TL;DR

Anthropic’s latest misuse disclosure spans eight months and seven categories of harm, from surveillance tooling to weapons software. Its sharpest finding concerns distillation: several Chinese labs sent their customers’ requests to Claude without telling them, exposing names, company files and credentials. For UK businesses reaching models through routing intermediaries, that is a supplier risk, not merely a US-China quarrel.

What the report covers

The report, published on 10 September, details operations Anthropic disrupted between December and August, grouped under cyber, influence campaigns, surveillance, fraud, biology, conventional weapons and distillation. Nearly all ran on Haiku, Sonnet or Opus; Fable and Mythos-class models figured in a single distillation case.

On biology, Anthropic offers five case studies and says that, to its knowledge, no private company has published this kind of evidence before. In one, a reseller serving roughly twelve clients used Opus 5 to write a full orthopoxvirus immune-evasion grant proposal in roughly an hour. Institutions and countries are withheld, and the company stresses it is not accusing the scientists of intending harm.

Six weapons cases follow. Russia accounts for two and China for three, while in Yemen one cell’s rocket guidance software got as far as outdoor testing. A companion Frontier Red Team evaluation finds models improving steadily on simulated targeting and weapons-engineering tasks.

The distillation numbers

Seven China-based labs were caught harvesting Claude’s output to train competing models. Alibaba’s campaign was the largest Anthropic has measured, peaking near 3 million exchanges a day through more than 3,500 fake accounts. Over one ten-day stretch Moonshot forwarded nearly 300,000 requests from its own users to Claude, while those users believed Kimi was answering; DeepSeek and Xiaomi ran comparable relays.

That goes further than the White House accusation against Moonshot in July. The forwarded sessions held names, email addresses and corporate material belonging to hundreds of people, in a dozen or more languages, and many arrived via model routers popular in the US and Europe. Anthropic concedes the practice is likely at odds with privacy law.

Looking forward

For UK firms the lesson sits in the supply chain. A developer choosing a cheap model through an aggregator may be handing code, credentials and client documents to organisations nobody contracted with. UK GDPR due diligence assumes you know who processes your data; these cases show that assumption failing silently.

Anthropic is also marking its own homework. The disclosures showcase safeguards that work, and they land weeks before its expected stock market listing. The detail is extensive, but none of it has been independently verified.