Editorial illustration representing AI threat intelligence, autonomous operations and defensive monitoring

Anthropic’s September 2026 Threat Report: AI Misuse Is Becoming More Autonomous

Anthropic has published its September 2026 threat intelligence report, offering one of the clearest snapshots yet of how capable AI systems are being misused in the real world. The report covers malicious activity the company says it identified and disrupted between December 2025 and August 2026, spanning cyber operations, influence campaigns, surveillance, scams and fraud, biological misuse, conventional weapons development and illicit model distillation.

The central theme is bigger than any single incident. Anthropic says AI is increasingly moving from a conversational assistant into an operational layer: models can help coordinate workflows, use tools, process large data sets and keep multi-step activity running for extended periods. Human operators still choose targets, objectives, monetization and review, but the amount of labor a capable model can absorb is growing.

That matters because the same features making AI useful to developers and businesses—coding, research, tool use, long context, automation and agentic execution—can also increase the speed and scale of abuse. Anthropic’s report does not argue that AI has become an independent attacker. Instead, it documents cases where people used AI to become substantially more productive operators.

The report also contains major allegations about the AI industry itself. Anthropic says it detected large-scale unauthorized attempts to extract Claude capabilities for training competing models, including campaigns it attributes to several China-based AI labs. Those claims are Anthropic’s findings and have not all been independently verified, so they should be read as allegations from the model provider rather than settled facts.

What Anthropic’s September 2026 report covers

Anthropic says its Threat Intelligence team spent eight months identifying and disrupting malicious use of Claude. The company emphasizes that the cases are among the most notable or novel incidents it has found, not a representative sample of normal Claude activity. The actors described include suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, propaganda institutions and politically motivated individuals.

Harm area What Anthropic says it observed
Cyber operations AI moving beyond advice into direct execution and orchestration across parts of the attack lifecycle.
Influence operations Fake personas, synthetic media workflows, coordinated social accounts and AI-assisted propaganda production.
Surveillance AI used to build surveillance systems, process large data sets and support state-aligned intelligence workflows.
Scams and fraud A deceptive dating-app network mixing thousands of AI personas with real gig workers.
Biological misuse Five dual-use research cases that Anthropic says could have supported biological-weapons development.
Conventional weapons Six cases involving weapons-related software, procurement or intelligence support.
Illicit distillation Large-scale attempts to extract Claude’s reasoning and other capabilities for use in training competing models.

Claude Haiku, Sonnet and Opus models appeared in the misuse cases. Anthropic says none of the misuse cases involved Claude Fable or Mythos-class models except for one illicit-distillation case. In each category, the company says it disrupted associated activity, strengthened safeguards and, where appropriate, shared intelligence with authorities or industry partners.

The biggest shift: AI is moving from assistant to operator

Anthropic frames the cyber section around a transition from conversational assistance to execution. The company says a majority of the cyber operations in the report were enabled by direct AI execution or orchestration rather than simple question-and-answer use. Some systems ran for hours or days, with multiple agents carrying out different parts of a workflow while humans stayed involved in the decisions that mattered most.

The report describes suspected state-linked espionage, financially motivated theft and other cyber activity in which AI was used across several stages of an operation. Anthropic also says it observed workflows that could adapt tooling after security products detected it, as well as scheduled collection jobs that continued without a person continuously supervising every step.

The defensive implication is significant. Traditional security often depends on imposing cost: detect a tool, block it, force an attacker to rebuild, and buy time. If AI helps an operator adapt faster, some of that cost advantage can shift back toward the attacker. The report does not show that conventional defenses are obsolete, but it suggests that static signatures and one-time blocking actions may be less sufficient against adaptive, agent-driven workflows.

Anthropic makes another important point: operational sophistication is becoming a weaker clue to the sophistication of the person behind an operation. Capable AI can compress gaps in coding ability, language knowledge, research speed and tool development. What once required a larger specialist team may increasingly be attempted by a smaller group or even an individual with access to powerful models and automation frameworks.

Influence operations are becoming full production systems

Anthropic says it disrupted nine influence operations originating across Russia, Iran, Turkey, the Gulf, South Asia, Africa and Europe, targeting audiences across six continents. The company describes actors using Claude not simply to write individual posts but to help construct the machinery behind campaigns: fake social profiles, news sites, targeting material, persona systems, content pipelines and internal campaign documentation.

Several campaigns were connected to political contexts or elections. Anthropic reports that Russian state media produced fabricated claims about Moldova’s president before the country’s September 2025 vote, while a pro-government operator in Kenya prepared fake grassroots content ahead of Kenya’s 2027 general election. The company argues that model providers can sometimes see the planning stage of an influence campaign before the finished content reaches social platforms.

One of the more striking cases involved an influence network targeting Iranian audiences. Anthropic says an AI-assisted account was instructed to imitate a real activist after analyzing roughly 8,400 Telegram posts. The wider network scraped more than 500 social channels and analyzed about 51,944 archived messages to build profiles of individuals. Anthropic says its investigation linked the activity to people associated with the PMOI/MEK and NCRI, while noting that it could not verify the level of centralized control.

The report also offers an important counterweight to fears about automated propaganda: Anthropic says many of the influence campaigns it discovered attracted little or no authentic engagement. Production can be cheap and scalable without distribution becoming effective. AI can make it easier to manufacture content and identities, but it does not automatically create a real audience, trust or political influence.

Surveillance may require fewer people to operate at larger scale

The surveillance section covers cases Anthropic says it disrupted between January and July 2026 involving state-aligned actors, state-linked contractors and commercial surveillance vendors. The company identifies activity connected to China, Iran, West Africa and the broader surveillance-for-hire market.

Anthropic highlights three patterns. First, AI can substitute for parts of an engineering workforce by helping a small number of people build and maintain complex systems. Second, models can process large amounts of public or collected information to create structured profiles and prioritize subjects. Third, AI is being integrated into government security bureaucracy rather than remaining an isolated tool used by technical staff.

Examples in the report include a consultant Anthropic says used Claude while engineering a communications-interception platform for Malian national-security authorities, Iranian actors using Claude in surveillance-related software work, and a Chinese intelligence collection unit using AI to produce investigations at large volume. Anthropic also says one Iranian unit analyzed hundreds of thousands of social-media posts before selecting 39 opposition accounts for monitoring.

The broader concern is scalability. Surveillance operations have historically been constrained by analyst time, language expertise, software-development capacity and administrative overhead. AI can compress those bottlenecks. It does not create surveillance authority or access on its own, but it can make institutions with existing access more capable of processing information and acting on it.

A dating-app case shows how AI fraud can scale

Anthropic’s fraud section includes a China-based app studio that the company says operated more than 20 dating apps while advertising the service as fully human. Over a two-week period in April 2026, Anthropic says it identified more than 4,700 AI personas interacting with at least 25,000 unique people.

The reported scale is notable. Anthropic says the match feed used roughly a three-to-one ratio of AI personas to real people, while Claude-powered personas generated about 2.36 million messages during the two-week window. Real gig workers were mixed into the system for interactions the AI could not convincingly perform, including live video calls or social-media follow-backs.

The case illustrates a broader pattern: fraud systems do not need AI to replace every human. A more scalable design can use models for the repetitive majority of interactions and humans only at moments when authenticity must be proven. The result is a hybrid operation in which a relatively small human workforce can support thousands of simultaneous synthetic relationships.

Anthropic says it banned the associated accounts and coordinated with other AI labs whose models were used for separate functions in the operation. For readers, the important point is the operating model: AI can turn deception into a high-volume service while keeping people available for the few tasks that still require a real person.

Biological misuse remains a difficult dual-use problem

Anthropic describes biological misuse as one of the most serious potential risks from frontier models. The report says earlier Claude models were clearly below the capability level where they could meaningfully assist a sophisticated user with dangerous biological research. For current frontier models, Anthropic says that assurance is less certain, which is why newer systems receive stronger safeguards around high-risk dual-use biology.

The company presents five cases in which model use could have supported work relevant to biological-weapons development. Anthropic deliberately withholds many institutions, countries, biological agents and technical details, and it does not claim that the researchers involved necessarily intended harm. That distinction matters because advanced biological research can be genuinely dual-use: similar knowledge may support beneficial science, defensive preparedness or dangerous applications.

Anthropic’s conclusion is that content filters alone are unlikely to solve the problem. It argues that safe access to powerful biological capabilities will increasingly require a combination of high-risk-content safeguards, institutional or account-level signals, trusted-access programs and enough observability to distinguish legitimate work from suspicious patterns.

Anthropic also found Claude use tied to conventional weapons activity

The report says Anthropic investigated six conventional-weapons-related cases: three connected to China, two to Russia and one to Yemen. Four involved software work associated with weapons systems, while two involved procurement or intelligence gathering.

Anthropic describes the category broadly as work related to weapons software, control systems, procurement and technical intelligence. The company says it introduced additional classifiers intended to detect and block high-risk weapons-development traffic and shared relevant information with public- and private-sector partners after disrupting associated accounts.

The distillation section may be the report’s biggest AI-industry story

The final section focuses on what Anthropic calls illicit distillation: large-scale, covert efforts to extract a frontier model’s capabilities and reproduce them in another model without authorization. Distillation itself is a standard machine-learning technique. Anthropic’s concern is unauthorized extraction using fraudulent accounts, stolen credentials, proxy services or undisclosed routing of user conversations.

Anthropic says that since February 2026 it has detected and disrupted unauthorized distillation campaigns that it attributes with high confidence to specific China-based labs targeting Opus-class models. The company says those efforts sought high-value capabilities such as reasoning, coding, data analysis, agentic tool use and long-horizon task performance.

The largest campaign in the report is attributed by Anthropic to Alibaba’s Qwen/Tongyi Lab. Anthropic says the campaign peaked at nearly 3 million exchanges per day from more than 3,500 fraudulent accounts and that it observed more than 151 million exchanges attributable to Alibaba between May and July 2026. These are Anthropic’s allegations and measurements; they should not be read as independently verified findings.

Anthropic also makes specific claims about other labs. It says Moonshot AI, maker of Kimi, relayed almost 300,000 customer requests to Claude over one ten-day period and attributes more than 23 million exchanges to Moonshot between May and July. It says DeepSeek conducted more than 12.1 million exchanges over 14 days in July. It attributes more than 3.4 million exchanges to Zhipu over 17 days in June and July and more than 400,000 requests to Xiaomi across 20 days in March and April.

The report additionally discusses SenseTime and MiniMax in the context of third-party reseller and proxy ecosystems. Anthropic alleges that some routing systems stored user conversations and that exchanges could be reused for model training. This creates a second issue beyond model intellectual property: data governance. According to Anthropic, some relayed sessions contained names, credentials, company information and other sensitive material from users who may not have known their requests were being forwarded to Claude.

That makes the AI supply chain itself part of the security boundary. A user may believe they are interacting with one model while a router, reseller or application sends the request somewhere else. For enterprises, the lesson is straightforward: knowing the model named in an interface is not enough. Organizations need to understand every intermediary, retention policy and routing layer between the user and the model provider.

What organizations should take from the report

The following is analysis based on the patterns Anthropic describes, not a list of instructions issued by Anthropic. The report suggests several practical defensive priorities for companies deploying AI systems.

  • Treat AI credentials as high-value secrets. Anthropic repeatedly describes stolen API keys and fraudulent account networks as enabling infrastructure. AI keys deserve controls comparable to other sensitive cloud credentials.
  • Monitor agent actions, not just prompts. When models can call tools or execute multi-step workflows, logs should capture what the agent actually did, which systems it touched and what data moved.
  • Separate autonomy from authority. A model can automate routine execution without unrestricted access to consequential systems. Human approval gates still matter for high-impact actions.
  • Verify routing and data retention. Third-party model routers can introduce privacy and supply-chain risks. Enterprises should know which providers may receive prompts and how those providers retain data.
  • Use identity and account context in abuse detection. Harmful behavior can look ordinary when viewed one prompt at a time. Account history, organization identity and unusual access patterns can provide stronger signals.
  • Assume adversaries will gain the same productivity benefits as defenders. Faster coding, research and automation are not exclusive to legitimate teams. Security programs should account for attackers receiving similar leverage.

Important caveats: this is Anthropic’s own threat intelligence

The report is unusually detailed, but readers should keep several limitations in mind. First, these are Anthropic’s investigations and attributions. The named actors, companies, measurements and conclusions are presented by Anthropic and have not all been independently verified. Where this article names a company or organization, it is describing Anthropic’s published finding or allegation.

Second, Anthropic explicitly says the cases are not typical misuse. They were selected because they were notable or novel. They therefore should not be used to estimate what percentage of Claude traffic is malicious or how common any specific abuse category is.

Third, Anthropic’s visibility has boundaries. The company can observe activity on its own platform and may detect planning before an operation moves elsewhere, but it does not necessarily see everything that happens after content or tools leave Claude. In its influence-operation discussion, Anthropic notes that it relies on open-source research, cross-platform data and public reporting to assess what happened after publication.

Finally, a model provider has its own incentives in describing both threats and mitigations. The report is valuable primary-source threat intelligence, but it should be read alongside independent security research, government reporting and evidence from other platforms as those become available.

Why this report matters for the AI industry

The September 2026 report shows that frontier AI safety is becoming less about isolated bad prompts and more about systems behavior. The relevant unit is increasingly an account network, an agentic workflow, a proxy service, a data pipeline or an organization—not a single conversation.

That shift has consequences for product design. Safety systems that judge only the text of an individual request can miss harmful behavior that emerges across hundreds or thousands of otherwise ordinary-looking interactions. Providers will increasingly need behavioral monitoring, identity signals, rate and access controls, tool-level permissions, anomaly detection and cross-industry intelligence sharing.

It also changes the debate about AI capability. The risk is not only that a model may know something dangerous. The more immediate operational issue is whether a model can coordinate tasks, use software, maintain context, adapt to feedback and continue working without constant human supervision. Those are the same capabilities that make AI agents useful for legitimate businesses—and the same capabilities that can increase the speed and scale of misuse.

This report arrives during a broader argument inside the AI industry about how quickly frontier capabilities are advancing and whether safety systems can keep pace. We recently covered the departure of Anthropic researcher Jacob Coxon and his warnings about the AI race. The threat-intelligence report approaches the issue from a different angle: instead of forecasting hypothetical future harms, it documents cases Anthropic says it has already seen on its platform.

The bottom line

Anthropic’s September 2026 threat report presents a world in which AI misuse is becoming more organized, more automated and more integrated into existing criminal, political, intelligence and model-development workflows. The headline is not that AI has replaced human attackers. It is that AI can make a human operator dramatically more productive.

In cyber operations, that can mean agents executing more of a workflow. In influence campaigns, it can mean entire content and persona systems. In surveillance, it can mean smaller teams processing more people and more data. In fraud, it can mean thousands of autonomous personas operating continuously. In model development, it can mean industrial-scale attempts to extract frontier capabilities through proxy networks and account abuse.

Anthropic says it disrupted the cases it found and used the resulting intelligence to strengthen its safeguards. Whether those safeguards can keep pace with increasingly capable models—and whether the rest of the AI ecosystem can establish similar visibility—is now one of the central security questions for the industry.


Source note: This article summarizes Anthropic’s September 2026 threat intelligence report. Unless otherwise stated, the operations, actor attributions, model-use claims and metrics described above are Anthropic’s findings. Anthropic says the cases are notable or novel examples and are not representative of typical Claude use.

Back to blog