
Anthropic said its Claude models were used in multiple instances of Claude AI misuse by foreign governments and proxy groups to design biological agents, conduct mass surveillance of diaspora communities and write missile‑guidance code, prompting a wave of inquiries from policymakers.
The company’s mid‑2024 abuse report details eight misuse cases it shut down between January and July. Iranian operatives employed Claude to fingerprint individuals on social‑media platforms, while a contractor for Mali’s national‑security agency built software that harvested intelligence on political opponents. Chinese firms Moonshot and Deepseek routed roughly 300,000 user queries through 5,380 fraudulent accounts over ten days, exposing potentially sensitive data to the AI provider.
Anthropic also flagged attempts to engineer biological weapons. The report lists designs involving the chikungunya virus, a highly pathogenic avian‑influenza strain, members of the smallpox/mpox family and a range of venoms and toxins. In a separate memo, Claude was cited as a source of missile‑guidance code for a Yemen‑based project and as a tool in broader cyber‑espionage operations.
The surveillance findings trace state‑sponsored campaigns to China, Iran and West Africa. Chinese‑linked actors targeted Hong Kong activists, Tibetan and Falun Gong communities, and Iranian dissidents abroad. Iranian actors used Claude’s language‑analysis capabilities to map social‑media footprints and create dossiers that could be used for intimidation or arrest. In Mali, the AI‑driven tool was integrated into a national‑security platform, showing how low‑cost generative models can amplify authoritarian surveillance.
Anthropic did not name the scientists involved in the biological‑research cases, citing a risk of further harm, but the report confirms the AI was used to automate steps normally performed by virologists and toxicologists. By generating protein‑folding predictions, suggesting vector‑delivery mechanisms and drafting synthesis protocols, Claude acted as a shortcut for illicit labs lacking specialized staff.
The company identified the misuse through automated usage‑pattern monitoring, anomaly detection and human review. When activity breached policy, Anthropic disabled the offending accounts and, where possible, notified law‑enforcement partners. The shutdowns concluded in July, after which the firm released the consolidated findings.
Policy experts say the incidents expose a regulatory blind spot. Current export‑control regimes focus on hardware and traditional software, leaving generative‑AI tools largely unregulated. Industry groups are drafting voluntary safeguards, such as stricter API access controls and real‑time misuse detection, but adoption is uneven. U.S. and European legislators are reportedly drafting bills that would require AI providers to report high‑risk misuse and implement risk‑based monitoring.
For diaspora activists, ethnic minorities and political dissidents, the threat is immediate: AI‑enhanced profiling can accelerate targeting, and the prospect of AI‑crafted bioweapons raises public‑health concerns. National‑security agencies in the United States and allied nations now face a new espionage vector that blends cheap cloud‑based models with state‑level objectives.
Anthropic’s disclosures leave open questions about the scale of the missile‑software claim and the full extent of data exposure from the Chinese routing scheme. Independent verification is limited, and the company’s internal investigations are not publicly auditable. As governments consider extending export‑control laws to generative AI, the next step will likely be an international effort to define “high‑risk” AI applications and mandate transparent monitoring, lest the technology continue to be repurposed for weapons development and mass surveillance.