Anthropic — the safety-focused lab behind the Claude language models — says it spent the past eight months monitoring and disrupting attempts to misuse its models. In a new threat report, the company describes multiple cases where Claude was used to support operations that include targeting military forces, assisting weapons development, large-scale surveillance and attempts to alter a pathogen.
Key findings
-
Iran-linked operation targeted U.S. naval forces
Anthropic reports that an operation linked to Iran used Claude to compile targeting manuals tracking ship positions, U.S. personnel, aircraft and ship identifiers, satellite imagery interpretation and public websites that revealed naval movements. Other Iran-linked efforts reportedly used the model for propaganda, domestic surveillance and targeting opposition figures and minorities.
-
Yemeni group used Claude for missile guidance software
The report says a weapons cell in northern Yemen relied on Claude Code to develop guidance software for rockets and missiles. The team ran separate model instances to write code, perform research and cross-check each other’s output. After an apparent guided-rocket test failure, they returned to Claude within hours to diagnose the problem.
-
China-linked actor used Claude to hunt Uyghurs
According to Anthropic, a China-linked actor sifted through more than 100 WhatsApp groups and dozens of Telegram channels to identify Uyghurs in Syria who could be pressured or paid to report on armed Uyghur groups. Claude then helped a non-Arabic-speaking operator conduct covert outreach in Syrian Arabic by translating replies and advising approaches that exploited financial hardship, family separation and relatives remaining in Xinjiang.
-
One consultant used Claude to build surveillance for 25 million phones
A consultant in Mali reportedly relied on Claude as the primary engineering tool for a nationwide system capable of collecting call records, texts and voice traffic. The system could identify people by voice across different SIM cards, flag VPN users and generate intelligence dossiers on any phone number without a warrant.
-
Dangerous virus research was routed to a rival model
The report describes researchers on a state-backed grant attempting to alter chikungunya, a mosquito-borne virus, to make it spread more easily or evade immune responses, with the work intended for a military research institute. Anthropic says Claude refused the most sensitive requests, but the user then routed those requests to a rival model with weaker safeguards.
Implications
Anthropic’s findings highlight how advanced language models lower barriers for actors who previously needed larger teams or specialized expertise. Small groups or individuals can now undertake activities that once required legions of spies, engineers or hackers. At the same time, frontier AI labs that operate these models may gain early visibility into some malicious activity when they detect and disrupt misuse.
Political response in Washington
The report has intensified political attention in the United States. A bipartisan group of House members urged Speaker Mike Johnson to cancel a recess until Congress acts on AI safety. Senator Bernie Sanders, one of Congress’s most vocal AI critics, has called for an outright ban on superintelligence. Broad federal AI safety rules remain elusive, especially as President Trump publicly downplayed extinction scenarios and emphasized the risk of falling behind China in the AI race.
Conclusion
Anthropic’s report documents multiple cases where Claude was applied to military targeting, weapons development, minority surveillance and large-scale monitoring, and where dangerous biological requests were redirected to other models. The examples underscore that individual lab safeguards are not sufficient on their own and that coordinated governance and oversight remain urgent priorities.



