Analysis
Anthropic's latest threat intelligence report, published this week, says an Iran-linked threat actor used Claude to compile targeting handbooks on US Navy warships operating in the Middle East -- one of the most concrete examples yet of a state actor using a commercial AI model directly against US military assets. The roughly 154-page report, titled "Countering misuse of AI," covers activity Anthropic detected and disrupted between December 2025 and August 2026 across seven harm categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and illicit model distillation.
How Claude Was Actually Used
According to Anthropic's account, reported by Navy Times, the actor used Claude -- with help from a Python data pipeline Claude itself helped write -- to collect and analyze publicly available information on US naval forces. The compiled material included a roster of US personnel scraped from captions on public military photographs, ship and aircraft transponder identifiers, commercial satellite-imagery query scripts, and a list of public websites that expose US naval movements. The same actor directed Claude to research known vulnerabilities in shipboard satellite-communications software. None of this required Claude to do anything a skilled human researcher couldn't do manually -- the concerning part is how much faster and more completely an AI model did it.
“Looking across just 30 days of activity, Anthropic identified roughly 35 distinct research efforts it judged potentially concerning enough to warrant review.”
Anthropic said it banned the account, built new detections aimed at similar patterns, and shared its findings with US government authorities. That response mirrors Anthropic's own July disclosure that its models had been manipulated into gaining unauthorized access to other organizations' systems during a separate incident -- a pattern of the company publicizing its own products' misuse that no other major AI lab has matched at the same level of specificity. Pulse's ongoing coverage of Anthropic has tracked that disclosure pattern across several incidents this year.
The Bioweapons Findings Are the Report's Real Escalation
Separate from the Navy case, Anthropic disclosed it detected and shut down five distinct cases where users attempted to apply Claude toward biological-weapons-relevant research -- including a request to draft a gain-of-function grant proposal involving chikungunya virus, work on H5N1's mammalian adaptation, and research touching orthopoxviruses, the family that includes smallpox and mpox. Looking across just 30 days of activity, Anthropic identified roughly 35 distinct research efforts it judged potentially concerning enough to warrant review. The company's own assessment is blunt: older models, it said, were well below the threshold where they could meaningfully assist in bioweapons development -- that is no longer a certainty with newer models.
What The Report Doesn't Resolve
However, every case in this report is one Anthropic caught -- the report says nothing about misuse patterns it hasn't yet detected, on Claude or on any competing model. OpenAI, Google, and Meta don't publish comparably detailed threat-intelligence reports on their own models' misuse, which means Anthropic's disclosure creates an asymmetry: the lab that reports the most transparently looks, on paper, like the one with the most abuse cases, when the more likely explanation is that it's simply the one looking hardest and saying so publicly.
For founders and investors in the AI-safety and red-teaming space, the report is a live demonstration of demand: government agencies, defense contractors, and any company handling sensitive operational data now have a documented, named case of a frontier model being weaponized against a specific military target. The open question the Pentagon and intelligence community now have to answer: whether they push every lab toward mandatory, standardized misuse reporting, or keep relying on voluntary disclosure from whichever one chooses to publish.