
Anthropic has released its latest threat intelligence report covering malicious activity detected between December 2025 and August 2026, revealing how AI has transformed from assistant to operator across cyber operations, influence campaigns, surveillance, scams, fraud, conventional weapons and biological research. According to the company's report published on September 10, 2026, the cases involved Claude Haiku, Sonnet and Opus AI models, with the common thread being how AI changes the economics of these operations by allowing tasks previously requiring teams of writers, analysts, programmers or operators to be divided between AI systems and much smaller human teams. The report, titled "Detecting and Countering Misuse of AI: September 2026," runs to 154 pages and covers seven categories of harm including cyber operations, influence operations, surveillance, weapons development, biological misuse, scams and fraud, and illicit distillation.
The most sophisticated example involves an influence-for-hire operation traced to LKM Company, a France-based digital advertising agency, which created approximately 70 fabricated news websites designed to look like independent local publications. The network was connected to roughly 70 matching X accounts and more than 250 additional inauthentic commenting accounts, targeting audiences across six continents. Anthropic found at least 8,913 articles published in around 20 languages, with the system requiring fixed JSON structures, formatted HTML, exact character limits and three to four internal links per article to generate predictable output. The operation showed how AI can remove layers of work from influence campaigns, with the system capable of rewriting the same underlying story for different ideological audiences and adding political angles to neutral stories while moving content across borders. In Bangladesh, an operator in Gaibandha district ran a script named "fake_news_3.py" to generate batches of pro-Awami League headlines and fabricated stories for rural Facebook, YouTube and TikTok audiences, writing in internal notes that "no one knows the news is fake."
Anthropic identified a commercial surveillance operation using Claude to analyze social media activity from users in Iran and the Persian Gulf, mapping users' locations, classifying them into demographic groups and producing Arabic-language intelligence briefings in the style of government reports. The system processed batches of roughly 25 social media posts at a time, determining posters' demographic group, location and political leanings with confidence ratings. Similar automation was found in Iran, where operators used Claude to process hundreds of thousands of social media posts and select 39 opposition accounts for monitoring, and in China, where operators used Claude to score social media and news content for political sensitivity and identify people for what they described as 'control'. One China-aligned operation used Claude to support an attempted recruitment campaign targeting Uyghurs in Syria, drafting outreach in appropriate regional dialects and translating replies in real time. The standout case is Mali, where a single Bamako-based consultant used Claude as the primary engineering workforce to build "Lakana 360," a domestic surveillance platform monitoring roughly 25 million SIM cards across all three national mobile networks, designed to skip the court orders Malian law otherwise requires.
The dating app case reveals how AI is changing online fraud business models, with Anthropic identifying a China-based app studio operating more than 20 dating apps while presenting interactions as human. Over two weeks in April 2026, more than 4,700 AI personas interacted with at least 25,000 people, with Claude generating about 2.36 million messages during the period. The operation divided work by using roughly three AI personas for every real person recruited as a gig worker, with AI handling continuous conversations while humans performed tasks requiring human verification. The app's feed was reportedly 75% Claude personas and 25% real people, with AI personas instructed not to reveal automation and steering conversations through predefined stages. This represents a fundamental shift where humans become verification layers for AI operations rather than maintaining individual conversations.
The bioweapons revelations have intensified existential concerns within the AI industry, with Anthropic researcher Jacob Coxon publicly resigning on September 9 in protest, stating that major AI labs are 'racing straight to self-improving superintelligence and gambling with our lives'. Coxon warned that those building these systems earnestly believe the technology could lead to human extinction by the end of the decade. His claims have been corroborated by senior staff, with Evan Hubinger, Anthropic's Alignment Science Lead, publicly backing Coxon's assessment on X, stating that he personally believes there is a greater than 10% chance that AI will kill all humans within the next decade. The growing internal dissent has amplified across the industry, with AI researchers at OpenAI, Meta and Google parsing Coxon's social media posts and expressing similar concerns. Sam Altman, OpenAI's CEO, wrote in a 2023 blog post that AI could "cause grievous harm to the world," and in recent employee meetings, Altman stated OpenAI was willing to decelerate development alongside rival labs until proper safety standards are established. On Saturday, Amodei published a 3,800-word essay calling for prudence in AI development, stating "We must slow the pace at which we improve the capabilities of models."
Anthropic's economic analysis, published alongside the threat report, projects significant changes to the US economy through 2030 across three scenarios. In the modest scenario, AI affects a fifth of the economy's tasks by 2030 and is used on a fifth of the instances it could handle, with GDP ending up just 1.6% above where it would otherwise be and unemployment barely moving from 3.8% to 3.9%. The substantial scenario shows three-quarters of AI-performed work is fully automated, with GDP 8.3% higher by 2030 and cognitive wages dipping 0.3% below their no-AI path while wages in manual and interpersonal work rise 5.9%. The extreme scenario projects AI automating roughly half of all cognitive work, with GDP 32.4% higher than its no-AI path and cognitive wages falling 11.5% below their no-AI path while wages elsewhere rise 33.6%. The paper's own fix for the extreme case, a transfer worth roughly 9% of GDP, comes with the blunt verdict that transfers of that scale 'have no precedent'. When Anthropic surveyed close to 11,000 US adults in August, the median implied scenario landed almost exactly on the substantial case, not the mild scenario.
The most concerning development involves illicit distillation operations, a fraud-enabled, industrial-scale effort to extract rival model capabilities from seven China-based labs since February. Anthropic alleges that Moonshot AI and DeepSeek are accused of silently routing their own paying customers' queries to Claude, serving Claude's answers back as their own, with Moonshot relaying almost 300,000 customer requests to Claude over ten days and DeepSeek relaying more than 12 million exchanges in a fortnight in July. The scale is massive, with Anthropic attributing more than 151 million exchanges to an Alibaba-linked campaign targeting its Qwen models between May and July, the largest such campaign the company has ever measured. The fallout exposes live credentials from a database linked to Russia's defence ministry, internal specifications for a Chinese tech company's flagship AI programme, and a tool built for a Chinese Public Security Bureau that cross-checks citizens' movements against national ID records. A suspected Russian state-linked actor used AI agents to automatically rebuild and redeploy malware, creating a detection-and-evasion loop that previously took defenders weeks to reopen.