$ 44.61 € 51.45 zł 11.81
+14° Kyiv +19° Warsaw +30° Washington
Rockets, swarms of drones, and surveillance: Anthropic showed what Claude is actually used for

Rockets, swarms of drones, and surveillance: Anthropic showed what Claude is actually used for

16 September 2026 17:41

Anthropic recently published a new comprehensive report on the misuse of artificial intelligence. The company described how its Claude models were targeted for use in the development of missiles and military software, government surveillance, information operations, cyberattacks, fraud, and potentially dangerous biological research.

Over the past eight months, the company’s Threat Intelligence team has identified and stopped a whole series of dangerous operations. The associated accounts were blocked, and in some cases, the information was shared with law enforcement agencies, government bodies, and other tech companies.

The most intriguing stories from the report read almost like the plots of a tech thriller. 

UA News highlights the most intriguing cases from Anthropic’s report—ranging from the use of Claude to develop missile systems and autonomous drones to surveillance, propaganda campaigns, and large-scale schemes involving AI.

In Yemen, there was an actual attempt to turn Claude into a team of missile engineers

Anthropic uncovered one of the most telling incidents in northern Yemen.

A group of users was simultaneously working on three weapons programs: a guided missile, a multistage ballistic missile with a claimed range of over 2,000 kilometers, and the R2000 missile family, which included a hypersonic glider among its variants.

The most interesting aspect of this story isn’t even the list of weapons, but the way they operated. Claude Code was effectively used in place of some of the programmers who were supposed to develop guidance, navigation, and flight control systems.

The model helped integrate an open-source autopilot with relatively simple computing hardware, wrote program code, configured the control system, and assisted in compiling firmware and running flight simulations.

Moreover, users could run multiple instances of Claude simultaneously.

One worked on the code, another on research, and yet another verified the results of the first. In effect, a single person could organize a small engineering department consisting of several AI agents.

This is one of the main trends running throughout the entire Anthropic report. AI is increasingly being used not just to perform a single task, but as a replacement for part of a human team.

However, in the case of Yemen, there is an important limit to the technology’s capabilities. Anthropic found no evidence that users had succeeded in developing a fully functional combat system.

But tests were conducted. According to the company, users carried out a test launch of a guided missile. Judging by their subsequent queries, it ended in failure: just a few hours later, they returned to Claude and began using it to figure out what had gone wrong.

image

Even after the accounts were blocked, one problem remained. The group had already managed to create a standalone simulation toolkit that could operate without further access to Claude.

In other words, the model isn’t necessarily needed all the time. It can help create a tool that will continue to exist even after access to the AI itself is cut off.

In Russia, Claude was used to develop an autonomous swarm of FPV drones

image

Anthropic links another case to Russia. The company identified a group of suspected Russian freelancers who were working on a system for an autonomous swarm of kamikaze FPV drones. The project was called either DronDoc or Serafim.

Here, too, Claude Code was more than just a typical chatbot. The model wrote and tested code directly within the project files. According to Anthropic, the developers used it to create a shared memory system for the drones, swarm coordination mechanisms, a guidance module for the final flight segment, a system for locating enemy UAV operators, and even an acoustic target detection module.

The most alarming detail was the system’s stated autonomy. The project called for a local language-based AI designed to control the drone’s behavior—whether to attack, conduct surveillance, or return to base.

According to the developers’ concept, the system could independently select targets. Humans were among the classes of potential targets. The system was also designed to be capable of issuing a detonation command without the operator’s direct involvement.

Anthropic saw signs that the development was not limited to simulations: users were working with actual circuit boards and single-board computers and setting up a testing environment.

The project participants themselves stated that they received funding from the Russian Foundation for Advanced Research, the National Technology Initiative, and the Russian Ministry of Defense. 

In China, Claude was developing a program that determined which air defense systems should be neutralized first

A separate, large section of the document is devoted to Chinese users. In one instance, Anthropic identified a developer who was creating a suite of approximately 16 software modules for electronic warfare and the suppression of enemy air defense systems.

Claude helped build virtually the entire software suite—from the basic logic to the user interface. The system analyzed radars, anti-aircraft missile system positions, command posts, and communications nodes. It could calculate detection zones, assess the effectiveness of jamming, and rank targets based on their value and vulnerability.

image

In other words, the program was designed to answer not just the question “where is the air defense system located,” but a much more practical one: which part of the enemy’s system should be neutralized first. The calculations specifically included the Patriot and THAAD systems.

At some point, the developer changed the standard simulation scenario. The new model consisted of 12 targets in Taiwan. Among them were a command bunker, an early-warning radar, Patriot batteries and batteries of the Taiwanese Tien Kung system, large air bases, and a command headquarters.

Anthropic assesses the user as a Chinese researcher associated with the defense or military-industrial sector. According to the company, the account data and the content of the queries indicated possible ties to Chinese research institutions.

And this was not the only such case. In another Chinese case, Claude was used to prepare a technical proposal of more than 200 pages regarding an anti-torpedo defense system.

Another user used the model to collect open-source data on foreign directed-energy systems and their supply chains, attempting to identify specific component manufacturers and understand how to replicate the technology or develop countermeasures against it.

AI is already helping governments monitor thousands of people

However, weapons make up only part of the report. An equally revealing section is devoted to surveillance. Between January and July 2026, Anthropic identified operations linked to China, Iran, West Africa, and private companies selling surveillance tools.

A common trend runs through all these stories: AI significantly reduces the cost of work that previously might have required entire teams of programmers, translators, and analysts.

In Mali, for example, a consultant working for national security agencies used Claude to design a system for the mass interception of mobile operators’ communications.

image

In Iran, the model helped create a malicious Firefox extension designed to collect user data from social media platforms. And in China, according to Anthropic’s assessment, one unit responsible for gathering intelligence on religious matters—which previously required several teams of analysts—was effectively reduced to a single office using AI to conduct thousands of checks each month.

There is an even more telling example. One operator linked to China gathered information from over 100 WhatsApp groups and dozens of Telegram channels and, using Claude, transformed this stream of messages into a structured database.

The model helped identify people who could potentially be exploited due to financial difficulties, separation from family, or ideological disillusionment. The operator paid particular attention to people whose relatives remained in Xinjiang.

Claude was also used for an operation targeting Uyghurs in Syria. The operator did not know Arabic himself, but the model wrote messages in the local dialect, translated responses in real time, and even helped verify the cover story and approach to potential targets.

In other words, the language barrier—which previously might have required a separate translator or staff member—has virtually disappeared.

Propaganda organizations now have their own automated “newsroom”

A similar transformation is taking place in information operations. Anthropic describes several scenarios in which Claude was effectively used as an editorial team: it drafted texts, adapted government messages for different audiences, created personas, helped manage campaigns, and organized internal operations.

AI allows small teams to launch information operations on a scale that previously required a much larger workforce. Anthropic cites Iran as one of the most telling examples.

The company blocked three accounts that it assessed to be linked to state-run or state-affiliated propaganda organizations. Claude was used for more than just writing posts.

The model created entire operational systems: campaign manuals, character profiles, target audience databases, internal documents, and plans for information influence.

Official statements were rephrased into content in Persian, Arabic, Urdu, Malay, Spanish, and English. In the future, the operators planned to work in approximately 20 languages.

A separate challenge was concealing the origin of the messages. Claude was instructed to make government talking points appear as if they were posts by foreign authors, independent media outlets, or ordinary users. Anthropic also describes operations in which AI was used to create entire networks of personas and content, with messages tailored to specific countries, political debates, and audiences.

Chinese companies made over 151 million requests to Claude to train their own models

Perhaps the largest figure in the entire document has nothing to do with weapons at all. Anthropic states that it uncovered large-scale campaigns of so-called illegal distillation of its models by seven Chinese AI labs.

Distillation itself is a common method for training AI: a large model generates responses, which are then used to train a smaller system. The problem, according to Anthropic, lay in how this data was obtained.

For example, a campaign the company links to Alibaba used thousands of fake accounts, home proxies, disposable email addresses, and virtual bank cards to conceal massive access to Claude. Between May and July alone, Anthropic counted over 151 million such interactions.

image

The company links another case to Moonshot AI, the developer of Kimi. Anthropic claims that in certain instances, Kimi users’ queries were secretly forwarded to Claude, and the resulting response was presented to the user as if it had been generated by the Moonshot model.

During a single ten-day period, nearly 300,000 queries were forwarded in this manner. According to Anthropic, a network of 5,380 fake accounts was used for this purpose. A particular concern is that, according to the company, the forwarded conversations included sensitive user and business information.

Anthropic cites examples of corporate financial plans, names, email addresses, and even active access keys to services. In other words, a user might have thought they were communicating with one AI service, while their request was actually routed through another company’s infrastructure.

A network of 4,700 fictional people communicated with at least 25,000 users

The report also includes a much more everyday example of what happens when AI enables the scaling of old schemes. A Chinese app studio created a network of over 20 dating services.

image

According to Anthropic, Claude was used both to build the apps themselves and to power artificial characters that interacted with real people. Users were led to believe that their conversation partners were real people.

In just two weeks in April 2026, Anthropic counted over 4,700 different AI personas engaging in conversations with at least 25,000 users. Technically, there’s nothing revolutionary about this.

Scam dating profiles existed long before ChatGPT or Claude. What’s revolutionary is the scale: a single operator no longer needs to hire hundreds of people to maintain tens of thousands of conversations around the clock. The model takes on part of this work.

The most dangerous section of Anthropic’s report does not concern missiles

Separately, the company describes five cases of potentially dangerous use of Claude in biological research. Anthropic emphasizes that it is not claiming that all of these researchers were attempting to create biological weapons.

In biology, the same technology can often have entirely legitimate scientific applications while also potentially being used for dangerous purposes. That is precisely why this area is so difficult to control.

Among the identified cases, the company mentions research on the chikungunya virus involving modifications related to transmission and evasion of the immune response, experiments on adapting avian influenza to mammals, work with orthopoxviruses, toxins, and toxic peptides.

image

In the case of chikungunya, Anthropic took particular note of the fact that the research was planned to be conducted at a military research facility. The company specifically refrained from naming countries, institutions, or specific researchers and noted separately that it has no basis for automatically attributing criminal intent to them.

For Anthropic, this restriction is important for another reason. Previously, AI developers could state with reasonable confidence that language models were not powerful enough to significantly assist a qualified specialist in creating dangerous biological systems.

With today’s models, however, that confidence is waning. That is precisely why the company is tightening restrictions on complex biological queries for new systems.

The danger no longer lies in a single AI response, but in the fact that it can drive the entire process

Just a few years ago, discussions about the risks of generative AI often boiled down to a single question: Can a chatbot be made to provide instructions for something dangerous? A new report from Anthropic shows that this threat model is now outdated.

In most of the cases described, users did not ask Claude in a single query to build a rocket, set up a surveillance system, or launch a propaganda campaign. Instead, a large task was broken down into dozens or hundreds of smaller ones.

In one dialogue, the model might write a piece of code; in another, it might search for an error; then analyze technical documentation, translate a message, structure the data received, or prepare the next step in the process.

Each of these requests on its own might not seem dangerous. The problem only becomes apparent when they all come together as a single process. This is precisely how Claude could gradually help develop software for missiles, coordinate work on autonomous drones, process large datasets for surveillance, or support information campaigns in multiple languages simultaneously.

That’s why, for Anthropic, it’s becoming increasingly important to consider not only the content of an individual message but also the context of the user’s entire activity: what they were doing before, what tools they’re creating, and what the final outcome of the entire sequence of requests is.

This also changes the very scale of the problem. AI did not invent missiles, espionage, propaganda, or fraud. But it can significantly lower the barrier to entry for such operations. What used to require several programmers, a translator, an analyst, and a specialist in a specific field can now be partially carried out by a single person with the help of a few AI agents.

And this, perhaps, is the main conclusion of the Anthropic report: the biggest change is not that AI has learned to do something fundamentally new, but that it allows a significantly smaller number of people to do complex things faster, cheaper, and on a much larger scale.

 

 

Read us on Telegram and Sends

Download our app