Skip to content

Product1 publisher3 min readPublished

Anthropic ties nine months of disrupted misuse to Haiku, Sonnet and Opus

Anthropic's report names the actors and the Claude tiers behind eight months of disrupted misuse. Google disclosed a bioweapons synthesis request two days before it. Both count cases without publishing totals.

The Product Desk · Product desk

Illustration accompanying Anthropic ties nine months of disrupted misuse to Haiku, Sonnet and Opus

What happened

  • Google said on Tuesday that someone had tried to use Gemini to obtain a complete, step-by-step technical guide for synthesizing weaponised biological agents.
  • Anthropic's report says actors linked to a Russia-based cyber espionage campaign and an Iranian propaganda institution used Claude, alongside cases involving fake dating apps and surveillance aimed at identifying dissidents.
  • One group, whose activity the report describes as consistent with Midnight Blizzard, allegedly used AI to build a system that spotted when its malware was flagged and rewrote the code until it evaded detection.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • capability Because Anthropic says which Claude tiers appeared in the cases and which did not, a security reviewer can write model-tier names into an internal usage standard.
  • constraint With case counts and no total of flagged attempts, nobody outside either company can turn these disclosures into a comparable misuse rate, so procurement gets colour on the threat and no number to price.
  • decision Anthropic's own dual-use framing puts a choice on life-science buyers: the filter that generated five bioweapons case studies is the one their researchers will run into, and the report gives no false-positive figure to weigh.
  • precedent Two providers describing bioweapon-adjacent prompts within the same week sets the expectation that a self-reported abuse log ships with a frontier model. A buyer can ask about its absence.

If you own the AI usage policy at a company with Claude already in production, the usable line in Anthropic's report is the model list. Malicious use was disrupted across Claude Haiku, Sonnet and Opus between December 2025 and August 2026 [5]. None of the misuse cases involved Claude Fable or the Mythos-class models, with the exception of one instance of distillation [6].

That is the level of detail an internal standard is written at. The counts around it stop short of a rate. Eleven of the case studies are weapons-related: five on biological weapons development [7], and six where Claude was used "to develop software for conventional weapons, including firearms, missiles, armed drones, bombs, and other munitions, as well as the targeting and control systems that operate them" [8][22]. There is no published total of flagged prompts or blocked accounts, so eleven counts write-ups and nothing else. The window is soft too: December 2025 through August 2026 is nine months by Anthropic's own dates, while the cases are described as detected over the past eight [24].

Anthropic said biological misuse is "one of the most serious risks of frontier AI model" [14]. Jacob Klein, the head of threat intelligence at Anthropic, told the New York Times it was "an incredibly nuanced situation" [12]. "You are not seeing someone in a comic book kind of way say, 'Hey, I want to build a biological weapon to kill everybody,'" he said [13].

Which matters for anyone buying this for a lab. Anthropic said it had blocked scientists who used its AI in ways that could support biological weapons development [1]. "The same information that can be used to develop a biological weapon could also be used to develop, for example, a vaccine or a cure for a disease," the company said [15]. The control that produced five case studies is the same control a life-science customer's own staff will meet, and the report gives no way to estimate how often it fires on legitimate work.

Google's disclosure two days earlier describes one person seeking a "complete, step-by-step technical guide for synthesizing weaponised biological agents" from Gemini [3][25]. That is a single narrative with no counts attached. The two documents together do not support any comparison of which provider draws more of this traffic or refuses more of it. They support a narrower claim: both providers see it, and both now say so in public.

Three things make the next abuse report from any vendor usable: which model tiers the cases involved, the total number of attempts flagged behind the written-up ones, and which specific product control changed as a result, in language a customer can verify. Anthropic answers the first. On the third, it said it had incorporated its findings into its processes "to better prevent, detect, and disrupt these activities in the future", and that it had shared intelligence with authorities and industry partners where appropriate [16].

What to watch

  • Whether Anthropic's next report publishes totals for flagged prompts and blocked accounts.
  • Whether Google follows with a per-model breakdown for Gemini.
  • Whether enterprise acceptable-use annexes start naming the specific model tiers these reports clear or implicate.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories