Safety

AI-generated text

Anthropic: State actors using Claude models to automate and expand surveillance

Anthropic's threat report says state-linked actors in Mali, China and Iran have used Claude models to automate collection, analysis and targeting in surveillance operations.

Anthropic: State actors using Claude models to automate and expand surveillance

Anthropic said in a threat report released on Thursday that state-linked operations in multiple countries have used Claude AI models to streamline and expand surveillance activities.

Findings from the report

  • The company identified cases in Mali, China and Iran where various Claude models were used in surveillance workflows. The report notes these operations used Claude Haiku, Sonnet or Opus rather than Anthropic’s newer Fable or Mythos-class models.

  • In Mali, a single consultant working for national security authorities built a system using Claude that collects data from the country’s mobile operators and compiles dossiers on individuals.

  • In Iran, Anthropic disclosed a case in which actors used Claude to create and deploy a malicious Firefox browser extension that harvested users’ identities from social networks.

  • In China, a religious affairs intelligence office reported reducing operations from “many teams of analysts” to “a single office” that uses an AI assistant to produce thousands of investigations per month.

How AI is changing practice

According to the report, Claude was used not only for data collection but also to analyze information and select surveillance targets. For example, the Chinese government used Claude to analyze social media data, assess the political sensitivity of posts, and then choose people for what authorities described as “control,” a process that could include coercive questioning or closer monitoring of a person’s movements and communications.

Anthropic emphasizes that AI tools are not necessarily changing which groups governments target, but they are lowering the cost and manpower required to carry out surveillance. Jacob Klein, head of threat intelligence at Anthropic, noted that AI enables individual government employees or contractors to automate work that previously required teams of analysts.

Anthropic’s response and limitations

  • Anthropic says it has banned every account linked to the surveillance operations it uncovered and has strengthened safeguards based on its findings.

  • The company also warns that cutting off access to Claude does not automatically stop the underlying operations. Klein said Anthropic has seen actors migrate to open-source models when its safeguards or enforcement introduced too much friction. In Mali, for example, the government ultimately deployed the surveillance platform locally using other models.

Increasingly routine tools

Anthropic reports that AI is moving from experimental use into everyday state surveillance bureaucracy. One Chinese state security bureau even produced an internal manual for using AI in surveillance operations, while other officials used Claude to automate daily intelligence reports and query government surveillance databases.

Conclusion

The cases documented in Anthropic’s report illustrate that AI-driven surveillance use cases are no longer hypothetical. The company expects AI capabilities to continue improving and warns that authoritarian states are already using AI for surveillance, repression and influence operations.

Quick facts

  • Report released: Thursday (exact date given by Anthropic).
  • Countries mentioned: Mali, China, Iran.
  • Models observed in use: Claude Haiku, Sonnet, Opus (not Fable or Mythos).
  • Action taken: Anthropic banned implicated accounts and tightened safeguards.
  • Ongoing risk: Actors may switch to open-source models or local deployments, so account bans are not a complete solution.