Analysis
Anthropic published its September 2026 threat intelligence report on September 10, detailing how the company's threat intelligence team identified and disrupted misuse of Claude across seven harm categories between December 2025 and August 2026, according to Anthropic's own disclosure. The categories -- cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and illicit model distillation -- represent the broadest single accounting of real-world AI misuse Anthropic has published to date, and CNBC covered the biological-misuse findings separately the same day.
The biological-misuse cases
The most sensitive disclosures involve five documented cases in which researchers used Claude in ways that could have supported biological-weapons development. In one instance from May 2026, a scientist sought Claude's help drafting a grant application for gain-of-function research on chikungunya virus, a mosquito-borne pathogen with no licensed treatment -- the kind of dual-use request that sits at the center of the biosecurity debate that has surrounded frontier AI labs since well before this report, as Pulse covered when more than 100 companies signed a coalition letter on AI-accelerated risk more broadly.
“That's a genuinely unusual level of proactive transparency for a frontier lab to publish about its own product's misuse.”
State surveillance, not hypothetical
Separately, Anthropic identified an actor tied to a municipal cyber-police unit in China using Claude to run a domestic surveillance operation that flagged targets ranging from pro-democracy figures in Hong Kong to advocates for Uyghurs and other human-rights groups. That case moves AI-enabled state surveillance from a frequently theorized risk in AI-safety literature to a documented, operational reality Anthropic says it actively disrupted -- a distinction that matters because it demonstrates state-level misuse is already happening at commercial-model scale, not only at the frontier of hypothetical future capability.
All the disclosed misuse cases -- across every one of the seven harm categories -- involved Claude's Haiku, Sonnet or Opus models, the versions most widely available to ordinary users and developers, rather than Anthropic's more tightly access-controlled Fable- or Mythos-class systems reserved for trusted-access programs in cybersecurity and life sciences. That's a meaningful distinction: it means none of this report's incidents tested whether Anthropic's most-restricted tier of safeguards actually holds against a determined, sophisticated actor, since none of the disclosed cases involved those systems at all.
What the report doesn't answer
Anthropic says every operation documented in the report was disrupted -- accounts removed, other safeguards applied, and in some cases findings shared with law enforcement or other AI companies. That's a genuinely unusual level of proactive transparency for a frontier lab to publish about its own product's misuse. But transparency about what Anthropic caught says nothing about what it didn't: the report is, by definition, a list of successfully disrupted cases, and the real risk is that it offers no way to estimate how much comparable misuse -- on Claude or any competing model -- went undetected over the same nine-month window.
For any VC or operator evaluating a frontier lab's safety posture as part of diligence, this report is a genuinely useful data point precisely because it names real, specific, disrupted incidents rather than describing safety in the abstract -- but critics would rightly note it should be read as a floor on documented misuse, not a ceiling on actual risk.