AI erases gap between state spies and lone attackers

Untitled design (3)

On 10 September 2026 the US firm Anthropic published its most detailed account yet of how governments, criminals and activists have tried to turn its Claude models to hostile ends. The report covers activity the company says it detected and disrupted between December 2025 and August 2026 across seven areas: cyber operations, influence operations, surveillance, scams, biological research, conventional weapons and the theft of AI capabilities. Its findings read less like a corporate security notice than a map of the fault lines running through great-power competition.

Sophistication is no longer a state prerogative

The report’s central claim is a geopolitical one. For decades, the capacity to run sustained, multi-target intelligence and cyber operations marked out well-resourced states. Anthropic argues that AI has collapsed that gap. “The main distinguishing feature between these classes of actors is no longer sophistication but intent,” it states. A lone hacktivist using stolen keys, a financially motivated crew and a state espionage unit were each shown running campaigns that, a year earlier, would have needed teams of trained operators.

If accurate, the implication cuts against assumptions underpinning export controls and deterrence, which treat advanced offensive capability as scarce and state-held. The report suggests the scarce input is now willingness, not skill.

Russia, China and Iran anchor the state cases

The named state activity tracks familiar geography. Anthropic attributes one espionage operation, consistent with public reporting on the group known as Midnight Blizzard, to Russian state-nexus actors who targeted Ukrainian and European government, diplomatic and defence bodies, with a recurring focus on military drone supply chains. A separate Russia-based team, which the company assesses to be freelance rather than state, used Claude to engineer software for an autonomous kamikaze drone swarm, testing code on real hardware and using a fixed coordinate in Donetsk Oblast as its demonstration strike point.

Chinese-linked cases concentrate on surveillance and weapons software. Anthropic describes PRC-aligned operations that profiled Uyghur, Tibetan, Falun Gong and Hong Kong pro-democracy targets, produced “situational awareness” briefings on overseas dissidents, and in one case sought venue details for a lawful protest in Vancouver — the machinery of transnational repression, automated. Other China-based actors used the model to draft an anti-torpedo fire-control specification and to build targeting software for electronic warfare, at one point switching the default scenario to 12 targets in Taiwan.

Iranian cases span domestic surveillance tooling, malware, naval reconnaissance against US forces and influence work tied to state propaganda bodies. Beyond the three, the report reaches into a Gulf information operation against the Muslim Brotherhood, a Mali state surveillance platform monitoring some 25 million SIM cards, and a guided-weapons cell in northern Yemen that test-fired a rocket, then returned to Claude within hours to work out why it failed.

Elections and the information environment

Several influence operations were timed to national votes — Russian state media targeting Moldova’s president before its September 2025 election, and operators preparing material ahead of elections in Kenya, Malaysia and Bangladesh. Anthropic notes that most such content drew little authentic engagement, and that the widest reach came where established state broadcasters carried it. That is a caution against overstating AI’s persuasive power, even as the tooling to manufacture fake newsrooms and personas becomes cheap.

The AI supply chain becomes contested terrain

The report’s most pointed geopolitical section concerns the models themselves. Anthropic accuses seven China-based AI labs of “illicit distillation” — covertly extracting Claude’s reasoning to train rival models. It attributes more than 151 million exchanges to operators linked to Alibaba between May and July 2026, and names DeepSeek, Moonshot, Zhipu, Xiaomi, SenseTime and MiniMax. In some cases, the company says, firms silently routed their own users’ requests to Claude, exposing sensitive data — including, in relayed sessions, Chinese police surveillance work and Russian defence records — to a US provider without users’ knowledge.

Here the frontier model is not a weapon but the prize: a contest over who captures the capabilities that Washington’s export controls were designed to keep scarce. The named firms had not publicly responded to the specific allegations at the time of writing.

A private firm with a state’s-eye view

Running through the report is an unusual fact. Because Anthropic sits at the point where operations are built rather than deployed, it can see campaigns while they are still being assembled — a vantage, it notes, that “even governments and intergovernmental organizations lack.” In the biological cases it withheld countries, institutions and agents, citing risk to the researchers involved.

That visibility is itself a geopolitical development. Intelligence about state behaviour, once the preserve of national agencies, increasingly accrues to a handful of private companies whose commercial interests, jurisdiction and disclosure choices shape what the public learns. Anthropic frames the report as an invitation to governments and industry to respond. It also, quietly, marks the arrival of the AI developer as a party to international security — reporting on states, sharing with authorities, and deciding for itself what to reveal.