Anthropic says Claude was used for weapons development, spying and cyber operations

Anthropic says actors in China, Russia, Iran, Yemen, and Mali used its Claude AI for weapons development, cyber ops, and surveillance, including a China-based simulation targeting 12 sites in Taiwan.

Categorized in: AI News Government
Published on: Sep 12, 2026
Anthropic says Claude was used for weapons development, spying and cyber operations

Anthropic said Thursday that multiple actors have used its Claude AI models for weapons development, cyber operations, surveillance, fraud, and biological research. The company published a threat intelligence report detailing cases across China, Russia, Iran, Yemen, and Mali, raising direct questions for government agencies about how commercial AI tools are being exploited against national security interests.

Anthropic said it banned accounts linked to the activity it identified. The report does not allege that the company cooperated with any of the actors; it describes efforts by outside parties to use Claude despite safety safeguards, some of which the company said blocked requests "but not all of them."

Weapons development and military applications

Anthropic described a China-based actor that used Claude to develop an electronic-warfare and air-defense suppression software suite. The actor changed a simulation to include 12 targets in Taiwan, including early-warning radar, Patriot and Tien Kung missile batteries, air bases, and a command bunker. Account information linked the actor to Chinese research institutions including the People's Liberation Army Academy of Military Sciences.

China's foreign ministry said it was not aware of the Anthropic report and that the government maintains AI should be developed for good. China claims democratically governed Taiwan as its own territory and has never renounced the use of force to bring the island under its control. Taiwan rejects Beijing's sovereignty claims.

Other cases in the report include a China-based actor using Claude to produce a more than 200-page technical proposal for an anti-torpedo system intended for the Chinese navy, and a Chinese defense-intelligence actor researching foreign high-power microwave weapons to identify components, suppliers, and supply chains. Anthropic said the latter actor drafted restricted briefings for senior Chinese Communist Party, military, or state-security officials.

In northern Yemen, a cell of threat actors used Claude to develop software for a guided rocket, a planned ballistic missile with a range of more than 2,000 km, and a missile variant incorporating a hypersonic glide vehicle. Anthropic said it had no evidence the actors successfully fielded an operational weapon. The report did not identify whether the actors were Houthis, who control most of northern Yemen and have intensified attacks on Saudi Arabia and its energy infrastructure.

Russia-based actors also appear in the report. Likely freelance operators used Claude to develop software for an autonomous swarm of first-person-view attack drones, including terminal guidance, target selection, and coordination between multiple aircraft. Separately, a Russia-based procurement manager used Claude to identify intermediaries in China and Hong Kong to acquire European-made goods with potential military uses, including German-made magnetometers, space-grade photovoltaic wafers, and aviation oxygen systems.

Cyber operations and surveillance

Anthropic said Chinese-speaking operators likely based in Changsha used Claude in cyber operations against about 50 organizations, including foreign government networks. The group, which included two university students in Hunan, used AI-driven workflows to search for previously unknown software vulnerabilities, develop exploits, and conduct parts of intrusions with limited human supervision.

A hacking group with tradecraft consistent with Russia-based threat actor Midnight Blizzard - which the U.S. government has linked to Russia's SVR foreign intelligence service - ran phishing, hotel Wi-Fi hijacking, and WhatsApp-takeover operations against Ukrainian government, military, and diplomatic targets, using AI at nearly every stage, according to Anthropic.

Anthropic also said it identified and disrupted an Iranian-linked operator that used Claude to collect and analyze publicly accessible data to develop targeting recommendations against U.S. naval forces. The compiled material included a roster of U.S. personnel scraped from captions on public military photographs, ship and aircraft transponder identifiers, and commercial satellite-imagery query scripts.

Surveillance cases span multiple regions. A China-aligned actor used Claude to track Uyghurs in Syria and offer payment for information about Uyghur units that had joined Syria's newly formed army. Anthropic assessed with low confidence that the operator was a contractor working for Chinese state security. Other China-linked actors used Claude to compile intelligence on Catholic cardinals, Taiwanese Christian leaders, Tibetan Buddhists, dissidents, and activists, and to automate government-style reports monitoring Uyghurs, Tibetans, Taiwan political figures, and foreign media.

Anthropic said it banned 16 Claude accounts operated by two linked units associated with unidentified Iranian paramilitary and domestic security agencies. One unit worked on a malicious browser extension used to mass-harvest user identities from social network platforms. In Mali, Claude served as the main engineering tool for a domestic surveillance platform called Lakana 360, built for Mali's state intelligence service to monitor data associated with about 25 million SIM cards across the country's three mobile operators.

Biological research and influence operations

Anthropic detailed five case studies of people attempting to use Claude in ways that could support biological weapons development. The attempts included drafting a grant application for research on modifying the chikungunya virus and efforts to research highly pathogenic avian influenza. Other examples involved research related to orthopoxvirus and non-transmissible novel venoms and toxins. Some of these attempts occurred in locations where Anthropic does not offer its services, requiring users to obfuscate their location.

Influence and fraud operations also appear in the report. A French-speaking actor used Claude to target 42 European political parties, media outlets, think-tanks, and software-as-a-service providers, compiling a doxxing platform. A China-based operation developed more than 20 dating apps containing over 4,700 AI personas that interacted with at least 25,000 users, combining automated personas with paid human workers to persuade users the profiles were genuine.

For government professionals tracking how commercial AI models intersect with state and non-state threat activity, the report offers a catalog of concrete techniques: reverse-engineering foreign weapons systems, automating vulnerability discovery, scraping open-source data on military personnel, and building domestic surveillance infrastructure. Understanding how Claude AI courses and certifications cover model safeguards and abuse patterns can help agencies assess vendor claims against documented misuse. Similarly, AI for government courses increasingly address the operational security questions raised when adversaries use the same commercial tools that public sector teams are evaluating for their own workflows.

Why this matters for government

Anthropic's report is not a theoretical exercise. It names specific weapons programs, intelligence collection efforts, and surveillance platforms that used a commercially available AI model. Government security, procurement, and policy teams should treat the report as a baseline for vendor risk assessments: if a model can be steered toward targeting simulations, vulnerability exploitation, or identity profiling, then deployment decisions inside government networks require controls that go beyond standard terms of service. The question is not whether adversaries will use commercial AI - the report shows they already are - but whether public sector adoption accounts for that reality.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)