Pay Attention: We are Under Attack

Segment #1033

Bad Actors in China and Russia Are Already Weaponizing Artificial Intelligence

The AI-risk debate has changed. It is no longer confined to hypothetical fears about a future superintelligence escaping human control. Anthropic now says it has detected and disrupted foreign scientists, hackers, military-linked organizations and security services using Claude for potentially dangerous work—including biological experimentation, cyberespionage, surveillance, weapons engineering and influence operations. The evidence indicates that adversaries are already circumventing geographic restrictions, creating fraudulent accounts and manipulating safeguards to gain access to advanced American AI.

Anthropic reported several especially troubling cases:

  • Researchers in a restricted country used Claude to plan experiments involving the chikungunya virus, including work potentially intended to increase transmissibility or evade immune defenses. Claude also helped prepare a grant application for the research. Anthropic characterized it as possible biological-weapons-related activity and terminated access.

  • Russian state-linked hackers reportedly used Claude to assist cyberattacks against Ukrainian officials. The model helped automate reconnaissance, phishing, malware development and methods intended to evade detection.

  • Russia-based users sought help developing autonomous drone-swarm software and locating dual-use components.

  • China-based actors used Claude for military and surveillance research, reportedly including targeting software, anti-torpedo systems and other weapons-related technologies.

  • Chinese AI laboratories allegedly created thousands of fraudulent accounts and made enormous numbers of automated requests to Claude in attempts to extract—or “distill”—its advanced reasoning capabilities into Chinese models.

  • A Yemen-linked group reportedly used Claude for missile-control software, navigation code and analysis of failed weapons tests.

These findings do not establish that Claude independently designed a successful biological weapon, missile or battlefield system. Much of the activity involved research assistance, coding, troubleshooting, planning and the synthesis of existing knowledge. But that distinction should not be comforting. AI’s immediate military value may be its ability to make existing specialists faster, reduce the number of people required for sophisticated projects and allow less capable organizations to perform work previously requiring larger teams of experts. Reuters and the Associated Press summarize the cases disclosed by Anthropic.

The warning from former OpenAI and Anthropic researcher Jacob Coxon belongs in the same discussion, but it should not be confused with Anthropic’s threat report. Coxon’s resignation focused primarily on the longer-term danger of companies racing toward self-improving, superhuman AI without reliable means of controlling it. Anthropic’s report supplies evidence of a different and more immediate threat: existing models being deliberately exploited by human adversaries. Coxon’s warning concerns what an advanced AI might eventually do on its own; Anthropic’s evidence concerns what hostile governments, laboratories and criminal organizations are doing with AI now.

The resulting risk assessment has three levels:

  1. Present danger: Human bad actors use AI to accelerate hacking, surveillance, propaganda and weapons research.

  2. Near-term danger: More capable AI agents could conduct longer and more complex operations with decreasing human supervision.

  3. Catastrophic danger: A future system could acquire the capacity to evade oversight, replicate, improve itself or independently manipulate critical infrastructure and biological systems.

The most important conclusion is that safeguards built into a chatbot are not a complete defense. Determined state actors can use intermediaries, stolen identities, distributed accounts, modified prompts and locally hosted models. Even if American companies successfully block their own systems, knowledge extracted from those systems may be transferred into foreign models that operate without comparable restrictions.

Anthropic deserves credit for detecting and disclosing these operations, but the report also demonstrates the limitations of voluntary corporate policing. Private companies are now making decisions that directly affect biological security, military technology and international espionage. That demands stronger identity verification for access to frontier models, continuous monitoring for coordinated abuse, strict controls over high-risk biological and weapons-related capabilities, mandatory reporting of serious incidents, protection for employees who expose safety failures and coordinated security standards among American AI laboratories.

The danger is no longer simply that AI might someday become uncontrollable. The immediate reality is that hostile actors are already attempting to turn American AI systems into force multipliers—and every improvement in capability potentially increases what those actors can accomplish.

Next
Next

Robots Will Destroy Civilization?