Adversaries Using Claude AI to Target Americans and Develop Missiles Anthropic released a 154-page threat intelligence report on September 2026 documenting that an Iran-linked actor used its Claude AI model to compile targeting handbooks against U.S. naval forces and that a group in Yemen, likely Iranian-backed Houthi militants, used Claude to assist with guidance systems for ballistic and hypersonic missiles. The report, which Anthropic calls its "most detailed" to date, also details Claude misuse for intelligence gathering, surveillance, cyberattacks, influence operations, and biological research over the past eight months by actors based in Russia, China, and other countries. Anthropic said it banned the Iran-linked account, developed detections to reduce future misuse, and shared threat intelligence with government authorities. Earlier this year, an Iran-linked actor used Anthropic’s Claude artificial intelligence model to scrape and analyze data with the aim of helping target U.S. naval forces in the Middle East https://www.twz.com/sea/where-are-the-american-aircraft-carriers-september-9-2026 . A group in Yemen – very likely Iranian-backed Houthi militants https://www.twz.com/the-anti-ship-missile-arsenal-houthis-are-firing-into-the-red-sea – also used Claude to assist with work on guidance systems for ballistic and hypersonic missiles. These are just some of the revelations about how adversaries and other malign actors have been using one of the premier pieces of AI software being developed in the United States that were contained in a new report Anthropic released late yesterday https://www.anthropic.com/threat-intelligence-report-september-2026 . The 154-page document also details instances where Claude was used directly and indirectly to support intelligence gathering and surveillance, cyberattacks, influence operations, and even worrisome biological research over the past eight months. In addition to Iran and Yemen, the human actors behind these activities were based in Russia, China, and a host of other countries. Anthropic has shared details about what it calls the “misuse” of its models in the past https://www.anthropic.com/news/detecting-countering-misuse-aug-2025 , but describes the new report as its “most detailed” to date. The company has clearly been cataloging these case studies, and has assigned each one a control number. Though the entire contents of the report are cause for concern, the explicit attempt to use Claude to target American forces, as well as to develop new higher-end missiles and other military technology, are particular standouts and signs of what’s to come, as we will highlight below. GTG-30005: Military reconnaissance GTG-30005 is the case study dealing with the targeting of U.S. naval forces, and the summary is as follows: “In another investigation, we identified and disrupted an Iran-nexus threat actor that used Claude to collect and analyze publicly accessible data to develop targeting recommendations against US naval forces in the region. The threat actor used Claude to compile targeting handbooks, through a Python pipeline the threat actor built with Claude’s assistance, to identify and track naval positions based on open-source information. The compiled material included a roster of US personnel scraped from captions on public military photographs; publicly accessible ship and aircraft transponder identifiers; commercial satellite-imagery query scripts; and an inventory of public websites that exposed US naval movements. The threat actor also directed Claude to compile vulnerability research on shipboard systems, cataloging known CVEs in maritime VSAT terminals, Cisco communications equipment, and industrial control products.” “We banned the actor’s account, developed detections to reduce the risk of future misuse, and shared threat intelligence with government authorities to disrupt the threat.” How exactly Anthropic defines the term “nexus” here is not immediately clear, and other entries in its new report also use “state-nexus” in addition to country-based variations. However, in this specific case, an addendum is added to the entry that explicitly says that the same account was separately tied to “domestic mass surveillance” software development work “for Iranian state systems,” clearly pointing to an actor directly linked to the regime in Tehran. Whether or not any of the data collected and analysed here was directly used to subsequently carry out attacks on U.S. forces is unknown. However, there have been media reports just in recent weeks https://www.nbcnews.com/world/iran/us-strikes-iranian-tankers-attempted-missile-attacks-navy-warship-rcna596699 that Iran has been increasingly trying to strike American warships https://www.wsj.com/world/middle-east/iran-launched-undisclosed-second-wave-of-attacks-on-u-s-navy-ships-560f31a1 . Those same reports have raised questions about how the country has been prosecuting those operations given its limited capabilities and capacity to track maritime targets far from its shores. The possibility that Russia or China could be supplying targeting data https://www.wsj.com/world/middle-east/with-close-calls-on-u-s-warships-iran-shows-new-appetite-for-escalation-e2758bbd has been put forward. The use of AI technology by nation-state armed forces to develop target sets and engage them is already known to be growing globally. The Israel Defense Forces IDF have been a pioneer in this regard https://www.npr.org/2023/12/14/1218643254/israel-is-using-an-ai-system-to-find-targets-in-gaza-experts-say-its-just-the-st , but the U.S. military https://www.bloomberg.com/news/articles/2026-06-25/pentagon-sees-broader-role-for-ai-in-setting-military-targets , China’s People’s Liberation Army https://www.scmp.com/news/china/military/article/3366256/chinese-militarys-ai-attack-chain-lags-foreign-models-researchers PLA , and others are also known to be developing and fielding these capabilities. U.S. military officials have also voiced increasing concern in recent years about the ability to track the movements and disposition of U.S. military assets https://www.twz.com/air-force-c-32-jets-are-going-incognito-under-new-security-policy and personnel using publicly available pictures and other data https://www.twz.com/tracking-u-s-military-aircraft-online-could-become-much-harder . There has been much talk, in turn, about how to balance transparency and operational security https://media.defense.gov/2023/Apr/28/2003211040/-1/-1/0/3054.PDF . GTG-87001: Disrupting a Yemen-based guided weapons engineering cell using Claude to develop guidance software Anthropic’s new report details an instance where an individual in Yemen used Claude as part of missile guidance work, which is given the control number GTG-87001. “We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile referred to as the “R2000” set that included a hypersonic glide vehicle variant.” “The actors used Claude Code in place of human software engineers to develop the guidance, navigation, and control GNC software that steers and stabilizes a flying vehicle. For example, they used Claude to integrate an open-source autopilot onto a phone-class flight computer, writing the control and position estimation software, tuning the control settings, running a firmware build pipeline, and performing a flight simulation. The actors managed several Claude instances at once, assigning each one a role, much as a lead would delegate work on a small engineering team: the actors tasked one instance with writing the code, another with research, and a third with reviewing the code the first instance produced.” “Our safeguards blocked many of their requests, but not all of them. The actors used a variety of tactics to evade our safeguards, including hiding their goals and the products the software was meant for, and they split their work across multiple sessions so no single session revealed their full intent.” “These actors carried out a sustained effort to develop guided weapons, including using Claude to design guidance software. We do not have evidence the actors succeeded in fielding an operational device; but they did test-fire a guided rocket. This field test appears to have failed: within hours, the actors returned to Claude to work out why it failed.” “We identified this activity as part of our internal investigations into suspected weapons development. We banned accounts associated with the actors and shared threat information with public- and private-sector partners to mitigate risks posed by the actors. Nevertheless, we have evidence that the actors had already built an offline simulation toolkit that does not rely on Claude or other engineering computing environments such as MATLAB.” As mentioned earlier, the report does not name the Houthis, but that group has historically been based primarily in the northern end of Yemen. It is also the only entity in the country known to have active missile https://www.twz.com/the-anti-ship-missile-arsenal-houthis-are-firing-into-the-red-sea development programs https://www.twz.com/news-features/what-air-defenses-do-the-houthis-in-yemen-actually-have , which are conducted with critical support from Iran. Whether this particular work directly resulted in any new capabilities is unknown. Anthropic notes that there looked to be at least one failed test launch before the accounts were banned, which would have occured sometime after the beginning of this year, based on the stated cutoff dates for the report. By the end of 2025, the Houthis had already amassed a wide array of very real ballistic missiles https://www.twz.com/the-anti-ship-missile-arsenal-houthis-are-firing-into-the-red-sea , including types with at least claimed ranges https://x.com/fab hinz/status/1835239097771684225 of 2,000 kilometers approximately 1,242 miles . The group also has a variety of cruise missiles https://www.twz.com/the-anti-ship-missile-arsenal-houthis-are-firing-into-the-red-sea and one-way attack drones https://www.twz.com/sea/red-sea-turkey-shoot-allied-warships-down-dozens-of-drones-within-hours that it has employed operationally. Still, being able to leverage Claude could only have helped any domestic missile development efforts in Yemen, which might help reduce dependency on Iran, at least to a degree. Furthermore, developing functional hypersonic glide vehicles capable of prolonged stable flight has historically been notoriously difficult, even for entities with extensive relevant knowledge bases on an organizational level. GTG-17001: Disrupting a China-based operation using Claude to draft a fire control specification and acquisition documents for undersea warfare Use of Claude in foreign military endeavours goes beyond the Middle East, as evidenced by case study GTG-17001. This involved a Chinese actor conducting work related to a naval counter-torpedo defense system. “We identified a China-based threat actor who used Claude to advance three parallel tracks of work on an anti-torpedo weapons system:” - “First, the actor used Claude to draft a Chinese-language specification for an anti-torpedo fire control system the core logic that aims and times an anti-torpedo weapon’s response . The document was written to win approval from a Chinese defense manufacturer, which would move the work on to technical certification and operational testing.” - “Second, the actor used Claude to produce a Chinese-language technical proposal of more than 200 pages, accompanied by an executive briefing deck.” - “Third, the actor used Claude to benchmark their own system against specific US anti-torpedo and anti-submarine programs based on publicly accessible information. They then generated a Chinese-language briefing on US Navy systems derived from open-source reporting.” “The actor presented themselves as an original equipment manufacturer in the US defense sector. We assess the actor was associated with a Chinese defense industry manufacturer aiming to produce a weapons specification and acquisition proposal for the People’s Liberation Army Navy.” “The actor used Claude to write the acquisition proposal, refining it over many drafts. After each draft, the actor instructed Claude to role-play a hostile expert reviewer to critique the proposal, then used that feedback to sharpen the next version. In parallel, the actor used Claude to build pieces of the anti-torpedo weapons system’s fire control software and a test matrix to validate them.” “The operational lift the actor achieved was a function of using Claude to automate complex technical outputs. The actor leveraged the model to compress the development timelines for the certification registry, compliance documentation, and automated fire control logic. The actor also accelerated the traditional human review cycle by having Claude critique the acquisition proposal across multiple rounds of review while role-playing a persona.” “We uncovered this activity as part of our internal investigations into suspected weapons development. We cannot attribute the activity to a specific entity or actor. But we have banned the account for violating our Supported Regions Policy and our Usage Policy, which prohibits weapons design and development, and incorporated our investigative findings into our safeguards to mitigate the risk of future misuse.” Anthropic’s report does not name the US programs leveraged here, but does note the information in question was publicly available. Anti-torpedo systems for surface warships and submarines have been an area of significant interest for the U.S. Navy https://www.twz.com/5543/the-navy-is-quietly-arming-its-supercarriers-with-anti-torpedo-torpedoes for years now https://www.twz.com/26347/the-navy-is-ripping-out-underperforming-anti-torpedo-torpedoes-from-its-supercarriers . Those developments have also produced compact torpedo designs https://www.twz.com/33606/northrop-grumman-reveals-new-mini-torpedo-aimed-at-arming-and-defending-navy-submarines for use in other applications. The PLAN’s interest in these same kinds of capabilities is not at all surprising. Underwater threats and countermeasures to them, broadly speaking, would play a central and vital role https://www.twz.com/submarine-hunt-incident-a-peak-into-cat-and-mouse-games-in-south-china-sea in any future conflict between the United States and China across the broad expanses of the Pacific. GTG-27005: Disrupting a Russia-based operation using Claude to engineer an autonomous military drone swarm Another case study, GTG-17001, details the use of Claude by Russian actors working on drone swarming technology. “We identified likely freelance Russia-based threat actors who set out to build a full-stack autonomous first-person-view FPV kamikaze drone swarm. The actors used Claude Code to write and test the code and save it directly into the actors’ own project files. In addition to Claude Code, the actors used a software-in-the-loop simulation stack and a rented graphics processing host for model training. They called the operation ‘DronDoc’ or ‘Serafim.'” “The actors used Claude to build the core software system, including the drones’ shared swarm memory and fault-tolerant coordination logic FTCL ; an onboard small language model to govern attack, observe, and return-to-base behaviors; a terminal guidance software system to steer drones to their target using the onboard camera and issue the call to detonate; a control-link geolocation module to find opposing drone operators; a passive acoustic detection layer; and low-level logic for the drones’ programmable chips. The actors designed the platform for autonomous lethal engagement; the onboard model could select targets including a ‘person’ target class and issue detonation commands without a human in the loop. The actors’ activity—including flashing the low-level firmware to live development boards, provisioning single-board computers, and wiring up a simulation environment over a mesh network—confirmed that they were using real hardware-in-loop testing within their sessions.” “The actors trained a computer vision classifier on scraped Ukrainian combat footage, splitting the target classes into “enemy” and “friendly,” and allow-listing Russian systems. They also repeatedly used a fixed coordinate in Donetsk Oblast as the demonstration strike point, with front-line cities and corridors in Ukraine as the mission geography.” “The actors created their accounts between late 2025 and early 2026 and started the operation in mid-May 2026. The actors circumvented our geographic access controls by routing traffic through commercial virtual private servers.” “We assess the actors were a small, specialized freelance team doing a mix of civilian and military work, not a Russian state entity. We identified nine accounts associated with this group; eight were used only for ordinary freelance work, not weapons-related software development. Based on our investigation, we assess the actors had ties to a regional university with a federal research center associated with the Russian Academy of Sciences. The actors claimed to have received funding from Russia’s Advanced Research Foundation, National Technology Initiative, and Ministry of Defence, though we cannot verify those claims. We identified this activity as part of our internal investigations into suspected weapons development, we banned accounts associated with the actors, and have incorporated our investigative findings into safeguards to reduce the risk of future misuse.” Anthropic’s report included a table, reproduced below, detailing different types of drones and other capabilities that were fed into the model as part of this work. Also, while Anthropic said it could not confirm any direct ties in this instance to the Russian government, the work described here is fully in line with capabilities https://www.twz.com/news-features/russian-fiber-optic-drones-are-now-reaching-into-ukrainian-cities-far-behind-the-lines that have already been demonstrated https://www.twz.com/news-features/automated-terminal-attack-capability-appears-to-be-making-its-way-into-ukraines-fpv-drones to varying degrees in Ukraine https://www.twz.com/news-features/russian-shahed-136-with-camera-cellular-modem-could-be-a-big-problem-for-ukraine in the past few years https://www.twz.com/news-features/russia-is-using-modified-shahed-136s-to-strike-dynamic-targets-near-the-front-lines . TWZ has been very closely tracking https://www.twz.com/news-features/inside-ukraines-ai-enabled-drone-campaign-targeting-russian-logistics-deep-behind-the-lines developments on both sides of the conflict https://www.twz.com/news-features/ukrainian-commanders-exclusive-insights-on-brutal-drone-warfare-on-the-frontline when it comes to new automated targeting https://www.twz.com/news-features/russian-trucks-get-dazzle-paint-to-throw-off-ai-enabled-drones and swarming capabilities https://www.twz.com/air/ai-enabled-hx-2-kamikaze-drones-now-in-production-for-ukraine for shorter- and longer-ranged kamikaze drones. In 2024, we also published a detailed feature https://www.twz.com/news-features/drone-warfares-terrifying-ai-enabled-next-step-is-imminent outlining a coming revolution in drone warfare, signs of which were already emerging then, thanks to AI and the ever-lowering barrier to entry to leveraging that technology. GTG-17002: Disrupting a China-based operation using Claude to build targeting software for electronic warfare and air defense suppression The last case study in the Conventional Weapons section of Anthropic’s new report, GTG-17002, covers electronic warfare-related work by a Chinese actor, with a particular focus on potential air defense targets in Taiwan. “We identified a China-based actor who used Claude’s chat, coding, and agentic work tools to design, build, and iterate on a Chinese-language suite of about 16 modules for electronic warfare, using the electromagnetic spectrum to detect, jam, or deceive an opponent’s radar and communications, and for suppressing an opponent’s air defenses.” “The actor used Claude to build the software system, from the underlying logic to the user interface, and iterated through 12 versions. This included implementing and optimizing the system’s radar detection and jamming physics, generating a vulnerability analysis module, and drafting Chinese-language targeting instructions. The software suite the actor built analyzed an opponent’s radars, surface-to-air missile sites, command posts, and communications nodes, then computed their detection coverage, assessed the effectiveness of jamming, ranked targets by value and vulnerability, including which to suppress first, and determined how best to assign jammer sorties to targets across multi-day campaigns. The suite also ranked which of an opponent’s assets to suppress first, and modeled specific engagement envelopes, including those of Patriot https://www.twz.com/we-now-know-the-types-of-patriot-missiles-being-used-in-ukraine and THAAD-class Terminal High Altitude Area Defense https://www.twz.com/land/thaad-kill-vehicles-infrared-seeker-appears-to-have-been-found-in-syria-intact systems.” “Mid-project, we observed the actor change the simulation’s default scenario to 12 targets in Taiwan. The targets included a command bunker in Taiwan, an early warning radar site, Patriot and Tien Kung https://www.missiledefenseadvocacy.org/defense-systems/tien-kung-sky-bow/ surface-to-air missile batteries, major air bases, and a regional combatant command headquarters.” “The actor also ran a self-hosted model on an internal network alongside Claude and connected the software suite to this model through a tool-use integration.” “Based on our investigation, we assess the actor is a China-based defense and military-industrial researcher. Account-level metadata and content flagged by our safeguards indicated the actor was linked to PRC research institutions, including the PLA Academy of Military Sciences. We detected this activity as part of our internal investigations into suspected weapons development, we banned accounts linked to the actor, and have incorporated our investigative findings into our safeguards to reduce the risk of future misuse.” An accompanying table, seen below, mentions several specific types of U.S.-made air defense radars, as well as the Link-16 datalink network, as having come up in the course of this work. Electronic warfare variants of the Chinese Y-8 and Y-9 aircraft https://www.twz.com/air/our-best-look-yet-at-chinas-new-standoff-electronic-warfare-plane , as well as the J-16D https://www.twz.com/42511/chinas-j-16d-electronic-attack-jet-seen-sporting-jamming-pods-for-the-first-time electronic warfare jet, and what appears to be a reference to the Golden Eagle drone helicopter https://www.forcesnews.com/technology/weapons-and-kit/golden-eagle-worlds-first-ever-ai-controlled-uav-weapons-system , are also mentioned. The suppression of enemy air defenses is an essential part of any modern air campaign, whether conducted independently or as a part of a larger operation. This would be no less critical in any military intervention against Taiwan from the mainland https://www.twz.com/this-is-how-taiwans-military-would-go-to-war-with-china , or any other larger-scale conflict the PLA might find itself in. Guardrails and ethics Beyond the details in any of the specific case studies, Anthropic’s new report underscores growing broader concerns about guardrails for the use of AI and general ethics surrounding the technology. As noted in the instances above, Anthropic has also implemented various safeguards to try to block access to Claude from certain regions and/or to prevent the model from conducting certain types of work. At the same time, what the company has now shared makes clear that those protections can still be circumvented to a significant degree, at least for now. For its part, Anthropic has been publicly supportive of transparency laws and regulation https://www.wired.com/story/why-anthropic-is-pushing-states-to-regulate-ai-faster/ , at least within the United States. The company also notably made tweaks to certain Claude models https://www.anthropic.com/news/redeploying-fable-5 earlier this year to address U.S. government cybersecurity concerns. Starting in December 2025, Anthropic has also been very publicly embroiled in a dispute with the Pentagon https://abcnews.com/Politics/anthropic-latest-pentagon-contract-bar-ai-autonomous-weapons/story?id=130558898 over the potential use of Claude to support mass surveillance and fully autonomous weapon systems https://www.bbc.com/news/articles/cn48jj3y8ezo . This subsequently led to the company being designated a supply chain risk https://www.reuters.com/business/anthropic-still-flagged-risk-defense-industrial-base-us-official-says-2026-09-03/ , and limitations being imposed on the use of that model https://www.anthropic.com/news/where-stand-department-war within the U.S. military and elsewhere across the U.S. government. Anthropic is continuing to fight that action in court https://www.reuters.com/legal/government/us-judge-blocks-pentagons-anthropic-blacklisting-2026-08-28/ . However, just yesterday, Under Secretary of Defense for Research and Engineering and the Pentagon Chief Technology Officer Emil Michael said the U.S. military had scaled back the use of Anthropic’s products in support of classified work by 90 percent. The concerns about ‘misuse’ outlined in Anthropic’s new report apply, in general terms, to publicly accessible models being developed by other companies, too. There have already been publicly disclosed instances of AI agents https://www.cbsnews.com/news/openai-hugging-face-hack-ai-risks/ themselves engaging in hacking and other malign behavior https://www.nytimes.com/2026/09/03/technology/openai-hugging-face-hacking.html in order to complete assigned tasks, raising additional questions about security and public safety https://www.wired.com/story/why-so-many-ai-researchers-think-the-machines-could-kill-everyone/ , not to mention ethics. TWZ has noted in the past https://www.twz.com/news-features/drone-warfares-terrifying-ai-enabled-next-step-is-imminent that America’s adversaries are likely to be less worried about ethics, in general, when it comes to AI. Anthropic’s new report also shows there are few bounds to what state-aligned or even non-state actors might seek to use this technology for, including the development of potential weapons of mass destruction. At the same time, AI models like Claude are not going away, and developments continue to advance at an ever-quickening pace, opening the door to further proliferation. Developments are rapidly intermingling globally, with companies in China notably leveraging models created in the U.S. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a to further their own work, which is then released publicly. The technology will increasingly become more integrated and critical to most aspects of military operations and weapons development, alongside its commercial and civilian applications. It is just as much a superweapon as anything else, and the country with the more capable models, and the willingness to deploy them, will have a major edge in future conflicts. With all this in mind, it seems very plausible, if not probable, that the case studies described in Anthropic’s new report are just the tip of an approaching iceberg that will need concerted effort to tackle. Contact the author: joe@twz.com