Story
September 12, 2026
Anthropic’s Safeguards Expose How AI Is Already Being Turned Into a Weapon
Anthropic presents its latest findings as evidence that AI providers can interrupt military and repressive misuse; the cases it describes show why critics see the technology as lowering the cost of targeting rivals, monitoring minorities and building weapons—while leaving no single company able to close every escape route.
Anthropic’s Sept. 10 threat report framed a fast-moving problem in unusually concrete terms: actors linked to hostile states and armed groups allegedly used Claude not for abstract research, but for targeting, weapons work and political surveillance. The company says it banned the identified accounts, tightened detection systems and shared relevant analysis with authorities.1
One China-based defense researcher, whom Anthropic linked through account metadata and content to Chinese military research institutions, allegedly used Claude to build a 16-module Chinese-language suite for electronic warfare and suppression of air defenses. The project went through 12 versions and, midway through development, shifted to a scenario involving 12 Taiwanese military targets—including radar sites, air bases and command facilities. Anthropic stressed that the software was “scenario-fed, not live ISR,” and did not say it was deployed or adopted by the PLA.2
The report also described an Iran-linked operation that compiled open-source handbooks for identifying and tracking U.S. naval positions in the Middle East, using material ranging from ship transponders and military photographs to commercial satellite imagery. It said northern Yemeni users separately turned to Claude for missile-development work.1
The danger was not confined to battlefields. Anthropic said China-aligned operators used the model to identify Uyghurs in Syria, monitor journalists and compile dossiers on religious communities and dissidents. In one alleged campaign, an operator ran a “religious affairs intelligence collection desk,” producing Chinese-language reports on Catholic cardinals, Taiwanese Presbyterian leaders, Tibetan Buddhists, Falun Gong practitioners and NTD; one machine generated 2,475 finished dossiers and reports in 30 days, according to the company.3
For AI-safety advocates, the cases are proof that frontier models can shrink work once requiring teams of analysts, engineers or intelligence officers. But Anthropic’s own findings also underline the limitation of company-level controls: when Claude refused sensitive requests involving chikungunya research, the platform allegedly routed them to a rival model with weaker safeguards.4
That leaves the central tension unresolved. Detection may deny one route to a military planner or surveillance operator; it does not stop them from finding another.