
A China-based operator used Claude to draft anti-torpedo system specifications, while another developed targeting software for electronic warfare and air defence suppression. In Yemen, a weapons engineering group used it to develop guidance software for rocket and missile programmes.
In a disclosure about activities on Claude’s platform between December 2025 and August 2026, Anthropic says hackers used AI to create automated monitoring ‘agents’ (autonomous tools that act on their own) that watch their own malware. When security products detected the malware, the agents modified and rebuilt it, repeating the process until it could evade detection.
“Sophisticated and persistent threat actors continuously test our safeguards and try to circumvent the technical measures we use to detect and prevent misuse,” Anthropic said in the report titled ‘Detecting and countering misuse of AI: September 2026’.
The company claimed that actors used Claude’s Haiku, Sonnet, and Opus models, not Fable or Mythos (except in one case), in the cases cited in the report.
Anthropic said it had disrupted the reported activities and used its findings to strengthen safeguards.
Apeksha Kaushik, Senior Principal Analyst at Gartner, said the concern is not that AI independently creates a pathogen or toxin, but that it can support multiple stages of a harmful workflow, including research ideation, grant preparation, experimental planning, computational optimisation, and concealing research objectives. “This could reduce the time, cost and specialised knowledge required to develop credible proposals, enabling capable threat actors to work more efficiently and giving less-specialised threat actors access to
information they may not previously have possessed,” she said.
Safeguards
“AI providers should test for multi-step misuse, restrict actionable assistance in high-risk biological areas, verify users and establish proportionate escalation processes,” she said.Srinivas L, Joint Managing Director and Joint Chief Executive Officer of 63SATS Cybertech, said AI hasn’t made dangerous science easier to invent; it’s made everything around it easier.
“The grant proposal, the experiment plan, and the data sifting once took years of training, but with AI it can take an afternoon. That lowers the entry barrier for less-skilled actors and widens the threat landscape well beyond traditional cyber,” he said.
Roshmik Saha, Co-founder and CTO of data privacy and cybersecurity company Skyflow, said that as models become more capable, the risk is no longer limited to what an AI can generate but extends to the data, tools and systems it can access and act on.
“When AI systems are given broad or persistent access, they can chain together tasks and interact with information in ways that are difficult to predict or contain. That unpredictability becomes a greater risk as AI becomes more autonomous,” he said.
“The focus, therefore, has to shift to where data is actually used. AI systems should only receive the minimum data required for a specific task, at the point it is needed, with clear visibility into what information was accessed, for what purpose, and how it was used,” he pointed out.
Published on September 11, 2026
