drone swarms. Intelligence agencies use AI to monitor dissidents, while rival AI companies secretly extract the capabilities of Western models.
The difference is that these are not fictional scenarios. Anthropic says they are real operations it detected and disrupted on Claude.
Published on September 10, 2026, Detecting and countering misuse of AI: September 2026 covers malicious activity identified between December 2025 and August 2026. The cases span cyberattacks, foreign-influence campaigns, surveillance, conventional weapons, biological research, fraud and the theft of AI capabilities.
The central message is unsettling: AI is evolving from an assistant that answers questions into an operational platform that can perform work previously requiring teams of engineers, analysts, programmers and intelligence officers.
China and military AI
One China-based defence researcher used Claude to create approximately 16 software modules for electronic warfare and the suppression of enemy air defences.
The system analyzed radar installations, missile batteries, command centres and communications networks. It calculated radar coverage, modelled jamming effectiveness and ranked targets according to their military value and vulnerability.
During development, the operator changed the simulation to include 12 targets in Taiwan, including Patriot and Tien Kung missile batteries, air bases, an early-warning radar installation and a command bunker. Anthropic says account information linked the operator to Chinese research institutions, including the People’s Liberation Army Academy of Military Sciences.
In another case, a China-based actor used Claude to develop portions of an anti-torpedo fire-control system and produce a technical proposal exceeding 200 pages. The operator repeatedly asked Claude to act as a hostile expert reviewer, using its criticism to improve successive drafts intended for a Chinese defence manufacturer.
A separate actor used Claude to investigate foreign high-power microwave weapons, identify their components and suppliers, reconstruct their supply chains and prepare restricted briefings for senior Chinese military or government officials.
These examples do not prove that Claude-designed systems became operational weapons. They do show, however, how AI can compress research, software development, technical documentation and review cycles that would ordinarily require large specialist teams.
Iranian reconnaissance and surveillance
Anthropic says an Iran-linked operator used Claude to assemble targeting recommendations concerning U.S. naval forces in the Middle East.
The system combined publicly available ship and aircraft transponder identifiers, commercial satellite-imagery searches, personnel names collected from military photographs and research into vulnerabilities affecting maritime communications and industrial-control equipment.
There is no evidence in the report that the intelligence resulted in an attack. Nevertheless, the case shows how AI can rapidly convert scattered public information into structured military intelligence.
Iran-linked organizations also used Claude for domestic surveillance. Anthropic banned 16 accounts associated, with what it describes as high confidence, with Iranian paramilitary and security agencies.
The operators reportedly used Claude to:
- Analyze more than 155,000 social-media posts.
- Build identity-resolution and social-network-analysis tools.
- Develop phishing pages and credential-stealing software.
- Create a malicious Firefox extension disguised as a prayer-times utility.
- Support a centralized case-management system containing national IDs, political or religious beliefs, criminal records and social-media accounts.
One organization claimed to have profiled 6,388 Iranians in a single year. That number comes from the operator rather than independent verification, but Anthropic says the malicious browser extension was completed and deployed.
Iranian state-aligned institutions also employed Claude to create propaganda strategies, multilingual content, artificial personas and campaigns designed to make government narratives appear to originate from independent writers or ordinary citizens. Anthropic found some of the resulting material circulating on Iranian and international platforms, although it could not establish its reach or influence.
AI-enabled repression
Some of the report’s most disturbing cases involve surveillance of religious minorities, activists and diaspora communities.
A China-aligned operation used Claude to monitor Uyghurs in Syria, identify people experiencing financial or personal difficulties and approach them for information about Uyghur military formations. Claude provided translation, cultural coaching and Syrian Arabic messaging to an operator who apparently did not speak Arabic.
Other China-based actors used Claude to produce intelligence dossiers on Catholic cardinals, Taiwanese Christian leaders, Tibetan Buddhists, Falun Gong practitioners, democracy activists and human-rights organizations.
One operation collected advance information about overseas gatherings, including the route of a pro-democracy march in Vancouver. Another used Claude Code and custom automation to query a government surveillance database and generate daily reports for supervisors.
Anthropic’s attribution confidence varies across these cases. Some were connected to identifiable government organizations, while others appeared to involve contractors or individuals aligned with Chinese state-security priorities.
Cyberattacks become agentic
The report describes Chinese-speaking operators, two reportedly university students in Hunan, using teams of AI agents to conduct vulnerability research and cyber operations.
Their workflows searched for exposed systems, reverse-engineered security products, developed exploits and maintained persistent records across multiple attacks. Anthropic says the group targeted approximately 50 organizations and successfully accessed an education-technology company, a retailer’s production environment and records held by a Southeast Asian government agency.
The important development is the use of “agent swarms.” A lead AI agent divided objectives among multiple subagents that could conduct reconnaissance, test vulnerabilities and collect information with limited human involvement.
This makes conventional assumptions about cyber-threat sophistication less reliable. A small group, or even an individual, may now be able to produce work that previously suggested the resources of a large criminal or state-backed organization.
Biological research and weapons
Anthropic identified five cases in which Claude was used for research that could support biological-weapons development. These included work involving avian influenza, chikungunya, orthopoxviruses and novel toxins.
The company is careful not to claim that anyone successfully produced a biological weapon. Some of the work could also have legitimate scientific applications, making intent difficult to determine.
The broader concern is that today’s models may be becoming capable enough to help knowledgeable researchers plan complex experiments. Anthropic says the evidence is no longer strong enough for it to assure the public that advanced models cannot meaningfully assist dangerous biological research.
Chinese laboratories extracting Claude
A separate section accuses seven Chinese AI laboratories of conducting industrial-scale “distillation” campaigns against Claude.
Distillation is normally a legitimate process in which a smaller model learns from the output of a more capable model. Anthropic considers these particular campaigns illicit because they allegedly involved fraudulent accounts, geographic-control evasion, stolen credentials and unauthorized attempts to extract Claude’s internal reasoning.
Anthropic attributes more than 151 million exchanges to an Alibaba-linked operation, 23 million to Moonshot, 12.1 million to DeepSeek, 3.4 million to Zhipu and more than 400,000 to Xiaomi.
The most serious privacy allegation is that Moonshot and DeepSeek silently forwarded some customer requests to Claude. According to Anthropic, the forwarded material included corporate information, authentication credentials, Chinese police and military surveillance data, and information associated with a Russian defence agency.
The named companies had not publicly answered the specific allegations when Reuters reported on the findings. China’s foreign ministry said it was unaware of the report and opposed distortions and smears against China.
What the report really tells us
The report does not demonstrate that Claude independently created a successful weapon or transformed an amateur into a sophisticated intelligence service overnight.
Its evidence also comes entirely from Anthropic. The company selected particularly serious cases rather than a representative sample, and many of its attribution judgements cannot be independently verified.
But the larger conclusion remains credible.
AI is lowering the cost of sophisticated cyber operations, surveillance, propaganda, military research and intelligence analysis. It is giving small teams access to multilingual, technical and analytical capabilities once available only to large institutions.
The modern Tom Clancy plot is therefore not about an all-powerful artificial intelligence deciding to start a war. It is about governments, contractors, criminals and military researchers using ordinary commercial AI to operate faster, at greater scale and with far fewer people.
That story is already being written.
Frequently Asked Questions
What is Anthropic’s September 2026 threat report?
It is a public document called Detecting and countering misuse of AI: September 2026, published on September 10, 2026. It describes malicious activity Anthropic says it detected and disrupted on Claude between December 2025 and August 2026, covering cyberattacks, influence operations, surveillance, conventional weapons research, biological research, fraud and the theft of AI capabilities.
Did anyone actually build a weapon using Claude?
Not according to the report. Anthropic documents research, software modules, technical proposals and targeting analysis, but it does not claim any of that work became an operational weapon or a successful biological agent. What the cases show is compression of the work: research, code, documentation and review cycles that would normally take large specialist teams got done by very few people.
What is an AI agent swarm, and why does it matter for cybersecurity?
An agent swarm is a lead AI agent that splits an objective across multiple subagents, each running reconnaissance, vulnerability testing or data collection with limited human supervision. It matters because it breaks the old assumption that scale implies resources. A campaign against 50 organizations used to suggest a state-backed team. Now it can come from two students.
What is illicit distillation, and which companies does Anthropic name?
Distillation is the ordinary practice of training a smaller model on the outputs of a larger one. Anthropic calls these campaigns illicit because of how the access was obtained: fraudulent accounts, evasion of geographic controls, stolen credentials and attempts to extract Claude’s internal reasoning. The report attributes more than 151 million exchanges to an Alibaba-linked operation, 23 million to Moonshot, 12.1 million to DeepSeek, 3.4 million to Zhipu and more than 400,000 to Xiaomi, and alleges that Moonshot and DeepSeek silently forwarded some of their own customers’ requests to Claude.
How much should we trust the findings?
Treat them as credible but one-sided. Every piece of evidence comes from Anthropic, the cases were selected for severity rather than sampled representatively, attribution confidence varies from case to case, and the named companies and governments have not answered the specific allegations. The pattern is more reliable than any single claim in it.