Invezz

Yemen missiles to Taiwan attack plans: Anthropic flags Claude’s alarming misuse cases

Yemen missiles to Taiwan attack plans: Anthropic flags Claude’s alarming misuse cases
Devesh Kumar
11 Sept 2026, 17:30 PM

powered by

Invezz
Anthropic (AI safety)

Buy: Anthropic/Claude exposure via a proxy like Microsoft (MSFT) or Alphabet (GOOGL) that monetizes frontier AI while investing in safety tooling. The news shows Anthropic is actively disrupting misuse and tightening controls—this reduces regulatory and reputational blow-up risk for the biggest AI platforms and supports durable enterprise adoption.

Key Risk: A major misuse incident still slips through and triggers hard regulation or a consumer backlash that hits AI platform demand and margins.

AI safety enforcement (cyber/identity)

Buy: CrowdStrike (CRWD) or Okta (OKTA). Second-order: misuse cases include account takeovers and “local on-prem” deployments that keep running after model bans. That shifts the spend from model providers to endpoint, identity, and monitoring controls that detect and contain AI-assisted operational tooling inside organizations and governments.

Key Risk: AI misuse detection fails to keep pace, so buyers cut budgets for security/identity tools and the market reprices the category downward.

  • Anthropic says Claude was used in missile and autonomous drone projects.
  • Claude helped build surveillance software covering 25 million SIM cards.
  • Report also details Taiwan targeting simulations and risky bio research.

Anthropic says it has disrupted attempts to use Claude for weapons development, mass surveillance and potentially dangerous biological research.

The cases matter because AI can compress technical work that once required teams and longer timelines.

The cases appear in Anthropic’s September 10 threat-intelligence report, covering activity detected between December 2025 and August 2026.

The company said it terminated accounts, strengthened safeguards and shared intelligence with authorities.

The report came days after Anthropic researcher Jacob Coxon resigned, warning that frontier labs are racing towards self-improving superintelligence without knowing how to control what they build safely.

Anthropic exposes Claude’s most alarming misuse cases

1. Yemen cell used Claude as a missile-software engineering team

The first case involved a cell in northern Yemen pursuing three guided-weapons programmes.

Anthropic said the group was developing a guided rocket using a phone-class flight computer, a multi-stage ballistic missile with a stated range above 2,000 kilometres, and an R2000 missile family that included a hypersonic-glide variant.

The group used Claude Code “in place of human software engineers”, assigning model instances to coding, research and code review.

The actors test-fired a guided rocket. Anthropic said the test appeared to fail, with the group returning to Claude within hours to investigate what went wrong.

The company found no evidence that the cell fielded an operational weapon.

2. Russia-based developers worked on autonomous kamikaze drones

A second case involved a small Russia-based freelance team developing what Anthropic described as a full-stack autonomous FPV kamikaze-drone swarm.

Claude was used to develop swarm coordination, terminal guidance and related software.

Anthropic said the planned system could allow an onboard model to select targets, including a “person” target class, and issue detonation commands without a human in the loop.

The developers trained computer-vision software using Ukrainian combat footage and used locations in Donetsk Oblast in demonstrations.

3. China-based researcher modelled military targets in Taiwan

Anthropic said a China-based defence and military-industrial researcher used Claude to build an electronic-warfare and air-defence suppression suite.

The software analysed radar coverage, surface-to-air missile systems, jamming effectiveness and the order in which targets should be suppressed.

Midway through the project, Anthropic observed the actor change the simulation’s default scenario to 12 targets in Taiwan, including a command bunker, early-warning radar, Patriot and Tien Kung batteries, major air bases and a regional combatant-command headquarters.

Anthropic assessed the user as linked to Chinese research institutions, including the PLA Academy of Military Sciences.

The finding should not be described as evidence of an actual Chinese invasion plan; it was a military-targeting simulation built by a researcher.

4. One subscriber helped build surveillance covering 25 million SIM cards

Anthropic said a single subscriber, assessed as a likely Bamako-based consultant, used Claude as the “primary engineering workforce” for Lakana 360, a surveillance platform built for Mali’s state intelligence service.

The system was designed to monitor roughly 25 million SIM cards across all three national mobile operators.

It could collect call records, texts and voice traffic, create intelligence dossiers on individual phone numbers, match voices across SIM cards, flag VPN or encryption users and connect targets with national biometric records.

Anthropic said a warrant requirement was removed from one dossier-generating component at the operator’s request.

The company banned the Claude account, but the final platform ran locally using an on-premises model.

Anthropic’s action therefore stopped further Claude-assisted engineering but did not disable the deployed surveillance system.

5. Scientists used Claude for potentially dangerous biological research

Anthropic described five biological-misuse case studies but said it could not always determine whether the scientists involved intended harm.

The company emphasised the dual-use nature of such work, where research that could aid vaccines or therapeutics could also make pathogens more dangerous.

In one case, a state-sponsored grant involved gain-of-function research on chikungunya aimed at transmissibility and immune evasion, with work intended for a military research institute.

Anthropic said the proposal sought to identify mutations, engineer them into infectious clones and select for greater virulence in animals.

Other cases involved mammal-adapted avian influenza, orthopoxvirus immune evasion and toxin-related research.

Anthropic framed the concern as research that could support biological-weapons development, rather than claiming Claude was directly used to build a bioweapon.

The change Anthropic is warning about is leverage. AI can let smaller groups attempt engineering, analysis and software tasks that previously required larger teams, deeper expertise and more time.

Anthropic says its safeguards detected or disrupted these operations.

Its report, however, shows why those safeguards will have to keep evolving as models become more capable and users find new ways to turn general-purpose AI into a practical operational tool.