A new 154-page report from Anthropic documents several cases in which criminals, state-linked groups and other actors allegedly used Claude for cyber operations, surveillance, propaganda, weapons development and large-scale social engineering.
Artificial intelligence is increasingly becoming a tool for both legitimate innovation and malicious activity. Anthropic’s latest threat report provides a detailed look at how its Claude models were allegedly exploited by different actors across several countries.
The 154-page report describes cases involving government surveillance, autonomous weapons research, influence campaigns, fraudulent online services and large-scale AI-generated interactions.
Anthropic said the incidents demonstrate how advanced AI can lower the barriers to activities that previously required larger teams, specialized expertise or significant resources.
Among the cases highlighted were a surveillance system in Mali, autonomous drone software developed by a Russian group, weapons-related experimentation in Yemen, an AI-assisted propaganda network in France, an influence campaign connected to the UAE and a network of apparently human-operated dating services in China that secretly relied on thousands of AI personas.
Surveillance System Allegedly Built With Claude in Mali
One of the most striking cases involved a technology consultant in Bamako who was reportedly working with Mali’s state intelligence service, known as ANSE.
According to Anthropic, the consultant used Claude Code to develop a surveillance platform called Lakana 360.
The system was reportedly designed to monitor mobile communications on a massive scale, with the ability to process information associated with millions of SIM cards.
Anthropic said the platform could potentially collect calls, text messages and voice communications. It could also reportedly recognize individuals through their voices even after they changed SIM cards.
The system was further described as capable of identifying whether users were relying on encryption services or virtual private networks.
The case illustrates one of the major concerns surrounding increasingly capable coding assistants. AI can potentially accelerate the development of sophisticated software even when the person using the system does not possess the same level of programming expertise traditionally required.
Russian Developers Used Claude for Autonomous Drone Software
Anthropic also described a case involving a small group of developers in Russia who allegedly used Claude to develop software intended for autonomous attack drones.
The company assessed the developers as likely freelancers rather than a formal government or military organization, although the group claimed to have received funding from Russian government and military research programs.
The reported software was designed to allow a swarm of drones to identify targets and conduct attacks with limited human intervention.
Anthropic said the developers repeatedly attempted to identify a location in Ukraine’s Donetsk region as a target during their work.
The group also reportedly used VPNs to bypass geographic restrictions imposed by Anthropic.
The case raises broader questions about how AI companies can prevent their models from being used to accelerate military applications, particularly when developers can attempt to circumvent geographic or platform restrictions.
Claude Was Also Used in Weapons Development Efforts in Yemen
Another case described in the report involved a group in northern Yemen that allegedly used Claude Code while working on weapons-related projects.
Anthropic said the group used the coding assistant for work involving a guided rocket, a long-range missile and a proposed hypersonic weapon system.
The individuals reportedly divided their activities between separate conversations with the AI in an apparent effort to make the overall project less visible.
Anthropic said there is no evidence that the group successfully completed a functioning weapon, although investigators found evidence that one rocket was test-fired.
After the test reportedly failed, the group returned to the AI system seeking assistance in determining what had gone wrong.
The incident demonstrates how AI assistance can potentially be incorporated into multiple stages of a technical project, even when the overall objective violates platform safety policies.
French Advertising Company Allegedly Ran AI-Powered Propaganda Network
Anthropic’s report also examined an influence operation allegedly connected to LKM Company, a French advertising agency.
The company reportedly used Claude to generate political and ideological content at large scale.
According to Anthropic, the operation involved approximately 70 fake news websites operating in around 20 languages.
At least 8,913 articles were reportedly produced.
The network allegedly created fictional journalist identities for the websites and established fake social-media accounts designed to make the publications appear more authentic.
Hundreds of additional accounts were reportedly used to post comments and amplify the material.
Anthropic characterized the operation as “propaganda as a service”, because the messaging could reportedly be modified according to the interests of whoever commissioned the campaign.
The operation allegedly targeted audiences in the United States, France and Brazil, while also producing substantial material concerning the Democratic Republic of Congo and its conflict with Rwanda.
The case illustrates how generative AI can dramatically reduce the cost and time required to manufacture seemingly independent media content.
UAE-Linked Influence Operation Targeted Critics
Anthropic also described an influence operation that it linked to actors associated with the United Arab Emirates.
The campaign reportedly focused on the Muslim Brotherhood and United Nations experts who had criticized Abu Dhabi’s alleged involvement in the conflict in Sudan.
Claude was allegedly used to prepare reports, advocacy documents, social-media material and testimony related to Sudan.
Anthropic said the campaign revolved around an AI persona called “Deadshot.”
The system was reportedly instructed to support a broader campaign aimed at weakening the Muslim Brotherhood internationally.
Another particularly notable element involved the preparation of testimony intended for the UN Human Rights Council.
According to Anthropic, AI-generated material was prepared under instructions that it should not disclose the UAE’s alleged connection to the campaign.
The case highlights a different category of AI misuse. Rather than directly attacking computer systems, AI can be used to produce persuasive material designed to influence public institutions, policymakers and international audiences.
Chinese App Developer Secretly Used AI Dating Personas
Anthropic’s report also examined an unusual commercial application of AI.
A China-based application developer reportedly created a network of more than 20 dating apps that presented users with what appeared to be human conversation partners.
Behind the scenes, however, many of those interactions were allegedly powered by Claude.
Over a period of approximately two weeks in April 2026, Anthropic identified more than 4,700 AI-generated characters communicating with at least 25,000 real users.
Together, the AI personas reportedly exchanged approximately 2.36 million messages.
The operation did not rely entirely on automated conversations.
Anthropic said human employees were incorporated into the system, with approximately one human worker for every three AI personas. Those employees reportedly handled interactions that AI systems could not easily perform, such as video calls.
The case demonstrates how AI can be used to scale deceptive interactions far beyond what would be practical for a conventional human workforce.
AI Misuse Is Becoming More Diverse
The cases described by Anthropic span several fundamentally different categories of abuse.
They include:
- Surveillance: AI-assisted monitoring of communications and mobile networks.
- Military applications: Development of software associated with autonomous weapons.
- Weapons research: AI assistance during missile and rocket development efforts.
- Propaganda: Automated production and distribution of political content.
- Influence operations: AI-generated advocacy and institutional communications.
- Fraud and deception: Large-scale interactions designed to appear human.
- Circumvention: Attempts to bypass geographic or platform restrictions imposed by AI providers.
The diversity of these cases is significant because it suggests that AI misuse is not limited to one particular type of criminal activity.
Instead, increasingly capable models can potentially become components within existing criminal, political or military operations.
The Challenge Goes Beyond Blocking Individual Prompts
Anthropic’s findings also point to a difficult problem for AI developers.
Preventing a model from directly answering a dangerous request is only one layer of defense. Users can potentially split projects across multiple conversations, combine AI-generated material with conventional software or use several different AI systems.
They can also attempt to circumvent geographic restrictions and other safeguards.
That makes misuse detection increasingly dependent on identifying patterns of behavior, rather than simply blocking individual prompts.
AI companies therefore face the challenge of balancing legitimate access to powerful models with safeguards against sophisticated misuse.
The Human Element Remains Critical
Despite the technological sophistication described in the report, none of these cases demonstrate that AI independently decided to conduct the activities.
Human operators reportedly established the objectives, provided instructions and integrated AI-generated output into broader operations.
That distinction matters.
The concern is not simply that AI systems can act autonomously. It is that they can potentially amplify the capabilities of people who already intend to conduct harmful activities.
A small group can potentially produce more content, write more software, communicate with more targets or process more information than would have been possible without automation.
Anthropic’s Report Highlights a Growing AI Security Problem
The cases documented in the September 2026 report illustrate how the rapid advancement of AI is creating a new security landscape.
Claude was reportedly used in everything from government surveillance and weapons-related development to propaganda production and deceptive commercial interactions.
The incidents also show why AI safety cannot depend exclusively on model-level restrictions.
Geographic controls, monitoring, threat intelligence, account-level detection and cooperation with governments and security researchers may all become increasingly important as malicious users become more sophisticated.
The broader lesson is straightforward: the same capabilities that make AI valuable for coding, research, communication and automation can also make existing forms of abuse faster and easier to scale.
Anthropic’s report suggests that the AI industry is now entering a phase where detecting and countering real-world misuse will be just as important as improving the capabilities of the models themselves.

