cd /news/ai-safety/anthropic-reports-russian-developers… · home topics ai-safety article
[ARTICLE · art-127690] src=cryptobriefing.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Anthropic reports Russian developers used AI for kamikaze drone software

Anthropic published a 154-page threat intelligence report on September 11, 2026, detailing how freelance Russian developers used its Claude Code AI coding assistant to build autonomous targeting and detonation software for kamikaze drones aimed at Ukraine, a project tracked as GTG-27005 and internally designated DronDoc or Serafim. According to Anthropic, the developers began work around mid-May 2026, trained a computer vision classifier on Ukrainian combat footage focused on the Donetsk region, and used VPNs and commercial servers to circumvent the company's geographic restrictions; Anthropic assessed the group as freelancers with connections to a Russian regional university and a federal research center, and noted no confirmed operational deployment of the drone system, which remained in simulation and testing phases.

read3 min views2 publishedSep 12, 2026
Anthropic reports Russian developers used AI for kamikaze drone software
Image: Cryptobriefing (auto-discovered)

Anthropic official brand assets (anthropic.com)

A 154-page threat intelligence report reveals freelance developers in Russia used Claude Code to build autonomous targeting systems for attack drones aimed at Ukraine

Anthropic just published what might be the most unsettling AI safety document to date: a 154-page threat intelligence report detailing how a group of Russian developers used Claude Code to build software for autonomous kamikaze drones designed to identify targets and detonate without human input.

The project, internally designated DronDoc or Serafim and tracked by Anthropic as GTG-27005, was designed to give attack drones the ability to select targets, distinguish between friendly and enemy forces, and execute terminal guidance maneuvers, all culminating in an autonomous detonation command. No human in the loop for the final kill decision.

What the developers actually built #

According to Anthropic’s report, released on September 11, 2026, the Russian developers began work on the project around mid-May 2026. They leveraged Claude Code, Anthropic’s AI coding assistant, to develop a suite of capabilities that reads like a military contractor’s wish list.

The software incorporated a computer vision classifier trained on Ukrainian combat footage, with a particular focus on the Donetsk region. It could perform target selection, including the ability to differentiate between what it classified as “enemy” and “friendly” targets, and it featured terminal guidance systems for the final approach phase.

Perhaps most concerning: the system was designed so that drones could decide to detonate autonomously. The developers used a fixed coordinate in Ukrainian Donetsk for demonstration strikes, specifically targeting simulated frontline areas and logistics positions.

To access Claude Code in the first place, the developers circumvented Anthropic’s geographic restrictions using VPNs and commercial servers.

Freelancers with interesting connections #

Anthropic assessed the developers as freelancers rather than state-sponsored actors. The report noted connections between the group and both a Russian regional university and a federal research center.

Part of a broader pattern #

The drone software wasn’t an isolated incident. Anthropic’s report placed the DronDoc project within a larger pattern of Russian-linked operations that used Claude for cyber espionage activities. These parallel efforts targeted drone technology and related assets in Ukraine, with the cyber operations involving data theft and attacks against various Ukrainian entities.

Anthropic did note one critical caveat: no confirmed operational deployment of the drone system has been documented. The project remained in simulation and testing phases.

The implications for AI companies and regulators #

Anthropic deserves some credit for transparency here. Publishing a 154-page report detailing how your own product was used to develop weapons software is not exactly a PR win. But it does set a precedent for how AI companies might handle disclosure when their tools get repurposed for military applications.

The computer vision component adds another layer of complexity. Training a targeting classifier on real combat footage suggests that publicly available conflict documentation, the kind shared by open-source intelligence communities and war correspondents, can become training data for weapons systems.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our

Editorial Policy.

── more in #ai-safety 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/anthropic-reports-ru…] indexed:0 read:3min 2026-09-12 ·