Anthropic published a detailed report this week cataloging misuse attempts against its Claude model spanning eight months, from December 2025 through August 2026. The report covers seven categories of harm, from cyber espionage to biological research, and the overall picture is more reassuring than the headline-grabbing details might suggest. Most attackers are unsophisticated, most operations fail, and the most damaging threat is not the one most people would guess.

Distillation as the Primary Threat

The report's most significant finding concerns distillation, the process of extracting a model's cognitive capabilities by sending it large volumes of queries and training a new model on the outputs. Distillation is dangerous not because of what it allows a single attacker to do, but because it transfers a model's skills without transferring its safety guardrails. A distilled model inherits the problem-solving ability but not the refusal behaviors that prevent misuse.

Anthropic disclosed that every major Chinese AI lab attempted to systematically distill Claude. DeepSeek, Moonshot, and Xiaomi each routed large volumes of user queries directly to Claude's API, collected the responses, and used them to train their own models. Moonshot went further, presenting Claude-generated outputs to its users as native Kimi responses. The practice amounts to using a competitor's infrastructure and safety investment to build a product you sell, while stripping out the protections that competitor built into its system.

The disclosure landed two days after a joint advisory from NSA, CISA, and FBI addressed the same distillation campaigns. Anthropic's report goes further by naming the specific labs involved and describing the mechanics of the attacks. The public identification of these actors creates diplomatic friction, but it also establishes a clear record of systematic theft that goes beyond typical competitive behavior.

Cyber Operations: Automation Meets Opportunism

The report details five distinct cyber operation clusters, each illustrating a different way AI changes the threat landscape. The most sophisticated is GTG-20006, a Russian espionage operation linked to the Midnight Blizzard group. This operation used Claude to test its malware against security defenses, iterating until detection tools failed to flag the code. It then automated phishing attacks from AI-generated domains, targeting Ukrainian government officials, military personnel, and the country's drone supply chain. The operation compromised WhatsApp accounts through headless browsers and targeted surveillance cameras, all without human intervention at each step.

At the other end of the spectrum is GTG-50014, associated with the ShinyHunters collective, which conducted what amounted to automated smash-and-grab operations. Rather than planning specific attacks, the group used Claude to scan broadly for any available vulnerability, living off the land and exploiting whatever it found. The approach lacks precision but achieves volume, casting a wide net across potential targets.

A Chinese-speaking operation designated GTG-10007, likely operating from Changsha in Hunan province, used Claude to automate vulnerability research and exploit development at industrial scale. The operation targeted roughly fifty organizations and successfully compromised an education technology company. GTG-50020, a Russian-speaking financially motivated actor, shifted its focus from hotel booking platforms to attacking AI companies directly, attempting to steal API keys through prompt injection attacks on sandboxed environments. The operation targeted thirty companies but never obtained the pre-release model access it sought.

Influence Operations: Large but Mostly Ineffective

Nine influence operation cases appear in the report, originating from Russia, Iran, Turkey, and actors across the Gulf, South Asia, Africa, and Europe. They targeted audiences on six continents. The operations share common tactics: building networks of fake social media profiles, creating entire AI-generated news sites, and laundering content through layers of synthetic personas to obscure attribution.

The largest operation, GTG-54002, operated as a commercial influence-as-a-service business based in France. It maintained seventy fabricated news sites and two hundred fifty inauthentic Twitter accounts, using Claude to write, rewrite, and tailor news articles for different audiences. An election manipulation platform targeting Malaysia, GTG-84005, deployed roughly a thousand fake Twitter accounts alongside fabricated political dossiers.

Despite the scale, the report suggests these operations have achieved limited real-world impact. The campaigns mostly target regions with less sophisticated media ecosystems, and the defenders have largely kept pace. Social media platforms have held up better than expected against AI-generated influence content, catching and removing fake accounts before they gain meaningful traction.

Surveillance and the Limits of Mitigation

Surveillance operations present a different kind of problem, one that does not yield to technical countermeasures. The report covers threat actors from China, Iran, and West Africa, as well as commercial surveillance-for-hire services. Many operations involved mass analysis of publicly accessible social media posts, often to identify dissidents or map opposition networks.

The most striking case is GTG-50027, involving a single consultant in Bamako, Mali, who used Claude to support the country's state intelligence service in targeting approximately twenty-five million SIM cards. The system was deployed before Anthropic intervened, and it remains operational. The case illustrates a fundamental limitation: AI companies can revoke access to their APIs, but they cannot undo the deployment of systems built with their technology.

An Iran-linked operation designated GTG-30005 used Claude to collect and analyze publicly accessible data to develop targeting recommendations against US naval forces in the region. The operation connects directly to the report's section on conventional weapons, where AI assists with targeting and military planning.

Conventional Weapons: The Thin Line Between Software and Arms

Six cases involve conventional weapons development, spanning three Chinese operations, two Russian, and one Yemeni. The operations range from guidance software for guided weapons to specifications for undersea warfare systems. GTG-87001, a Yemen-based engineering cell, used Claude to develop guidance software for weapons. GTG-17001, a Chinese operation within a defense contractor ecosystem, drafted fire control specifications for undersea warfare, impersonating an American entity to elicit cooperation from Claude.

A Russian operation designated GTG-27005 attempted to engineer an autonomous military first-person-view kamikaze drone swarm. The operation illustrates how the line between conventional software development and weapons development has blurred. Writing control software for an autonomous drone swarm is, from a technical perspective, not fundamentally different from writing control software for a commercial drone fleet. The intent is what makes it a weapon.

The report acknowledges this ambiguity directly. It notes that Western weapons developers presumably also use Claude for similar tasks, and that distinguishing between legitimate and illegitimate software development becomes increasingly difficult as AI capabilities expand.

Biological Misuse: Less Alarming Than Headlines Suggest

The biological misuse section covers five cases, none of which involved the kind of catastrophic scenarios that dominate public concern about AI and bioweapons. The cases involve researchers conducting dual-use work: a grant application for gain-of-function research, a program engineering highly pathogenic avian influenza, orthopoxvirus research, and two cases involving novel venoms and toxins.

These are legitimate scientific activities that carry inherent risk, not attempts to build bioweapons. The researchers used Claude because AI is useful for ordinary scientific tasks, not because it provided unique uplift for weaponization. The distinction matters for policy. Treating all dual-use biological research as a weapons threat would capture a significant portion of mainstream virology and toxicology.

The Uncomfortable Implications

The report's overall message is that the threat from misuse of closed models is real but manageable, and that the attackers are largely unsophisticated operators who benefit from AI's ability to compensate for their limitations. Sophisticated attacks no longer require sophisticated attackers, which is both the promise and the peril of the technology.

The distillation campaigns present a harder problem. They are not the work of individual bad actors but of state-backed organizations systematically extracting value from a competitor's model while stripping its protections. Addressing this requires coordination between governments and companies, not just technical countermeasures.

The timing of the report coincides with political developments that complicate the response. President Trump declared AI existential risk a hoax, comparing it to climate change and the Russia investigation. The statement forecloses certain policy approaches and makes bipartisan coordination on AI safety more difficult. For companies like Anthropic that have built their business on the premise that AI poses genuine risks requiring genuine safeguards, the political environment is shifting beneath them.

What the report demonstrates, above all, is that the fight over AI safety is not theoretical. It is happening now, in specific operations targeting specific organizations, and the outcomes depend on decisions being made by companies, governments, and researchers in real time.