Key Points
- Anthropic detected a north Yemen threat cell using Claude on three weapons development programs.
- The company did not name the Houthis, who control most of northern Yemen.
- A guided munition launch test appears to have failed, Anthropic said.
The latest:
A threat cell based in northern Yemen used Anthropic’s Claude model to help build guidance, control and navigation software for ballistic missiles, the company said. Anthropic stopped short of naming the Houthis, describing instead a cell running three weapons development programs. The Financial Times noted that the Houthis control most of northern Yemen and that few other groups fit the description.
Details:
- The programs: Anthropic said the cell’s work covered three efforts: a multi-stage ballistic missile, a missile with multiple variants, and a guided munition built around a flight computer with smartphone-grade specifications. The company did not describe how far each program had advanced.
- How Claude was used: According to Anthropic, the group used Claude Code as a substitute for software engineers, developing systems to steer the missile and stabilize it in flight. That included integrating an open-source autopilot, writing control and position-estimation software, and running flight simulations.
- Safeguards: Anthropic said its protections blocked “many but not all” of the requests, an acknowledgment that the guardrails were partially circumvented over the course of the activity rather than holding across the board.
- Evasion tactics: Users concealed their objectives and split the work across multiple sessions so that no single conversation exposed the full project, the company said. The technique kept each individual request looking more benign than the program behind it.
- The failed test: The group reached an actual launch test of a guided munition, but the test appears to have failed, according to Anthropic. Within hours, members of the cell returned to Claude to try to work out what had gone wrong.
- Limits of the finding: Anthropic said it has no evidence the group succeeded in producing an operationally usable weapon. The company did not indicate how long the activity ran before it was detected.
- The response: Anthropic said it banned the accounts linked to the cell and shared threat intelligence with public and private sector partners. It did not identify which agencies or companies received the information.
- The attribution gap: The company’s own language stopped at a cell of threat actors based in northern Yemen. The Financial Times supplied the geographic inference pointing toward the Houthis, who hold most of that territory.
Background:
The Houthis have fired ballistic missiles and drones at shipping in the Red Sea and at targets beyond Yemen, making their missile development capability a standing concern for regional and Western governments.
Between the lines:
The case points less to a capability breakthrough than to a control problem. The test failed and Anthropic found no operational weapon, but the cell got as far as autopilot integration, control software and flight simulations before detection. The session-splitting tactic it used suggests safeguards that evaluate single requests can miss a weapons program assembled across many of them.
What’s next
Watch whether Anthropic publishes further detail on the cell’s timeline, whether other AI developers report similar misuse patterns, and whether governments receiving the threat intelligence act publicly on it.