Anthropic Reports Adversaries Bypassing Claude AI Restrictions
Chinese, Russian, and Iranian actors exploited fraudulent accounts to access the company's AI models for weapons research, cyberattacks, and surveillance.
Anthropic has disclosed that state actors and criminal groups from U.S. adversary nations have systematically bypassed geographic restrictions to access its Claude AI models for dangerous applications, including possible bioweapons research, autonomous weapons development, and mass surveillance programs.
In a nearly 150-page report released Thursday, the AI company documented cases involving Chinese security bureaus, Russia-linked operatives, Iranian state actors, and Yemen-based arms manufacturers who used virtual private networks and fraudulent accounts to mask their locations and access Claude models that should have been restricted in their countries.
Bioweapons Research and Military Hardware
Anthropicidentified five cases this year where scientists in unspecified foreign countries used Claude to research dangerous pathogens in what may have been bioweapons programs. In one instance, a scientist used the AI to help write a grant application for gain-of-function research on a deadly mosquito-borne virus at a military research institute. Another researcher used Claude to study compounds that could serve as either therapeutics or toxic agents, while a third spent weeks researching adaptations in highly pathogenic avian influenza.
The company also documented weapons development cases, including a cell in northern Yemen using Claude for guided rockets, multi-stage ballistic missiles, and hypersonic glide missiles. A Russia-based actor attempted to design autonomous kamikaze drones using the AI assistant.
Surveillance and Influence Operations
Iranian and Chinese state actors deployed Claude to analyze domestic social media content at scale, identifying potential dissidents and politically sensitive material. In Mali, a single consultant working for security authorities used Claude to code a mass-interception platform capable of surveilling all mobile communications nationwide and generating target dossiers.
Anthropicidentified nine influence operations from countries including Russia, Turkey, and Iran, with several campaigns timed to national elections in Moldova and Kenya. However, the company noted that most AI-generated content in these operations drew minimal authentic engagement before disruption.
Why It Matters
This disclosure reveals that commercially available AI systems—not just unreleased frontier models—already possess sufficient capability to enable serious security threats when accessed by sophisticated adversaries. The report demonstrates how intermediaries are creating a shadow market to help restricted users bypass geographic controls and safety filters, turning theoretical AI risks into documented incidents. For policymakers debating AI safety regulations, the findings provide concrete evidence that current safeguards can be circumvented and that dual-use AI technology is actively being weaponized.
Industry Response
Jacob Klein, Anthropic's head of threat research, emphasized the company wanted to present what the technology can actually be misused for today rather than hypothetical scenarios. Anthropic reported all documented cases to relevant governments and industry groups and has strengthened safeguards around affected Claude versions, including Sonnet, Opus, and Haiku.
None of the incidents involved Claude Mythos, Anthropic's most powerful model, which remains tightly restricted to trusted U.S. partners due to its advanced capability to identify software vulnerabilities.
The findings were first reported by Politico, which noted the disclosure comes as lawmakers pressed for aggressive AI safety regulations following warnings from Anthropic scientists about existential risks from increasingly powerful models.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call