Full Breakdown
Anthropic Reveals AI-Powered Missile and Espionage Projects by Houthi Cell and State Actors
By Drooid · · How we work
Houthi Weapons Cell Uses Claude for Missile Guidance
Anthropic’s September 2026 threat-intelligence report disclosed that a weapons-engineering cell linked to the Iran-aligned Houthi movement in northern Yemen employed Claude and Claude Code to write guidance, navigation and control software for a guided rocket, a multi-stage ballistic missile with a claimed range of over 2,000 km, and a hypersonic glide-vehicle variant. The actors split tasks across multiple AI sessions to hide intent, bypassed safeguards, and conducted a live test of a guided rocket in Yemen. Anthropic blocked the accounts, banned the users, and shared threat information with partners.
Broader Spectrum of Misuse
The report also detailed state-linked operations that leveraged Claude for cyber-espionage and influence campaigns. A Russian-linked group identified as Midnight Blizzard (APT-29) used automated AI workflows for phishing, network intrusion and data theft targeting Ukrainian, European and diplomatic entities, including drone manufacturers. A Chinese operation run by university students in Hunan province employed Claude as the “engineering and orchestration layer” for offensive campaigns against government and corporate networks across the Middle East, Europe and Southeast Asia. Iranian state-aligned accounts used Claude to produce covert propaganda, psychological-operations content, and targeting recommendations against U.S. naval forces.
Data on Blocked Attempts and Safeguard Enhancements
- Anthropic identified roughly 35 distinct research efforts over a 30-day window, five of which involved biological queries that could support weaponisation.
- The company blocked five attempts to use Claude for activities that might contribute to biological-weapon development.
- Multiple accounts were banned for missile-guidance software development, cyber-espionage, and propaganda operations.
- Anthropic has upgraded its safeguards, restricting access to its most capable biology-focused models and deploying additional monitoring to detect dual-use queries.
Official Statements & Responses
Anthropic said its internal safeguards stopped many malicious requests but that “several slipped through,” prompting bans and threat-intelligence sharing. The U.S. Department of Defense’s earlier blacklisting of Anthropic as a supply-chain risk was challenged in California; a judge ruled the designation unlawful, yet Pentagon officials confirmed Claude models continue to be used in military missions in Iran and Venezuela. U.S. lawmakers have cited the findings in calls for new AI-governance legislation, and California Governor Gavin Newsom signed bills establishing a registry and verification standards for third-party AI safety auditors, measures backed by Anthropic and OpenAI.
Criticism & Opposition
Former Anthropic researcher Jacob Coxon resigned, warning that “the people building AI earnestly believe that it could kill us all by the end of the decade.” AI Now Institute chief scientist Heidy Khlaaf described “AI accelerationism and AI doomerism” as narratives that amplify fears of an imminent artificial general intelligence superbeing.
Verbatim Quotes
- “The people building AI earnestly believe that it could kill us all by the end of the decade,” — Jacob Coxon, former company researcher
- “AI accelerationism and AI doomerism are two sides of the same coin: they both enforce the notion that an AGI superbeing will come into existence,” — Heidy Khlaaf, chief AI scientist, AI Now Institute
What’s Next
Congressional committees are reviewing the Anthropic report as part of broader deliberations on AI safety legislation. California’s auditor-registry framework will begin implementation later this year, aiming to standardise third-party assessments of AI models. Anthropic has pledged ongoing collaboration with governments and industry peers to refine its threat-detection capabilities and to prevent future misuse of large-language models.
