Home World News Bad actors in China and Russia are already weaponizing...
World News

Bad actors in China and Russia are already weaponizing Anthropic’s AI

Key Points

Artificial intelligence threats that might have seemed like science fiction nightmares just a year ago are much closer to reality today, according to AI powerhouse Anthropic. And some may already be here. In a lengthy new report out Thursday, Anthropic said that criminal hacking gangs, Chinese security bureaus, Russia-linked spies and Yemen-based arms manufacturers, among others, have exploited a web of fraudulent accounts and online services to access some of the...

Killer drones. Mass surveillance. Bioweapons.

Artificial intelligence threats that might have seemed like science fiction nightmares just a year ago are much closer to reality today, according to AI powerhouse Anthropic. And some may already be here.

In a lengthy new report out Thursday, Anthropic said that criminal hacking gangs, Chinese security bureaus, Russia-linked spies and Yemen-based arms manufacturers, among others, have exploited a web of fraudulent accounts and online services to access some of the company’s advanced AI assistants, known as Claude.

And they’re using those tools to attempt attacks or design weapons that previously lay beyond their capabilities.

In the last eight months alone, Anthropic said, people in countries where Claude should be restricted circumvented those controls to automate cyberattacks, try designing advanced military hardware, spread propaganda at scale and mount broad digital surveillance campaigns. Though Claude models are broadly available commercially, Anthropic tries to restrict access in major U.S. adversaries, including Russia, China and Iran.

The AI giant also said it uncovered five cases this year where scientists in unspecified foreign countries used their models to research dangerous pathogens, work that may have been conducted as part of a bioweapons program.

At a time when lawmakers, the Trump administration and Silicon Valley are grappling with the safety risks of the most advanced models — some of which have not been publicly released — the nearly 150-page report is a stark reminder that more widely available AI systems are powerful enough as is to cause harm in the wrong hands.

“We’re not trying to be hyperbolic here. We just want to present to the world: Here’s what the technology can actually be misused for today,” Jacob Klein, the head of threat research at Anthropic, said in an interview ahead of the report’s release.

In the report, Anthropic said it has moved to disrupt every case detailed Thursday, and reported them to relevant governments and industry groups. It also said it has worked to strengthen its safeguards around affected versions of Claude, including Sonnet, Opus and Haiku. Bad actors were able to access the models using virtual private networks and fraudulent or stolen accounts to mask where they were coming from, the company said.

It added that much of illicit access was facilitated by intermediaries who help customers circumvent the geographic restrictions and internal safety filters built into top U.S. AI models.

Klein clarified that none of the incidents detailed in Thursday’s report involved Anthropic’s most powerful AI model, Claude Mythos, which is so adept at spotting flaws in software that the company has tightly restricted access to trusted partners, mostly in the U.S.

Still, the report highlights how recent advances in the capabilities of AI have turned threats that once seemed outlandish into reality.

“Some cases of misuse that used to be hypothetical are now real,” Klein said.

In one of the possible bioweapons cases, Anthropic said a scientist used Claude to help write a grant application involving gain-of-function research into a deadly mosquito-borne virus. Though the research could be used to develop more effective vaccines, Anthropic acknowledged, the activity was “a cause for concern” because the grant would have been performed at a military research institute.

In another, a scientist who appeared to be working for a state-supported program used Claude to research compounds that “can simultaneously be developed into novel therapeutics or toxic agents.” And in a third, a researcher outside the U.S. “spent weeks” using Claude to research experiments involving adaptations in a highly pathogenic avian influenza.

Anthropic said it was not identifying the individuals, institutions or countries involved because it could not conclude if the requests constituted legitimate scientific research or not — a line they acknowledged was difficult to adjudicate.

But they said the attempts were worrying because the researchers circumvented geographic restrictions to access Claude and undertook “efforts to obfuscate the purpose of their research to evade our safeguards.”

The report also documented some of the first known cases where AI was used to help design advanced military hardware and run mass digital surveillance operations.

Anthropic said it stopped “a cell of threat actors based in Northern Yemen” who had been using Claude in a trio of weapons development programs, including a guided rocket, a multi-stage ballistic missile and a hypersonic glide missile. It also said it identified a “freelance” Russia-based threat actor that tried using Claude to build drones capable of autonomous kamikaze attacks.

Anthropic said Iranian and Chinese state actors used Claude to analyze reams of domestic social media content to pinpoint potential dissidents and surface politically sensitive content.

In Mali, a single consultant working for the country’s security authorities used Claude to code “a mass-interception platform capable of surveilling communications on all of the country’s mobile operators and generating dossiers on targets,” it said.

The report details a number of cases involving the misuse of Claude in criminal and state hacking operations, including by Russia-linked groups. Overall, Anthropic said using AI has become so common for hackers that even the most low-level groups now automate broad swathes of their work.

Anthropic also identified nine influence operations originating in countries like Russia, Turkey and Iran that were allegedly undertaken by a mix of private and state actors. Anthropic said several of the campaigns, which targeted audiences across six continents, were timed to national elections in countries including Moldova and Kenya.

But the company emphasized in its report that most of the AI-generated content associated with the influence operations it caught “drew little or no authentic engagement” before they were disrupted — the same caveat OpenAI and X have shared in disclosing influence operations that proliferated on their platforms.

Anthropic has tried to position itself as the most safety-conscious U.S. AI lab, though some critics allege it overhypes the risk of AI in order to spur regulation that would inhibit upstarts and competitors.

Anthropic said it was publishing Thursday’s report because it felt an obligation to do so and because it wanted to give governments and civil society “a clearer view of how emerging threats take shape, and strengthen collective defenses across the industry.”

Those in Washington and Silicon Valley may not need the reminder.

After one Anthropic researcher quit this week in protest of the AI industry’s race to build increasingly powerful models, a top scientist at the company wrote online that many AI safety staffers “earnestly believe” there is roughly 10% chance AI “could kill all humans” in the next decade.

That led to a series of urgent pleas from lawmakers on Capitol Hill this Wednesday for new and aggressive safety regulations over the AI industry.

Jacob Wendler contributed to this report.

China (LOCATION) Russia (LOCATION) AI Killer (PERSON) AI (ORG) Chinese (ORG) Yemen (LOCATION) Anthropic (PERSON) Claude (PERSON) access in (PERSON) U.S. (LOCATION) Iran (LOCATION) Trump (ORG) Silicon Valley (LOCATION) Klein (PERSON) U.S. AI (LOCATION)
Originally published by Politico EU Read original →