Skip to main content
  • Home
  • Tech
  • “From Weapons Development to Cyberattacks”: AI Misuse Becomes a Reality in China and Russia as U.S. Bolsters Safety Defenses Ahead of U.S.–China Summit

“From Weapons Development to Cyberattacks”: AI Misuse Becomes a Reality in China and Russia as U.S. Bolsters Safety Defenses Ahead of U.S.–China Summit

Picture

Member for

1 year 9 months
Real name
Tyler Hansbrough
Bio
[email protected]

As one of the youngest members of the team, Tyler Hansbrough is a rising star in financial journalism. His fresh perspective and analytical approach bring a modern edge to business reporting. Whether he’s covering stock market trends or dissecting corporate earnings, his sharp insights resonate with the new generation of investors.

Modified

Anthropic’s Claude used in weapons development, cyberattacks and biological experiments
“Safety and alignment paramount” consensus gains ground across U.S. AI industry
U.S. flags unauthorized distillation by Chinese firms as attention turns to this month’s summit

Advanced U.S.-made artificial intelligence (AI) models have reportedly been misused by government-linked organizations and criminals in countries including China and Russia. Anthropic’s generative AI model Claude was allegedly deployed for △missile and loitering-munition development △cyberattacks △influence operations and △research with potential biological-weapons applications. As rapidly advancing AI capabilities amplify the risk of misuse in the military and cyber domains, calls are spreading across the U.S. industry and beyond to moderate the pace of model development and strengthen safety and alignment frameworks. The U.S. government has likewise begun publicly challenging unauthorized distillation and access-circumvention practices by Chinese AI companies, elevating AI safety and technological misuse into core issues between the two countries.

Cases of Misuse Involving Anthropic’s AI Models

On Sept. 10 local time, Anthropic published its “AI Misuse Detection and Reporting” report, disclosing the findings of an investigation into cases in which Claude was misused between December last year and August this year. The most immediate threat involved weapons development. Anthropic said it had identified six cases in which Claude was used to develop conventional weapons such as missiles and loitering munitions: three in China, two in Russia and one in Yemen. An armed group in northern Yemen developing a multistage ballistic missile with a range exceeding 2,000 km and a hypersonic glide vehicle tasked the AI with writing flight-control software. The group subsequently conducted an actual test launch of a guided rocket, but the test failed. Several hours later, it fed the flight data back into the AI and asked it to analyze the cause of the failure.

In China, one organization used AI to design torpedo-defense fire-control software for submission to the People’s Liberation Army Navy and drafted a technical proposal exceeding 200 pages. Another Chinese organization used AI to create 16 software modules for electronic warfare and the suppression of air-defense networks, then ran simulations targeting 12 real-world facilities in Taiwan, including command bunkers and early-warning radars. In Russia, unidentified developers were also found to have used AI to develop autonomous attack-drone swarm software capable of identifying people and issuing attack commands without human intervention.

Biological-Weapons Threats Come to the Fore

Five research cases were also identified as having the potential to be misused for biological weapons of mass destruction. In one case, a researcher in a region where the service is unavailable worked with Claude over several weeks to design experiments involving avian influenza. Anthropic said its safety filters were activated, limiting the work to its least capable model. Another researcher was detected while attempting to use AI to draft a grant application for research aimed at increasing the transmissibility and immune-evasion capabilities of the mosquito-borne chikungunya virus. Anthropic emphasized that it could not determine whether the scientists in the disclosed cases intended to cause harm, but said it had suspended all accounts mentioned in the report.

Claude was also actively deployed in cyberattacks. A Russia-linked hacking group used AI to automate a phishing program targeting the Ukrainian government and military. The system was designed so that whenever malware was detected, the AI would automatically modify the code and redeploy it. A Chinese government-linked organization used AI to track and recruit Uyghurs and members of Uyghur militant groups in Syria. Evidence also emerged that it was preparing an AI-enabled influence operation to monitor journalists in the Uyghur diaspora and undermine the credibility of their media outlets. Anthropic explained that in many of the operations it identified, humans set the objectives and reviewed the material collected, while AI performed a substantial share of the actual work.

Alarm Mounts Across the U.S. AI Industry

Chinese organizations involved in these operations were found to have disguised their access locations by routing connections through intermediary servers in the United States, Japan and Singapore to circumvent restrictions on Claude. When creating accounts, they used fabricated identities, disposable email addresses and virtual or stolen credit cards. If a particular account was detected and blocked, they immediately created another using a new email address and payment method, allowing them to maintain access. Anthropic warned that “AI misuse is becoming organized through a combination of server circumvention and repeated account creation,” adding that “as AI models become more powerful, the risks will increase unless developers and society strengthen safeguards accordingly.”

Such concerns extend well beyond Anthropic and are being raised throughout the U.S. AI industry. On Sept. 12, Anthropic Chief Executive Officer (CEO) Dario Amodei published an essay titled “We Must Pace the Frontier” on his website, arguing that “we need to slow the rate at which AI model capabilities improve.” Amodei said, “This does not mean halting model training or technological progress. It means ensuring that companies have enough time to ‘align’ their models and make them safe.” He added, “If we can secure an additional one to two years before models reach critical capability thresholds and use that time to advance alignment, we can significantly reduce the risk of severe problems arising.” Alignment refers to the process of ensuring that AI remains within safety guardrails and follows human intentions and instructions.

U.S. Government Takes Notice of the Risks

Other leading figures in the AI industry also rallied behind Amodei’s position. OpenAI CEO Sam Altman, widely regarded as one of Amodei’s most prominent adversaries, reposted Amodei’s essay on the social media platform X, formerly Twitter, writing, “I agree with Amodei,” and adding that “the proposal to appoint independent evaluators with the same access privileges as employees is a very good idea.” In an interview with Fortune, Altman had also said, “Given everything surrounding AI safety, I do not think it would be wise to announce an IPO at this time,” adding that “there is still much to be done, including meeting the requirements for safety and alignment and determining how industry and government can work together.” Tesla CEO Elon Musk, who has frequently criticized Amodei’s comments for provoking unnecessary alarm, also recently wrote on X that “Dario is right.”

The U.S. government is also stepping up its response, treating the potential misuse of AI as a national-security risk. In its “2026 Annual Threat Assessment,” released in March, the Office of the Director of National Intelligence (ODNI) identified China as the most active and persistent cyber threat targeting the U.S. government, private sector and critical infrastructure, while characterizing Russia as a persistent and sophisticated cyber and intelligence threat. It further assessed that advances in AI could improve the speed and efficiency of cyberattackers’ operations and could also be applied to weapons and systems design, target selection and decision-making. The Trump administration likewise stated in a June executive order that advanced AI could create new national-security risks. It instructed the Committee on National Security Systems (CNSS) to prioritize the cyber defense of national-security systems and directed the Department of Homeland Security to reinforce the protection of civilian federal information systems through the Cybersecurity and Infrastructure Security Agency (CISA). The attorney general was also ordered to strengthen federal enforcement against unauthorized intrusions into public and private information systems using AI and the unlawful acquisition of data through AI agents.

Table 1. U.S. Government Measures to Counter AI Threats Originating from China

AreaKey Measure
Threat assessmentDesignation of China as a major cyber threat targeting the U.S. government, private sector and critical infrastructure
Cyber defenseStrengthening of defenses for national-security systems and federal government information systems
Law enforcementExpanded federal enforcement against AI-enabled unauthorized intrusions and data theft
Scrutiny of Chinese companiesDisclosure of large-scale distillation activities by six Chinese AI companies, including DeepSeek, Moonshot AI and Alibaba
Technical countermeasuresRecommendation to apply differential privacy techniques or lower-capability models to suspicious accounts
Source: Office of the Director of National Intelligence, National Security Agency, Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency

Tensions Rise Ahead of U.S.-China Summit

As tensions surrounding the AI industry intensify, some observers expect the issue to reach the negotiating table at the U.S.-China summit scheduled for later this month. On Sept. 8, the National Security Agency (NSA), Federal Bureau of Investigation (FBI) and CISA issued a joint cybersecurity advisory, AA26-251A, titled “Industrial-Scale Distillation Campaigns by China-Based Artificial Intelligence Companies Against U.S. AI Firms.” The advisory named six companies: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Zhipu AI (Z.AI). With the summit only weeks away, the agencies formally raised the issue while identifying the companies directly. Distillation refers to a technique in which large volumes of questions are submitted to a high-performance AI model, its responses are collected and the resulting material is used as training data to improve another model.

U.S. authorities alleged that since at least late 2024, the companies had sent millions of requests to U.S. frontier models—including OpenAI’s GPT, Anthropic’s Claude, Google’s Gemini and xAI’s Grok—and extracted billions of tokens. The authorities argued that this went beyond merely referencing another AI system’s responses and amounted to the systematic use of capabilities built by U.S. companies through substantial research and development (R&D) spending and computing resources to develop Chinese models. While acknowledging that distillation itself is a legitimate and useful research technique, officials concluded that the methods and scale of the Chinese companies’ access were problematic. According to the advisory, the Chinese AI companies distributed requests across multiple accounts and access routes to circumvent anomalous-transaction detection systems. Their proxy networks managed tens of thousands of fraudulent accounts and mixed distillation requests with ordinary user traffic to evade detection. To minimize such access, U.S. authorities proposed that AI companies alter the responses provided to accounts suspected of conducting distillation. For requests assessed with high confidence to be malicious distillation activity, companies were advised to apply differential privacy techniques or respond with lower-capability models, thereby reducing the value of the output as training data.

Picture

Member for

1 year 9 months
Real name
Tyler Hansbrough
Bio
[email protected]

As one of the youngest members of the team, Tyler Hansbrough is a rising star in financial journalism. His fresh perspective and analytical approach bring a modern edge to business reporting. Whether he’s covering stock market trends or dissecting corporate earnings, his sharp insights resonate with the new generation of investors.