Artificial intelligence entered our lives with sweeping promises: it would make work easier, help cure diseases and put knowledge within everyone’s reach. Today, we are discussing how that same technology is being used to monitor people, manipulate public opinion and develop weapons. These are no longer merely the plots of science fiction films. They are cases that AI companies themselves are documenting and trying to stop.
Anthropic’s 154-page report, published in September 2026, offers a measure of the threat. The company behind Claude describes operations it says it disrupted between December 2025 and August 2026, ranging from cyberattacks and political propaganda to surveillance and attempts to develop weapons.
One of the most striking cases comes from Yemen. According to Anthropic, users sought Claude’s assistance in developing software for guided rockets. The report also describes an unsuccessful field test. In a separate case in Russia, users worked on software designed to coordinate the movements of multiple drones.
The report also documents research that raised concerns about potential biological weapons applications. According to the company, some users sought Claude’s help with work that could make viruses more dangerous. It does not, however, provide evidence that these efforts resulted in the production of a biological weapon.
The danger lies in making specialist work—research, calculations and software development—easier to carry out. As the time needed to advance a project falls, groups with limited expertise may gain greater scope to experiment. Not every attempt has to succeed for the threat to grow. Giving those intent on causing harm more opportunities to try is itself a serious security concern.
AI Makes Repression and Manipulation Easier
The surveillance cases are equally troubling. According to Anthropic, users in Iran whom it assessed to be linked to security bodies used Claude in systems that brought together individuals’ identity details, beliefs and social media accounts. In Mali, Claude was used to develop a system that compiled dossiers on people using their phone numbers. A safeguard requiring a check for judicial authorization before generating a dossier was also removed.
The spread of such systems could make it easier to build detailed profiles of people, faster and on a much larger scale. A social media post, a phone call and a membership record may each seem unremarkable in isolation. Combined, they can reveal intimate details of a person’s life. When the system makes a mistaken connection, it is the person placed under suspicion who bears the consequences. A journalist’s contact with a source, a citizen’s political views or a community’s religious beliefs can become grounds for repression when those collecting the information face no meaningful oversight.
Attempts to manipulate public opinion present a related challenge. The report describes a network of fabricated news outlets that published at least 8,913 articles in roughly 20 languages. It also notes that the network’s reach among real readers remained limited. Producing large quantities of content is not the same as persuading the public.
Nevertheless, as falsehoods become cheaper to produce, establishing the truth becomes more costly. A claim can circulate in several languages within minutes, while checking it may require hours of research. By the time a journalist has located the relevant documents, witnesses and sources, dozens of new versions of the same falsehood may already have appeared.
A more corrosive consequence is the possibility that people will cease to believe anything at all. Authentic footage of an attack, evidence of corruption or a victim’s testimony could be dismissed with a simple suggestion: “It could be AI-generated.” Such an environment serves not only those spreading lies, but also those seeking to conceal what they have done.
Anthropic’s report should itself be read critically. The company is disclosing dangerous uses of its product while also seeking to demonstrate that it is taking action against them. Its account should therefore not be accepted without scrutiny. Detecting an attempt does not establish that harm was prevented. Closing an account may not stop the same user from returning under another identity. Independent experts should also assess whether the safeguards are effective.
Simply telling people to be careful is no answer. No individual can investigate every message, news story or image they encounter. AI companies must explain clearly what they are doing to prevent misuse. Governments must oversee those companies and protect people’s rights. Yet security must not become a pretext for subjecting everyone’s private life to surveillance.
AI’s growing capabilities are a source of excitement. But we must also consider what those capabilities make possible for a fraudster, an attacker or a government determined to silence its critics. Machines do not have to turn against humanity for the danger to become real. Making it easier for people to harm one another is enough.
When someone’s life is ruined, their private information stolen or a crime they did not commit pinned on them, “AI did it” must not become an excuse. Artificial intelligence may have no conscience. Those who develop it, use it and are responsible for overseeing it cannot evade accountability.