Measuring tactical intelligence targeting and conventional weapons capabilities Anthropic's Frontier Red Team developed new evaluations showing AI models are making consistent progress on simulated tactical intelligence targeting and conventional weapons development tasks, according to a new report from Anthropic's Threat Intelligence Team. The report cites instances of AI misuse in surveillance and weapons development, and notes that open-weights models tested lag frontier models (typically between Sonnet and Mythos-class performance) but often still reach concerning capability levels. Anthropic warns that models well short of the frontier will have intelligence and military applications, and that capabilities are not about to plateau. Subscribe to the Frontier Red Team newsletter Get updates on our latest red-teaming research and findings. Anthropic’s Frontier Red Team developed new evaluations to measure AI capabilities in tactical intelligence targeting like finding where people are based on fragmentary information and conventional weapons development like engineering drones to strike a moving target . Cybersecurity and biorisk are among the best-studied https://www.anthropic.com/research/zero-days domains https://www.anthropic.com/research/exploit-evals of risk from misuse of AI. But most of modern conflict occurs in more conventional realms. Adversaries try to identify and target one another to collect intelligence. Combatants try to make conventional weapons more precise and less vulnerable to countermeasures. “Kill chains,” such as “find, fix, track, target, engage, assess,” are end-to-end conceptual models https://www.esd.whs.mil/Portals/54/Documents/FOID/Reading%20Room/Joint Staff/21-F-0520 JP 3-60 9-28-2018.pdf page=25 of these engagements. Making improvements in any step of this process has typically required expert human labor and judgment: experienced intelligence analysts or highly-trained engineers, for example. As AI shows tremendous progress in data analysis, software development, and coding, can it apply these skills to the specialized domains associated with national security? A new report https://www.anthropic.com/threat-intelligence-report-september-2026 from Anthropic’s Threat Intelligence Team suggests the answer is yes. It includes instances of AI misuse in surveillance and conventional weapons development which show threat actors already perceiving benefit from the use of AI models. The Frontier Red Team https://www.anthropic.com/research/team/frontier-red-team has developed some complementary capability evaluations to better illustrate how AI progress is changing the risk landscape across different parts of the kill chain. The evaluations show that models are making consistent progress on simulated intelligence and weapons development tasks. Open-weights models we tested on the same evaluations are behind the frontier typically between Sonnet and Mythos-class models in performance , but often still capable of concerning levels of capability. Models well short of the frontier will have intelligence and military applications. Looking ahead, we do not think capabilities are about to plateau. Instead, we should consider the potential for AI to make substantive contributions to more novel and geostrategically consequential breakthroughs in the intelligence and military domains. The development of these capabilities may affect how models should be trained, safeguarded, and released, or used to preserve stability and liberty. The rest of this post expands on the research and results underlying these conclusions. In an intelligence agency, the core job of a targeter is to find and fix people and things. "Find" means identifying targets of interest a person, an account, a facility, a vehicle and building enough of a picture to know who or what they are and why they matter. "Fix" means pinning them to a place and time precisely enough to enable further intelligence collection or disruption of their activities. Targeting sits at the front of the intelligence cycle, before collection and analysis, and it is where a significant amount of the labor goes. This process has been historically labor-intensive, specialized, and expensive.