AI Security Threats Aren’t a Hoax—But They Also Aren’t as Existential as They Might Seem

Public alarm is running high over AI. And why shouldn’t it be? Last week, Anthropic published a report on the misuse of its AI models by malicious actors, where examples of bioweapons research and using AI to track U.S. naval movements in the Gulf have captured public attention. Add to the mix recent incidents of AI agents escaping their testing environments and the high-profile resignation of an AI researcher out of concern that AI might kill humans and it becomes clear why public sentiment feels rooted in fear of AI’s impact on humanity, captured in headlines about the “AI Doomsday Threat” and “America’s Great AI Freakout.” By contrast, President Donald Trump labelled these threats a “hoax,” while David Sacks, his AI adviser, attributed public panic to an “orchestrated media campaign.” So, what should the public think?

These concerns about the urgency and pace of the threat are real—but perhaps slightly misdirected. From a national security perspective, the abuses of AI outlined in Anthropic’s report are legitimate but not especially new or surprising: In fact, they are remarkably consistent with how threat actors already behave, using AI to enhance the speed, scale, efficacy, and reach of their operations. What is alarming is the presence of far less skilled or mature actors misusing AI, such as militant rebels or hacktivists: AI models give them a significant uplift, enabling them to skip vital steps of developing, acquiring, and refining these capabilities. There is a non-catastrophic way forward through the current moment, but it rests on the national security community adopting a louder voice to draw attention to—and contextualize for the public—how these threats are evolving, helping form a more nuanced understanding of the risks they pose.

Q1: What does Anthropic’s threat intelligence report tell us about the use of AI models by malicious actors?

A1: The report tells us three things:

  1. AI enhances threat actors’ existing modus operandi. The majority of examples in Anthropic’s report reflect what many of these state and non-state actors were doing prior to the advent of AI. For state-affiliated actors, the examples include cyber operations (e.g., cyber espionage, cybercrime, hacktivism, vulnerability research), information operations (e.g., disinformation campaigns, influencing domestic and international audiences), and scaled surveillance operations. Each of these are well known and understood in national security, and are certainly where Russia, Iran, and China are the most active and capable actors—reflected in the breadth of Anthropic’s examples.

    The report also reflects the exploitation of AI by actors across the breadth of states’ ecosystems, whether contractors, defense research institutes, or even students at state-linked universities. This is especially true in weapons design and development, where these actors have been shown to use AI for ends such as researching electronic warfare software against Taiwanese targets, sourcing dual-use goods from Chinese suppliers, and gathering intelligence on advanced energy weapons. Importantly, none of these are new areas of activity; they existed long before AI. This applies especially to bioweapons, which seem to have grabbed the most public attention. Although it might seem alarming at first glance that unknown actors used AI to research toxins and pathogens, military research institutes—which Anthropic attributes some of the research to—have a long history of conducting dual-use research in this space.
  2. AI misuse reflects states’ strategic objectives. State-affiliated actors have misused Anthropic’s models in ways that directly support their broader strategic objectives, such as running AI-enabled information operations against their citizens, tracking dissidents overseas, and conducting AI-driven surveillance operations. These patterns of behavior reflect the objectives of Iran, Russia, China, and others to maintain domestic social control. Cyber espionage operations support broader national security and economic goals to gain advantage over rivals. Even the weapons research described above reflects long-term strategic objectives to achieve military superiority, defend against new threats, and deter rivals.

    This principle extends to conflict. Iran’s use of Claude for reconnaissance and targeting of U.S. troops in the Middle East directly supports Iran’s wartime objectives to attrite the United States, ensure regime survival, and continuously shape the operating environment in its favor. Iran has used cyber capabilities in a similar way. Even Russian state actors have used Claude to engineer autonomous drone swarms, likely for use in Donestk.

    Numerous states around the world have identified developing sovereign AI capabilities as a national strategic priority, and as means of leading them into the future. It should come as no surprise that malicious actors have tried to hack Claude itself as a means of gaining—unauthorized—access to Anthropic’s most advanced capabilities for their own gain.
  3. AI is being used across the full life cycle of operations: With the advent of frontier AI, the early thinking was that threat actors would employ AI predominantly to find zero-day vulnerabilities—unknown technical vulnerabilities in software or hardware—they could exploit to conduct disruptive cyberattacks. In fact, this report confirms a long-term trend familiar to the cybersecurity industry: Threat actors are applying AI across the full life cycle of their operations. This includes using AI models for improved target reconnaissance of potential victims, tailored approaches to deceive victims, malware development, evading detection, and the creation of fake social media personas that can amplify an information operation. Across the board, AI is resulting in faster, more efficient approaches at each stage of an attack.

Q2: Are the attack methods identified in Anthropic’s report new? 

A2: Not especially. The use of AI by malicious state actors reflects much of what they were already doing. Chinese students using Claude to maintain an autonomous technical vulnerability research program is consistent with China’s voracious appetite to collect and exploit technical vulnerabilities, as is its use of AI “agent swarms” for bulk open-source intelligence collection. Iran, which appears frequently in the report, has used AI to enhance its cyber capabilities for several years; a Google report identified Iran’s cyber apparatus as the heaviest user of Gemini in 2026, whilst Iran’s CyberAv3ngers group (hacktivists linked to the Islamic Revolutionary Guard Corps) are known to use ChatGPT for research into specific industrial control technology (such as programmable logic controllers, which were exploited in the recent U.S. water facility hacks in 2024).

It is also worth noting that some of the attack methods that Anthropic presents as new are not as novel as they appear. Anthropic’s claims that access to AI itself has “increasingly become the sole objective of multiple criminal groups” is essentially a form of credential theft—which cyber criminals have longtrafficked in, selling access to victims’ systems for subsequent exploitation. Even distillation attacks by Chinese AI labs—the use of more-capable AI models to train less-capable AI models (but in this case at industrial scale and using fraudulent credentials)—continues China’s long history of intellectual property theft targeting U.S. companies.

Similarly, the use of Claude by an Israeli-Singaporean commercial vendor to build a commercial surveillance platform is not new; spyware has been a burgeoningindustry for decades that relies upon extremely sophisticated cyber capabilities to evade user detection, a sector in which Israel has long been a pivotal actor.

Q3: Where should the public be truly concerned? 

A3: The key question here is which threat actors would have the ability to conduct such operations without AI. The vast majority of actors identified in Anthropic’s report—whether state actors, cyber criminals, military research institutes, or even state-linked academies—would be very likely to pursue the same operations and arrive at the same outcomes through sophisticated cyber and analytical capabilities. However, it would take them significantly more time (likely months) and significantly more human resources. And indeed, some researchers question whether the use of AI is transforming criminal capabilities as much as thought relative to other incentives.

The real concern comes from actors that do not already possess such capabilities or who may gain significant uplift from using AI models. Two examples stand out. The first is threat actors in northern Yemen—likely to be Houthi rebels, who used Claude for weapons design and development, including designing targeting software for rockets and missiles, resulting in the test fire of a guided rocket (which failed). The second is a hacktivist actor that used Claude to target European political parties, media, and think tanks, including exfiltrating large amounts of data for subsequent use. With AI, both actors’ attacks could generate significant geopolitical risk. Without AI, both actors would likely have been years away from being able to conduct such attacks.

Anthropic’s report also points to an additional concerning development: the use of PentAGI, an autonomous AI agent that performs penetration testing, to conduct scaled cyber operations. The barrier to entry to conduct attacks in cyberspace has steadily been lowering over the past decade, in large part owing to the availability of commercial cyber capabilities—readily available, off-the-shelf capabilities that require minimal skill to deploy. When AI and open-source frameworks are added into the mix, there is real pause for concern related to the capability uplift provided to far less skilled, less established actors—in this case, ones who operate without the usual normative, ethical, political, or legal constraints that shape more mature actors’ behaviors.

Q4: What is actually new in the Anthropic report?

A4: The first novel takeaway is the players in this space. AI firms such as Anthropic and OpenAI are still new to national security, and far less familiar with the scope, depth, and complexity of national security threats. Such companies are of an ilk that puts innovation first and security second; this can lead to a mindset of dealing with the consequences after, which, in this case, renders significant consequences for national security. This has left many in the cybersecurity sector frustrated, both at the acceleration of cybersecurity threats by companies with little grounding in how their services will be exploited and at the burden of fixing this problem at pace.

The second takeaway is the jump of these national security threats into the public’s consciousness—with limited context. Companies such as Anthropic are accidental entrants to the threat assessment space, only just arriving at what industries such as the cyber threat intelligence sphere have been doing for decades. They should be applauded for the transparency they have provided in the misuse of their models. However, as these companies are learning, discerning the strategic intent of malicious actors is one of the hardest things to do when it comes to threat assessment; without strategic context or doctrinal and geopolitical understanding of how threat actors operate, the examples published are presented in a void, and as though they have appeared from nowhere. Given the vast media capture these companies have, the natural result is public alarm.

Q5: How is the policy response to these risks taking shape?

A5: It is imperative that the public maintain a realistic view of the threat posed by AI. Most of the threats set out in Anthropic’s report existed before AI, though AI is exacerbating the risks they pose by accelerating, scaling, and speeding up their evolution. Access to the same models is also enabling new entrants to the threat landscape who lack the same constraints as states, and even some non-state actors, with more mature ecosystems; this should concern us all. However, this is not the same as existential risk to the future of humanity.

The way ahead is split between those who believe the development of AI models should be slowed down and those who believe that slowing down will only enable adversaries—including China—to rush ahead with their models, generating further national security risk. Suggestions for how to reign in these models vary, including ideas such as controlled testingenvironments, kill switches, and regulating AI companies, including holding them liable for their products. President Trump’s dismissal of these concerns is hardly reassuring but may reflect a political calculation to preserve an open space for a conversation with President Xi ahead of their summit on September 24, where AI safety is expected to be high on the agenda. That runs into a familiar tension: China is both a necessary partner in managing AI-related national security threats and risks—and a key source of a threat to U.S. AI models.

Regardless of which path is chosen, one point is clear: The national security community needs to share much more information with AI companies and with the public, drawing upon its deep expertise to help contextualize what AI companies are seeing, the legitimate risks these create, and what measures are being taken in response. The benefits are clear: Deepening public understanding of this technology will strengthen national resilience in the longer term, particularly as public awareness—and suspicion—of national security threats grows. That seems like a better strategic outcome than misplaced fear regarding the future of humanity.

Nikita Shah is s senior fellow with the Intelligence, National Security, and Technology Program at the Center for Strategic and International Studies (CSIS) in Washington, D.C.

Senior Fellow, Intelligence, National Security, and Technology Program