Logo via Wikimedia Commons; treatment-A cover, license to verify on approval
An AI safety report reveals Houthi-linked operatives ran parallel Claude sessions to develop guidance systems for rockets and a hypersonic glide vehicle over nine months.
A weapons-engineering cell in northern Yemen spent roughly nine months using Anthropic’s Claude AI models to develop missile guidance, navigation, and control software, according to a report the AI company published on September 10, 2026. The cell, which Anthropic identified as likely connected to Iran-backed Houthi militants, ran projects from December 2025 through August 2026 before accounts were detected and banned.
The group pursued three distinct weapons programs simultaneously: a guided rocket built around a phone-grade flight computer, a multi-stage ballistic missile designed for ranges exceeding 2,000 km, and the R2000 missile family, which included plans for a hypersonic glide vehicle.
How the cell operated #
The Yemeni operatives ran multiple Claude instances in parallel, each assigned a different function. Some sessions handled coding tasks, others were dedicated to research, and a third category performed review of the outputs.
Anthropic’s report, titled “Detecting and Countering Misuse of AI,” documented that the cell worked across several of Claude’s model tiers, including Haiku, Sonnet, and Opus.
The cell apparently test-fired one of the guided rockets. It failed. After Anthropic detected the activity and banned the associated accounts, the group had already built a simulation toolkit that allowed them to continue some development work offline.
Part of a larger pattern #
The Yemen case wasn’t an isolated incident. Anthropic’s report documented six separate misuse incidents involving weapons software development, including activities linked to state actors in China and Russia.
Anthropic stated it found no evidence that operational weapons emerged from any of the Yemeni cell’s projects.
What this means for AI companies and regulators #
Anthropic published these findings publicly rather than burying them. The report is, in effect, an admission that safety guardrails were circumvented by a determined adversary over an extended period.
The offline simulation toolkit the cell created before being banned illustrates a fundamental challenge: once knowledge is extracted from an AI system, revoking access doesn’t claw it back.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our