Anthropic’s September 2026 threat report outlines how state-backed hackers, criminal organizations and overseas AI developers have allegedly misused Claude for cyberattacks, influence campaigns, surveillance, fraud and other high-risk activities.
Anthropic has released a new September 2026 threat report examining the growing misuse of advanced artificial intelligence systems.
The report describes a broad range of malicious activity involving state-sponsored actors, criminal networks and AI research organizations, highlighting how capable AI models can be adapted for purposes far beyond legitimate research and productivity.
Anthropic groups the identified activity into seven major categories of harm:
- Cyber operations
- Influence operations
- Surveillance
- Scams and fraud
- Biological misuse
- Conventional weapons development
- AI model distillation
The findings underline a growing challenge for AI developers. As models become more capable, the same tools that can accelerate legitimate work can also potentially reduce the expertise, time and resources required to conduct sophisticated malicious operations.
Cyber Operations Emerge as a Major AI Misuse Risk
According to Anthropic’s report, Claude has been used in activities connected to cyber operations.
AI systems can assist with tasks across the cybersecurity lifecycle, including analyzing technical information, generating code and automating repetitive processes.
The concern is that these capabilities can also be exploited by threat actors seeking to scale attacks or reduce the technical expertise traditionally required for certain operations.
Anthropic’s findings place AI-enabled cyber activity alongside several other emerging categories of misuse, suggesting that the security challenge extends beyond conventional hacking.
Influence Campaigns and Surveillance Add Another Layer
Anthropic also identified influence operations and surveillance among the areas in which AI capabilities may be abused.
Generative AI can produce large amounts of text and other content quickly, potentially making coordinated influence campaigns easier to scale.
Surveillance presents a different concern. AI can help process and organize large volumes of information, potentially increasing the effectiveness of monitoring activities when combined with other technologies.
These applications demonstrate why AI safety discussions increasingly extend beyond model outputs themselves to the broader systems and organizations using them.
Scams and Fraud Can Become More Scalable
The report also highlights the use of AI in scams and fraudulent activity.
Criminal organizations can potentially use generative AI to automate portions of operations that previously required substantial human effort.
That could include creating convincing communications, adapting messages for different targets and coordinating activities at greater scale.
The underlying concern is not simply that AI can generate fraudulent content. More capable models can potentially make existing criminal operations faster, cheaper and easier to scale.
Biological and Conventional Weapons Misuse
Anthropic’s threat assessment also identifies risks involving biological misuse and conventional weapons development.
These categories represent some of the most serious potential consequences of advanced AI misuse because they involve capabilities that could extend beyond digital systems and affect the physical world.
The inclusion of these categories illustrates Anthropic’s broader concern that increasingly capable AI models may eventually become useful to actors pursuing harmful objectives across multiple domains.
AI Distillation Becomes a New Security Concern
One of the report’s notable areas is distillation, a process through which capabilities or useful behavior from a more capable AI system can potentially be transferred into another model.
Anthropic’s report describes what it characterizes as a significant illicit distillation campaign involving Alibaba, DeepSeek, Moonshot and other organizations.
The issue is particularly important for AI developers because model capabilities represent substantial research and development investments.
If another organization can systematically extract useful capabilities from a more advanced model and reproduce them in another system, the process could potentially undermine technical safeguards and provide a shortcut around years of model development.
Alibaba, DeepSeek and Moonshot Named in Distillation Findings
Anthropic’s report points to activity involving several Chinese AI organizations, including Alibaba, DeepSeek and Moonshot, in what it describes as a major illicit distillation campaign.
The allegations place model distillation alongside more traditional security threats as an emerging issue for frontier AI companies.
Distillation itself can have legitimate applications in AI development, including creating smaller or more efficient models. The concern arises when the process allegedly involves unauthorized extraction of capabilities from another company’s systems.
For AI companies, this creates a difficult security problem because preventing unauthorized capability transfer requires monitoring not only how models are accessed, but also how their outputs may be systematically collected and reused.
The AI Security Challenge Is Expanding
Anthropic’s September 2026 report portrays AI misuse as a rapidly expanding problem involving both digital and physical-world risks.
Cybercrime and fraud remain familiar categories, but the addition of influence operations, surveillance, biological applications, weapons development and model distillation demonstrates the breadth of potential threats.
The report also highlights an increasingly important distinction in AI security.
The risk does not necessarily come from a model being explicitly designed for malicious purposes. Instead, general-purpose capabilities can be repurposed by different actors for very different objectives.
AI Developers Face a Dual Challenge
The findings create a difficult balancing act for AI companies.
Developers need to make models useful enough to support legitimate users while simultaneously preventing malicious actors from exploiting the same capabilities.
That requires safeguards covering model access, monitoring, threat intelligence, abuse detection and collaboration with governments and other technology companies.
The growing importance of model distillation adds another dimension, since AI companies must also protect their systems against attempts to extract or replicate valuable capabilities.
A Broader Warning for the AI Industry
Anthropic’s latest report suggests that the security debate surrounding advanced AI is moving beyond hypothetical scenarios.
State-linked groups, criminal organizations and other actors are increasingly experimenting with AI capabilities for activities ranging from cyber operations and fraud to surveillance and influence campaigns.
At the same time, competition among AI developers has created a new concern around unauthorized capability transfer and model distillation.
The report ultimately illustrates the central challenge facing the industry: the more capable AI becomes, the greater its potential value to legitimate users and the greater the incentive for malicious actors to exploit it.
As frontier models continue to advance, controlling misuse may require not only stronger model-level safeguards but also tighter monitoring of how AI systems are accessed, deployed and replicated.

