AI giant Anthropic has uncovered alarming attempts to use its Claude models for developing missile guidance software in Yemen and conducting state-sponsored cyber-espionage across Europe and Asia.

  • Claude AI was attempted to be used as a replacement for human engineers to write missile-guidance software in Yemen.
  • State-linked actors from Russia, China, and Iran utilized AI for automated phishing, data theft, and psychological operations.
  • Anthropic is facing internal safety warnings from former researchers and a complex legal relationship with the US Pentagon.

In a startling disclosure, Anthropic has revealed that its advanced AI model, Claude, was targeted by various state-aligned actors to facilitate high-stakes military projects and global intelligence operations. The company's latest threat report details a range of malicious activities, from the design of conventional weapons to sophisticated mass surveillance campaigns.

AI-Assisted Weaponry in Yemen

One of the most concerning revelations involves efforts in northern Yemen, where operators attempted to deploy Claude to develop guidance software for guided rockets and long-range ballistic missiles. According to the report, the actors treated the AI as a substitute for human software engineers, assigning different instances of the model specific roles to write flight-control code.

While Anthropic's internal safeguards blocked the majority of these requests, the company admitted that some prompts successfully bypassed filters. The operators employed a strategy of "fragmentation," breaking complex tasks across multiple sessions to hide the ultimate objective from the AI's safety monitors. Although a test-fire was reportedly attempted, Anthropic states there is no evidence that a fully functional weapon was successfully fielded.

Why This Matters

BozokMedia analysis shows that this incident marks a pivotal shift in the AI arms race. The transition from using AI for simple propaganda to using it for critical military engineering suggests that current safety guardrails may be insufficient against determined state actors. It highlights a dangerous vulnerability where AI could drastically lower the barrier to entry for developing precision weaponry.

The ability of state actors to bypass safety filters through fragmented prompting demonstrates that AI safety is currently a game of cat-and-mouse that the developers are struggling to win.

Global Espionage and Influence Operations

The report further details a Russian-linked operation, likely associated with Midnight Blizzard (APT29), which used automated AI workflows to conduct phishing and data theft against European diplomatic targets and drone manufacturers. Similarly, university students in Hunan, China, were found using Claude as an "orchestration layer" for offensive cyber programs targeting the Middle East and Southeast Asia.

Beyond cyber-attacks, Iran-aligned accounts were identified using the AI for psychological operations. These accounts, tied to institutions like the Islamic Revolutionary Guards Corps (IRGC), generated narratives to influence public opinion. In another case, a China-aligned actor used Claude to infiltrate Uyghur targets in Syria, utilizing the AI to draft outreach in regional dialects and translate replies in real-time despite the operator having no Arabic skills.

Actor/Region Primary AI Use Case Target Area
Yemen-based Groups Missile Guidance Software Military Hardware
Russia (APT29) Automated Phishing/Theft EU & Ukraine
China-linked Infiltration & Orchestration Middle East/SE Asia
Iran (IRGC) Psychological Operations Global Narratives

Internal Turmoil and the Pentagon Standoff

The revelations come amid internal strife. Former researcher Jacob Coxon recently resigned, warning that AI could pose an existential threat to humanity by the end of the decade. This internal alarm is mirrored in the company's strained relationship with the US Pentagon. After being blacklisted as a supply chain risk for refusing to remove safeguards against autonomous weaponry, Anthropic won a legal battle to overturn the designation.

Ironically, reports suggest the Pentagon has continued to deploy Claude models in missions within Iran and Venezuela, highlighting the contradictory nature of the US government's approach to AI safety and military utility.

Did You Know?: AI "fragmentation" is a technique where users break a forbidden request into ten small, innocent-looking parts to trick the AI into completing a prohibited task.

Frequently Asked Questions

Q1: Did the Yemeni group successfully build a missile using Claude?
No, Anthropic reports that while a test-fire was attempted, there is no evidence that a working weapon was successfully fielded.

Q2: Why did the US Pentagon blacklist Anthropic?
The Pentagon flagged the company as a risk because Anthropic refused to remove ethical guardrails that prevent the AI from being used for autonomous weapons and domestic surveillance.