Anthropic reports Claude misused for missiles, drones

Anthropic disrupted attempts to use Claude for weapons, mass surveillance and risky biological research from December 2025 to August 2026, the company reported Sept. 10.

Anthropic released a threat-intelligence report on Sept. 10 that describes multiple attempts to use its Claude AI for weapons development, large-scale surveillance and potentially dangerous biological research. The company detected the cases between December 2025 and August 2026 and took action including account terminations, tighter safeguards and intelligence sharing with authorities.

One high-priority case involved a cell in northern Yemen that used Claude Code as a substitute for human software engineers while developing three guided-weapon programs. The projects included a guided rocket using a phone-class flight computer, a multi-stage ballistic missile with a claimed range above 2,000 kilometers, and an R2000 missile family that included a hypersonic-glide variant. The group test-fired a guided rocket that appeared to fail and returned to Claude to troubleshoot. Anthropic found no evidence the cell fielded an operational weapon.

A second case involved a small freelance team based in Russia that used Claude to develop an autonomous first-person-view kamikaze-drone swarm. The team applied the model to swarm coordination, terminal guidance and onboard decision-making that could allow the system to select targets and initiate detonation without a human in the loop. Developers used Ukrainian combat footage to train computer-vision models and demonstrated software using locations in Donetsk Oblast.

In another case, a China-based defence researcher used Claude to build an electronic-warfare and air-defence suppression simulation. The software analyzed radar coverage, surface-to-air missile systems, jamming effectiveness and target suppression order. During the project the user changed the scenario to model 12 targets in Taiwan, including a command bunker, early-warning radar, Patriot and Tien Kung batteries, major air bases and a regional combatant-command headquarters. Anthropic assessed links to Chinese research institutions, including the PLA Academy of Military Sciences, and cautioned that the simulation should not be treated as evidence of an invasion plan.

Anthropic reported a Bamako-based consultant applied Claude as the primary engineering workforce for Lakana 360, a surveillance platform built for Mali’s state intelligence service. The system was designed to monitor about 25 million SIM cards across three mobile operators, collect call records, texts and voice traffic, create dossiers on phone numbers, match voices across SIM cards, flag VPN or encrypted users and connect targets to national biometric records. A warrant requirement was removed from one dossier component at an operator’s request. Anthropic banned the account, but the final platform ran on-premises, so the company’s intervention stopped further Claude-assisted development without disabling the deployed system.

The report lists five biology-related cases that could lower technical barriers for risky work. One example was a state-sponsored grant proposal for gain-of-function research on chikungunya that aimed to increase transmissibility and immune evasion with work intended at a military research institute. Other cases involved mammal-adapted avian influenza, orthopoxvirus immune evasion and toxin-related research. Anthropic emphasized the dual-use nature of the projects and did not claim Claude produced an operational biological weapon.

Anthropic noted the incidents illustrate how advanced AI can compress tasks that previously required larger teams and longer timelines. The company reported its safeguards detected or disrupted the flagged operations and stated it will update protections as user techniques and model capabilities change.

The report was published days after researcher Jacob Coxon resigned from Anthropic and warned about frontier laboratories pursuing self-improving systems without clear methods for safe control. Anthropic reported it shared its findings with law enforcement and implemented policy and technical changes intended to reduce similar misuse.

Articles by this author