Anthropic published what is effectively its first threat intelligence report this week, revealing that state-backed actors from Iran, Russia, China and Yemen used Claude to support weapons development, espionage and military targeting operations between December 2025 and August 2026.
The report is unusual in the AI industry. Most model providers stay quiet about misuse cases. Anthropic chose transparency, and the picture it paints is worth understanding.
What the Report Found
The incidents Anthropic identified and shut down span a range of military and intelligence applications:
Iran built targeting handbooks using Claude, tracking U.S. naval ship positions, personnel data, aircraft and ship identifiers, and satellite imagery. Separate Iran-linked operations used Claude for domestic propaganda, surveillance of dissidents, and targeting of opposition figures and ethnic minorities.
Yemen stands out because a weapons cell relied specifically on Claude Code, the agentic development tool, to write guidance software for rockets and missiles. The cell was working on at least three weapons systems, including a guided rocket, a ballistic missile with a claimed range exceeding 2,000 kilometres, and a separate missile family.
Russia involved a state-nexus espionage campaign alongside discovered designs for autonomous drones programmed to select human targets without human approval in the loop.
China saw an actor use Claude to develop an electronic-warfare and air-defense suppression software suite. The simulation modelled radar jamming across 12 targets, several of them in Taiwan.
On the biological weapons front, Anthropic flagged five cases where researchers used Claude in ways linked to weapons development, including one instance where a scientist sought help drafting a grant application for gain-of-function research on the chikungunya virus.
A notable detail: none of these incidents involved Anthropic’s most capable models. Fable 5.1 and Mythos 5.1, Anthropic’s frontier-tier releases, were not implicated.
Why This Is Significant for Enterprise AI Users
You might read this story and think it has nothing to do with your business. It does, for several reasons.
The misuse problem confirms that AI governance is not optional. The fact that state-backed actors are systematically probing AI systems for weapons applications means the technology is genuinely powerful enough to warrant oversight. If you are deploying AI agents inside your organisation, the governance question is not bureaucratic box-ticking. It is a real operational requirement.
Claude Code’s involvement is worth noting. The Yemen case used Claude Code, an agentic coding tool, not just a chat interface. Agentic AI can plan, write and execute code with minimal human intervention. That capability is exactly what makes it valuable for productivity, and it is exactly what made it attractive for weapons software development. The lesson for enterprises is not to avoid agentic AI, but to think carefully about what tasks you authorise your agents to take on and what human checkpoints you build in.
Transparency matters when choosing AI vendors. Anthropic published this report, which says something about the company’s stance on accountability. Not every AI provider is this forthcoming about misuse. When your organisation is evaluating AI vendors, ask what their threat intelligence and misuse detection practices look like. The answer tells you a lot.
Your AI tools are part of a threat landscape. Sophisticated state actors are actively studying how to exploit commercial AI. That includes probing the tools your developers use. The GitSpawn vulnerability class disclosed earlier this month, which affected Claude Code, Cursor, Codex CLI and others through malicious Git configurations, is a related data point. AI coding agents are being targeted because they run with meaningful system access.
What Anthropic Is Doing About It
The report itself is a form of accountability. By publishing it, Anthropic is creating a public record of the threat categories it is tracking and the cases it has shut down. The incidents described were identified and terminated. The company is clearly investing in threat intelligence rather than treating it as a PR afterthought.
The fact that none of the cases involved the most capable models is partly reassuring, but should not create complacency. Capable-enough models are already accessible to sophisticated actors.
What This Means for Business AI Decisions
If you are a business leader evaluating or expanding your AI investment, the practical takeaway is not alarm. It is calibration.
The AI models you deploy for data analysis, customer communications, and operational workflows are the same underlying technology being studied and probed by state-level threat actors. That does not mean you should not use them. It means you should use them with proper governance, defined scope, human oversight, and vendor relationships where transparency is valued.
Enterprise DNA works with businesses building AI capabilities across operations, data and customer experience. The question of what your AI agents are authorised to do, and what your oversight model looks like, is central to deploying AI that is both effective and defensible.
If you are building out an AI strategy and want to think through governance and agent design properly, talk to us.
Source
Bloomberg
Free Resource
Going deeper with Claude?
Get the free 32-page implementation guide for ANZ teams.
Your guide is ready
Check your downloads folder. If it did not open automatically, use the button below.
Download the GuideWant this working inside your business?
See what's possible