The company says Claude was used to analyse social media, compile mobile-data dossiers and develop malware #
Governments are increasingly using AI to automate parts of their surveillance operations.
According to Anthropic's latest threat intelligence report, people linked to governments in Mali, China and Iran have used its Claude models to streamline surveillance work, ranging from mobile data dossiers to malware that harvested people's identities from social media.
The company disclosed on Thursday that these state-linked actors had used Claude to automate work that could previously have required teams of analysts. Anthropic said the findings highlight how AI is lowering the barriers to government surveillance.
China Cut Analyst Teams Down to One Office #
In China, Anthropic's report found that a religious affairs intelligence office had previously relied on 'many teams of analysts' to monitor people. The office had reduced its operation to 'a single office, using an AI assistant to produce thousands of investigations per month'.
Separately, according to the report, the China-linked actors used Claude to analyse social media posts, gauge how politically sensitive they were, then identify possible targets for what officials internally called 'control'. The report states that the designation could include coercive questioning or closer monitoring of someone's movements and communications.
One Chinese state security bureau went a step further and, according to Anthropic's findings, created its own internal manual for using AI in surveillance operations. Other officials used Claude to automate daily intelligence reports and query government surveillance databases, the report found.
Mali and Iran Show How AI Is Making Surveillance Cheaper #
According to the report, a single consultant working with Mali's national security authorities used Claude to build a system that collected data from the country's mobile operators and compiled dossiers on individuals. Anthropic said Claude was used to engineer the surveillance platform, which was later deployed locally using other models.
Iranian actors, meanwhile, used Claude to build and deploy a malicious Firefox browser extension that 'harvested users' identities from social networks', the report found. Anthropic separately banned an account in June 2026 that had been using Claude to build a commercial surveillance platform designed to spy on people in Iran and the Persian Gulf.
The company detected the activity before the platform became operational. Jacob Klein, Anthropic's head of threat intelligence, told Axios that the technology is making surveillance cheaper and more efficient rather than fundamentally changing who governments target.
'They're effectively automating parts of the job within the intel apparatus,' Klein said.
Banning Accounts Did Not End the Underlying Operations #
Anthropic said it banned every account tied to the surveillance operations it uncovered and strengthened its safeguards as a result. That did not necessarily end the underlying surveillance, according to the company.
Klein said the company has seen actors move to open-source AI models once Anthropic's safeguards or enforcement created too much friction. In Mali's case, the government ultimately deployed its surveillance platform locally using other models, the report found.
The cases did not require access to Anthropic's newest Fable or Mythos-class models, according to Anthropic's findings.
All of the surveillance operations documented in the report involved Claude Haiku, Sonnet or Opus.
The findings show that AI-driven surveillance is no longer merely theoretical.
Anthropic's cases show government-linked actors using AI to analyse social media, collect mobile data, automate intelligence reporting and identify surveillance targets.
For people in the countries identified in the report, the findings show how AI can reduce the amount of human labour needed for some surveillance tasks. As Klein put it, the technology is effectively automating parts of the intelligence process, while the Mali case shows that restricting access to one AI platform does not necessarily prevent the same approach from continuing elsewhere.
© Copyright IBTimes 2026. All rights reserved.