The Same Week Its Researcher Quit Warning AI Could Kill Us All, Anthropic Detailed How Its AI Is Already Being Weaponized and Used by Militant Groups
Its own researcher quit saying the race could kill us all. Days later, Anthropic published proof its AI is already hacking governments and building missiles.
If this caught your attention, that’s not accidental.
The best editorial systems don’t happen by accident. Outlever builds them.

On Tuesday, a researcher named Jacob Coxon quit Anthropic in public. He had spent about three years training frontier models, first at OpenAI and then at Anthropic, and he left saying the companies are gambling with our lives by racing to build AI that can improve itself. His posts spread fast and reached more than a hundred million people. The next day, Anthropic's own alignment lead, Evan Hubinger, said out loud that he and many of his colleagues believe the technology could kill everyone, and he put his personal odds of that at better than one in ten within the decade.
Then, days later, Anthropic published its September 2026 threat report, a long account of how its AI is already being used, right now, to hack governments, spy on dissidents, help build weapons, and run fraud at scale.
The two documents sit uneasily together. One is a warning about a future catastrophe. The other is a record of present harm. Read them next to each other and a plain point comes into focus. The people building these systems are telling you what they think the risk is, and they are speeding up anyway.
Here is what the report actually shows, and why it reads differently in that light.
Sophistication stopped meaning anything
The main finding is blunt. You no longer need a skilled team to run a serious attack. Work that used to demand a well-funded state operation can now be done by one person with a stolen API key and a willingness to let the model do the heavy lifting. Anthropic documents a Russian state espionage group, a French-speaking hacktivist, and financially motivated crews all running the same kind of campaign, each using AI to handle the reconnaissance, the tooling, the intrusion, and the sorting of stolen data.
For years, how advanced an operation looked told investigators who was probably behind it. The report says that signal is gone. When everyone has the same capability, the only thing separating a bored individual from a national intelligence service is what they want. That is a harder world to defend, and it is here now.
It helped build actual weapons
The line about militant groups is not a metaphor. One case describes a cell in northern Yemen running three weapons programs at once, including a guided rocket and a ballistic missile with a stated range goal above two thousand kilometers. They used Claude in place of the software engineers they did not have, writing the guidance and control code that steers a flying weapon, tuning it, and building a simulation to test it. They ran several instances of the model at the same time, giving each one a job, the way a team lead splits work among engineers.
They took a guided rocket out and test-fired it. It appears to have failed. Within hours, the operators were back talking to Claude, trying to work out why.
Other cases in the same section involve a Russian team building software for an autonomous drone swarm that could pick a human target and detonate with nobody in the loop, and Chinese actors drafting fire-control specs and electronic-warfare targeting tools, in one instance with a simulated strike list set to a dozen sites in Taiwan. Anthropic says its safeguards blocked many of these requests, and that the actors got around the blocks by breaking the work into small, innocent-looking pieces spread across many sessions. Some got through.
From helper to operator
The more unsettling pattern across the whole report is autonomy. The uses run from Claude as a coding assistant on one end to multi-agent systems that run reconnaissance, break in, and steal data across many victims at once, for days at a time, with a person only choosing targets and checking the results. One Russian group set up an automated loop that rebuilt its malware every time a security product caught it, so it could stay ahead of the people trying to stop it. Breaches that once took teams weeks were done in a couple of hours.
Anthropic is careful to say that autonomy and harm are not the same thing, and that some of the worst cases were directed by hand at every step. That is true. But the economics are the scary part. When the machine does the labor, the cost of attacking drops while the payoff stays the same. You do not get one dramatic disaster. You get a flood of cheap, competent attacks aimed at targets that were not worth the trouble before.
The AI itself became the prize
The most forward-looking part of the report is where AI is the thing being stolen. A working API key turns out to be worth a lot. It can be resold for cash. It also gives an attacker free compute, since the workload runs on the victim's bill, and it hides the activity behind the legitimate owner's name. A whole criminal supply chain has grown up around harvesting these keys, including fake discount storefronts that pretend to sell cheap access to Claude and quietly steal the credentials of everyone who signs up.
The report goes further and accuses seven Chinese labs, among them Alibaba, DeepSeek, and Moonshot, of secretly copying Claude's reasoning to train their own models. In some cases, it says, those labs quietly rerouted their own users' questions to Claude and exposed that private data in the process. Take the accusations as Anthropic's claims, several of them hedged. The structural point still lands. The model is now valuable enough to steal, and everything around it is a target.
The wall the filters cannot climb
The biology section is where Anthropic is most honest about what it cannot do. Its classifiers blocked the most dangerous requests and pushed some researchers onto weaker models, which is a real result. But the report admits the deeper problem. In genuinely dual-use research, a request for a vaccine and a request for a weapon can look identical, and no filter reliably tells them apart. So Anthropic is shifting toward a different answer, one built on vetting who the user is rather than screening what they ask. That is an honest concession about the limits of the current approach. It also happens to point toward gated, verified, vendor-controlled access, which is a business a frontier lab is well placed to run.
Read it for what it is
None of this makes the report dishonest. The technical detail is real, outside investigators back up several of the cases, and disclosing any of this is more than most companies do. But it is a company describing itself, and the framing shows. It stresses, more than once, that the misuse landed on the widely available models and not on the more locked-down Fable and Mythos tiers. It foregrounds Anthropic catching the threats. And it lands on a policy conclusion, trusted access with verified users, that fits its own interests. A threat report can be a public service and a sales document at the same time, and this one manages both.
What the week really said
Put the resignation and the report next to each other and the through line is not science fiction. It is speed getting ahead of control, in the present tense. A person who helped build these systems walked out saying the race is reckless, and a senior colleague confirmed on the record that the people running it privately share the fear. Days later, the same company laid out, in detail, how its product is already being turned into a tool for spying, fraud, and weapons, and admitted its guardrails catch some of that and miss the rest.
There is an optimistic reading, that defenders have the same tools and the same speed. The report does not claim the two sides are even. What it documents, if you read it the week it came out, is an industry that can see the danger clearly enough to write it all down and has decided the only move is to go faster. The most honest thing anyone said about the state of AI this week came from the man who quit.
Source: Anthropic, Detecting and countering misuse of AI: September 2026.
If this caught your attention, that’s not accidental.
The best editorial systems don’t happen by accident. Outlever builds them.


Get the latest AI insights first.
Sign up for updates, interviews, and fresh analysis on how AI is reshaping business, brands, and technology.





