Anthropic’s latest threat intelligence report, released September 10, 2026, reveals a fundamental shift in the cyber-threat landscape: the “labor gap” between individual operators and well-funded nation-states is rapidly disappearing. By introducing a metric called “Uplift,” Anthropic’s Detecting and countering misuse of AI report quantifies how AI tools allow malicious actors to achieve scale and technical depth that previously required entire intelligence agencies.

Biological Research and Kinetic Ambition
The report details attempts to use AI for kinetic and biological warfare. Anthropic intervened in five distinct cases where users attempted to utilize Claude for research into biological weapons, including gain-of-function studies and bird flu adaptation. In Yemen, an individual used “Claude Code” skills to attempt the development of rocket guidance software, even returning to the AI for troubleshooting advice after a failed physical test flight.
Industrial-Scale Scrapers and Fraud
The report also accuses several prominent Chinese AI labs of engaging in “industrial-scale distillation.” According to a Reuters report cited by Anthropic, entities including Alibaba, DeepSeek, Moonshot, Xiaomi, Zhipu, SenseTime, and MiniMax allegedly used thousands of fake accounts to harvest Claude’s outputs. The goal of this scraping was to use Anthropic’s proprietary logic to train and “distill” their own competing models.
The use of AI to simulate human behavior at scale has also transformed low-level cybercrime. Anthropic identified a China-based scam operation that used Claude to power more than 4,700 fraudulent personas on dating apps. These automated accounts exchanged 2.36 million messages with real users, demonstrating how AI can maintain personal, high-frequency engagement that was previously impossible without a massive human “click farm” operation.
Anthropic notes that while its safety filters successfully blocked many of the more egregious attempts—particularly in the biological and kinetic categories—the “Uplift” provided to low-skill actors remains a primary concern for the security community. The ability for actors to achieve significant technical depth suggests that traditional defensive models focused on the scarcity of high-level hacker talent may no longer be sufficient.
