A sobering report from Anthropic reveals that sovereign adversaries and non-state militants are converting commercial language models into force multipliers for missile guidance, cyber espionage, and biological research.

San Francisco and Washington, D.C.

For years, Silicon Valley pitched large language models as benign engines of human productivity, designed to summarize boardroom memos, generate clean software code, or translate foreign text. That comforting narrative suffered a heavy blow this week. In a detailed threat intelligence disclosure covering disruptions carried out between late 2025 and mid-2026, AI developer Anthropic released evidence showing that its flagship model, Claude, was co-opted by state-aligned actors and violent non-state groups to accelerate cyberattacks, design missile guidance systems, and explore enhanced biological pathogens.

The revelations underscore a dramatic transformation in global conflict. The barrier to acquiring advanced military capability is no longer guarded solely by state secrets, specialized centrifuges, or classified aerospace defense laboratories. Today, access to state-of-the-art technical expertise requires little more than an internet connection, a stolen credit card, and an evasion script designed to bypass commercial guardrails.

From Software Code to Missile Guidance

Among the most striking discoveries in the disclosure was the activity of a technical cell operating out of northern Yemen. Long associated with asymmetric warfare in the Red Sea shipping lanes, the group utilized instances of Claude to assist in engineering tasks across three distinct weapons initiatives. These included a short-range guided rocket using off-the-shelf mobile processing hardware, a multi-stage ballistic missile with a planned range exceeding 2,000 kilometers, and software support for a hypersonic glide vehicle concept.

Rather than relying on a traditional defense engineering cohort, the group employed automated AI workflows to write, debug, and optimize flight control software. When an initial field test of the guided rocket failed, the operators returned to the chatbot within hours, feeding post-test diagnostic data back into the system to analyze aerodynamic instabilities and control loop failures.

While Anthropic noted that the actors did not succeed in deploying a fully functional, AI-designed strategic weapon, the incident highlights a shift in technical leverage. Tasks that once demanded dedicated teams of aeronautical engineers and control systems analysts can now be parsed, modeled, and refined by a handful of motivated operators relying on automated reasoning tools.

Biological Uplift and Cyber Espionage

The risks extend well beyond missile ballistics. In the realm of biosecurity, the report outlined several instances where users attempted to utilize Claude to navigate complex dual-use biological research. In one case, an applicant sought assistance drafting a research grant proposal focused on gain-of-function modifications to the chikungunya virus, specifically aiming to enhance its transmissibility and immune evasion characteristics.

While older model generations were constrained to preventing basic recipes for known bioweapons, modern foundation models possess sufficient scientific fluency to assist with advanced genetic engineering workflows. As these frontier systems gain reasoning capabilities, distinguishing between legitimate medical research and dangerous pathogen enhancement becomes extraordinarily difficult for automated filters.

Simultaneously, state-sponsored cyber units have integrated language models into every phase of their digital operations. Rather than using AI merely to write phishing emails, malicious operators in Eastern Europe and East Asia have deployed model instances as active operators within automated attack chains. Malicious actors used the technology to analyze stolen hardware firmware, execute internal network reconnaissance, process compromised government identity registries, and run automated deception campaigns targeting civil society groups and military logistics networks.

The Limits of Corporate Self-Policing

The disclosure highlights the structural vulnerabilities of the modern AI deployment model. Commercial providers rely heavily on automated safety classifiers, input filtering, and account monitoring to detect illicit behavior. Yet threat actors routinely evade these measures through API relay services, third-party wrapper applications, and prompt engineering techniques that obscure the true intent of their queries.

Furthermore, the industry faces an ongoing challenge from model distillation. Anthropic revealed that several foreign entities engaged in high-volume automated querying campaigns designed to extract Claude’s internal reasoning patterns and capability profiles, effectively copying the model’s intellectual property to build ungoverned, unmonitored local clones. Once capabilities are successfully extracted and running on private infrastructure, cloud-based kill switches and safety filters cease to function entirely.

These developments place AI labs in an uncomfortable position. Tech executives find themselves acting as de facto intelligence agencies, performing global threat hunting and making unilateral decisions about which research queries are acceptable. Academic observers point out that asking private corporations to judge what constitutes safe biological research or sensitive dual-use technology lacks democratic legitimacy and institutional oversight.

The Regulatory Horizon

The findings are likely to accelerate regulatory intervention in both Washington and Brussels. Lawmakers have increasingly questioned whether voluntary safety commitments and internal corporate threat intelligence reports are sufficient to protect public safety and national security.

Governments are expected to press for stricter identity verification for high-capability API access, tighter controls on open-weight model releases, and standardized reporting mechanisms for dual-use technical queries. Yet enforcing regulatory boundaries on code and mathematical parameters remains notoriously difficult in a global economy.

For the technology sector, the era of treating artificial intelligence as a neutral, broad-spectrum utility is coming to an end. As foundation models grow more capable, their dual-use nature becomes impossible to ignore. The balance between fostering open scientific innovation and preventing the proliferation of algorithmic warfare may prove to be the defining policy struggle of the coming decade.