Key Points
- Anthropic says an Iran-linked group used its Claude model to track U.S. Navy ships in the Middle East.
- The finding sits in a 154-page report on state-aligned misuse of AI across Iran, China, Russia and Yemen.
- The report lands as Washington debates whether policymakers grasp AI's national-security risks.
The latest:
An Iran-linked group used Anthropic’s Claude model to compile transponder data, military photographs and commercial satellite imagery in an effort to track U.S. Navy warships in the Middle East and probe their shipborne communications for vulnerabilities, according to a new report from the AI company. Anthropic said it disrupted the effort. The case is one of several in a 154-page document on adversarial misuse of its models.
Details:
- The targeting effort: Anthropic said the Iran-linked actor fused ship and aircraft transponder signals with military photographs and commercial satellite images to locate American warships and hunt for weaknesses in their communications systems. The company attributed the disrupted plot to a threat actor using the advanced Claude model.
- The scope: The 154-page report describes what the company presents as a playbook of how U.S. adversaries are deploying AI in novel ways: missile development, aggressive disinformation, surveillance of dissidents, and attempts to pursue biological weapons capabilities.
- Bioweapons cases: Anthropic said it identified and disrupted efforts to use its models to develop biological weapons, but did not name the countries or governments linked to those attempts. Without the right safeguards, the report said, such capabilities could carry catastrophic consequences.
- Yemen and missiles: A group in northern Yemen used Claude to develop guidance software for high-end weapons, including a multistage ballistic missile, according to the report. “Our safeguards blocked many of their requests, but not all of them,” Anthropic said of that effort.
- The response: Anthropic said it banned the accounts tied to the Yemeni weapons work, shared the information with government partners, and built new detection protocols to reduce future misuse. Its rules bar using the models to build weapons, conduct surveillance or carry out violence. Users frequently obscured their intentions and kept trying new approaches after Claude rejected requests, the company said.
- China and Uyghurs: Anthropic said a Chinese-government-aligned operation used Claude to track and surveil Uyghurs, with particular focus on those who joined the newly formed Syrian Army. The same operation ran mass reporting and bot-network amplification against Uyghur diaspora journalists.
- Religious dossiers: Another set of accounts linked to the Chinese government used Claude to build dossiers on religious figures across Asia that Beijing views with suspicion, including senior Catholic cardinals, the leadership of the Presbyterian Church in Taiwan, and Tibetan Buddhist civil society and the administration in exile.
- Russian activity: Russia-based actors tried to use Claude to build autonomous killer drone swarms drawing on Ukrainian battlefield data, and to distribute AI-generated Russian-aligned state propaganda in resource-rich central African countries including the Central African Republic and the Democratic Republic of Congo.
- Internal alarm: A top Anthropic researcher resigned this week over fears AI firms are building systems they cannot control. Evan Hubinger, another senior scientist, wrote on social media that he puts the odds AI kills all humans above 10% within the decade and said the company has no plan yet to solve alignment for superintelligence.
Background:
Yemen’s north is home to the Houthi rebels, one of the strongest Iran-aligned groups in the region, who recently consolidated control over the Bab al-Mandeb waterway, a chokepoint for energy shipments through the Red Sea. The U.S. declared China’s repression of Uyghurs a genocide in 2021.
Between the lines:
Anthropic’s own account contains the tension: it says safeguards blocked many Yemeni weapons requests but not all, and that users repeatedly reworked rejected prompts. That admission, alongside a senior scientist publicly putting existential risk above 10%, frames the report less as a security win than as evidence that enforcement is partial. Top AI firms publish such threat reports routinely to inform partners and the public.
What’s next
Watch whether Washington policymakers respond to the report’s specific claims, whether the named governments issue denials, and whether Anthropic discloses which countries were tied to the biological-weapons attempts it says it disrupted.