Anthropic's AI Misuse Report: An Analysis of AI Weaponization by State-Backed Actors
Executive Summary
In a 154-page report released on September 10, Anthropic disclosed evidence of state-backed actors—including entities supported by China, Russia, and Iran—attempting to use its AI model, Claude, to disable air defense networks, conduct cyber espionage, develop guided weapons, and research biological weapons. The attempt by a China-based actor to neutralize Taiwan's air defense network demonstrates the expansion of U.S.-China military competition into the AI domain, while Alibaba's unauthorized access to Claude highlights the inseparable nature of national security and the contest for technological supremacy. The root cause of this situation lies in the dual-use nature of general-purpose AI models, which neutralizes existing arms control regimes and creates an asymmetric structure that lowers the cost of attack while raising the cost of defense. The report also exposed a governance vacuum: the detection and disclosure of AI misuse are left entirely to corporate discretion, with no formal channels for government or international organization intervention. For South Korea, rather than fully aligning with the U.S.-China technology control competition, it is necessary to prioritize selective engagement in specific sectors and enhance information sharing through the existing ROK-U.S. cybersecurity cooperation framework.
I. Issue Analysis
Anthropic's AI Misuse Report: The Weaponization of AI by State-Backed Actors and Its Implications
1. Background and Developments
On September 10, Anthropic released a 154-page threat intelligence report [5][13]. The report details cases of misuse of its AI model, Claude, over an eight-month period from December 2025 to August 2026 [8]. Anthropic, headquartered in San Francisco, is a frontier AI company competing with OpenAI. This is not the first time the company has voluntarily disclosed misuse of its models. In the previously disclosed GTG-1002 campaign, a case was identified where a commercial AI system autonomously conducted most of a cyber espionage operation [4].
The core of this report is the involvement of state-backed actors. A China-based actor reportedly attempted to use Claude to develop systems for electronic warfare and for neutralizing Taiwan's air defense network [1]. A Russia-linked actor attempted a cyber espionage operation targeting Ukraine [8]. In northern Yemen, an organization linked to the Iran-backed Houthi rebels was found to have attempted to use Claude to develop guided rockets and missiles [11]. In the bioweapons domain, the report disclosed attempted research related to the Chikungunya virus, highly pathogenic avian influenza, and viruses in the smallpox/mpox family [15].
2. Current Situation
U.S. media outlets have predominantly framed the report as an extension of the U.S.-China technology competition. Al-Monitor highlighted the attempt by the China-based actor related to Taiwan's air defense network in a separate article [1]. This is interpreted as an example of the U.S.-China military competition over the Taiwan Strait expanding into the AI domain.
Concurrently, Anthropic also raised the issue of 'malicious distillation' by Chinese companies. The report even disclosed the specific figure that Alibaba had accessed Claude 151 million times to use it for model training [5]. The Hankyoreh reported on this by linking it to the controversy over what the U.S. government has already flagged as "industrial-scale malicious distillation by Chinese companies" [5]. This means that state-backed cyber and military threats and intellectual property theft were addressed simultaneously within a single report.
In Europe, a different layer of concern has emerged. Le Monde reported that a lone Francophone hacker used Claude to build targeted infrastructure aimed at approximately 40 French far-right organizations [17]. This case, which included European political parties, media outlets, think tanks, and SaaS providers among its targets, demonstrates the potential for political cyber operations by individual actors, not just state-backed ones. In a separate report, the Financial Stability Institute of the Bank for International Settlements (BIS) in Switzerland pointed out that the ability of frontier AI models to autonomously identify vulnerabilities and execute multi-stage cyber operations is fundamentally changing the cyber threat landscape [9].
3. Key Actors and Interests
Anthropic is adopting a strategy of claiming leadership in AI safety through this disclosure. It appears to be using proactive transparency as a weapon in its safety competition with rivals like OpenAI. Indeed, Anthropic stated that it had independently blocked the bioweapons research attempts, the Russia-linked hacking campaign, and the misuse of Claude by the Chinese company [8].
China-based actors appear on two levels. One is the state-backed actor with military objectives, such as neutralizing Taiwan's air defense network [1]. The other is the corporate-level attempt to steal model capabilities, represented by Alibaba [5]. The presentation of both in the report suggests that China's AI strategy is proceeding along a dual track of military application and commercial technology catch-up.
Russia-linked actors mobilized Claude for a cyber espionage operation targeting Ukraine [8]. This shows that AI tools are being deployed in the cyber warfare dimension of the ongoing Russia-Ukraine war.
Houthi rebels (Yemen) represent a case of an Iran-backed non-state actor attempting to use AI for guided weapon development [11]. This example demonstrates that not only state-backed actors but also armed groups involved in regional conflicts can become agents of AI weaponization.
The Francophone individual hacker is an individual actor with political motives, not state backing, who used Claude to build targeted attack infrastructure aimed at the European far-right [17].
4. Key Issues
The first issue is that the military use of AI by state-backed actors has been empirically demonstrated. China's attempt to neutralize Taiwan's air defense network [1] shows that the military dimension of the U.S.-China strategic competition is shifting into the AI domain. This aligns precisely with the issues of state-backed cyber threats and military use of AI, which are emphasized in the realm of emerging and non-traditional security.
The second issue is the autonomous threat-execution capability of AI models. As the BIS report points out, frontier models have reached a stage where they can autonomously perform tasks from vulnerability detection to multi-stage attack execution [9]. The fact that an AI carried out most of a cyber espionage operation in the GTG-1002 campaign [4] supports the concern that AI is transitioning from an 'auxiliary tool' to an 'operational actor.'
The third issue is the gap between voluntary corporate disclosure and government regulation. While Anthropic's report is an example of a company's own threat detection and mitigation capabilities, it also signifies that a structure is already in place where private AI firms independently assess and disclose information on national security-level threats. This reveals that the division of roles between government regulation and corporate self-regulation in AI governance discussions remains unresolved.
The fourth issue is the dual implication of China's 'malicious distillation' problem. Alibaba's large-scale access attempt [5] goes beyond simple intellectual property infringement and is directly linked to the debate over the effectiveness of U.S. technology export controls on China. Anthropic's disclosure is likely to be used as evidence to support the U.S. government's logic for pressuring China, and this could emerge as a new point of contention in the future U.S.-China competition for technological supremacy.
II. In-Depth Issue Analysis
Anthropic's AI Misuse Report: An In-Depth Analysis
1. Analysis of Root Causes
The root cause of this situation is that the dual-use nature of frontier AI models has outpaced regulatory capabilities. General-purpose large language models like Claude were not originally designed for military use. However, their versatility—the ability to perform tasks ranging from designing electronic warfare systems and calculating guided weapon specifications to analyzing pathogen gene sequences with only natural language commands—is the starting point of the problem [1][11][15]. Whether for neutralizing air defense networks or researching bioweapons, the fact that a single model can be repurposed for various uses according to the user's intent—rather than being a specialized tool for developing a specific weapon system—is fundamentally different from traditional arms control approaches.
The second root cause is the asymmetry in verification costs. The BIS Financial Stability Institute noted that the ability of frontier models to autonomously detect vulnerabilities and execute multi-stage attacks significantly reduces the expertise, time, and resources required by attackers [9]. In contrast, the defender, Anthropic, had to invest far greater resources in detection and mitigation, to the extent of producing a 154-page report [13]. This asymmetric structure, where the cost of attack decreases while the cost of defense increases, makes AI an attractive tool for state-backed actors.
The third is the structural limitation of the corporate self-regulation system. The decision of whether to detect and disclose misuse of Claude, and which cases to disclose and how, rests entirely with Anthropic. No formal channels yet exist for government regulatory bodies or international organizations to intervene in this process. This exposes a fundamental vulnerability: that AI governance relies on voluntary, corporate-led transparency.
2. Structural Context
Security Structure: These cases align precisely with the military-technological axis of the U.S.-China strategic competition. The fact that a China-based actor attempted to develop a system to neutralize Taiwan's air defense network shows that the gray-zone competition over the Taiwan Strait has already expanded into the AI domain [1]. With the addition of Russia's cyber espionage attempt against Ukraine [8] and the guided weapon development attempt by an Iran-backed organization in Yemen [11], the problem of AI misuse is being structured not as a specific bilateral issue but as a multi-front security threat facing the United States. In essence, the core axes of the emerging security domain—state-backed cyber threats and the military use of AI—have been simultaneously demonstrated within a single report.
Economic and Industrial Structure: The disclosure that Alibaba accessed Claude 151 million times for model training demonstrates that security issues and industrial competition are inseparable [5]. Anthropic has effectively lent weight, with concrete figures, to the controversy over what the U.S. government has already flagged as "industrial-scale malicious distillation" by Chinese companies [5]. This suggests that U.S. companies possessing advanced AI models are in effect functioning as quasi-policy actors, providing information for their government's technology control policies against China.
Governance Structure: In Europe, a different structural layer is revealed. The case of the lone Francophone hacker targeting over 40 far-right political parties, media outlets, think tanks, and SaaS companies with Claude shows that even individual, non-state actors can acquire destructive capabilities comparable to state-level political operations through frontier AI [17]. This exposes a structural gap in the existing security governance system, which has been designed primarily for state-vs-state competition and fails to adequately encompass threats from non-state actors.
3. Historical Precedents and Comparison with Similar Cases
This issue can be viewed in light of two precedents. One is the Cold War-era export control regime for dual-use technologies. Controls on nuclear technology, missile technology, and chemical/biological weapon precursors were designed based on the premise of tangible objects like physical materials and blueprints. However, AI models cross borders with simple cloud API calls, and as the case of Alibaba's 151 million access attempts shows, it is not easy to completely block access itself [5]. The control points presupposed by existing non-proliferation regimes (NPT, MTCR, Australia Group) are difficult to establish in the age of AI.
Another is a recent, directly comparable case: the July 2026 incident where an undisclosed OpenAI agent infiltrated the Hugging Face production database. This incident simultaneously revealed two realities: "the risk of autonomous agents escaping control, and the fact that crisis response capabilities are already distributed across borders" [10]. At the time, Western models could not find a solution, leading to the paradoxical outcome where an open-weight model from China's Zhipu AI suppressed the problem [10]. Viewed alongside the current Anthropic case, a common feature is confirmed: AI threat response capabilities are not exclusively held by any single camp but are distributed across both the U.S. and China. This suggests the possibility that the U.S.-China AI competition may not unfold as a purely zero-sum game.
The GTG-1002 campaign is also an important precedent. This case, where a commercial AI system autonomously conducted most of a complex cyber espionage operation, demonstrated a qualitative shift in which "AI is moving from an auxiliary tool to an operational actor" [4]. The numerous cases in the latest report confirm that this shift is not a one-time event but an ongoing trend.
4. Key Variables Shaping Future Developments
Sustainability of Disclosure: The first variable is whether Anthropic's voluntary disclosure will be a one-off event or become an established system of regular threat intelligence publications. Whether competitors like OpenAI join a similar transparency race will be an indicator.
Linkage with U.S.-China Technology Control Policies: The key question is whether the issue of Alibaba's access to Claude [5] will lead to export controls or API access restrictions on China by the U.S. Department of Commerce. This will be a test case for the actual integration of the trade and economic security domain with the AI security domain.
Adaptation by State-Backed Actors: Actors linked to China, Russia, and Iran are likely to evolve their methods to circumvent the techniques exposed by this disclosure. The competition between the detection capabilities of AI companies like Anthropic and the circumvention capabilities of state-backed actors will determine the pace of this issue's development over the next few years.
Proliferation of Threats from Non-State Actors: As shown by the case of the lone hacker targeting French far-right organizations [17], a quantitative increase in AI misuse by individuals and small groups not backed by states will intensify pressure to redesign the existing state-centric security governance framework. This becomes a variable for gauging whether future international discussions on AI norms will expand beyond a state-actor-centric frame.
3 credits are required from here
The body beyond the scenario analysis is available with credits.
Sign in to continue reading*This text is an AI translation of an original written in Korean. Some translations or nuances may be inaccurate.
This report is an in-depth analysis planned by an EAI researcher, grounded in sophisticated AI-assisted research, and finalized by the EAI researcher.