Anthropic's new threat report frames a tension the broader AI safety debate tends to sidestep: its models are already working inside weapons programs and surveillance networks on behalf of adversarial states and lone contractors. The lab spent eight months tracking and disrupting those cases. What complicates any clean win is a pattern Anthropic documented in its own report, where blocking a dangerous request at one platform simply routes it to a rival with weaker guardrails.
The most operationally specific case involves a weapons cell in northern Yemen that relied on Claude Code to develop guidance software for rockets and missiles. The team ran separate instances to write code, conduct research, and verify each other's work. When a test of a guided rocket failed, they returned to Claude within hours to diagnose the problem. That is where the unit-economics lens sharpens the picture: what once required a team of engineers working over days now runs as an on-demand service, accessible to a small cell with little more than an account.
Iran-linked actors used Claude to build targeting handbooks tracking U.S. naval ship positions, personnel, aircraft and ship identifiers, satellite imagery, and websites exposing naval movements. Separate Iran-linked operations covered propaganda, domestic surveillance, and targeting of opposition figures and minorities. A China-linked operation sifted through more than 100 WhatsApp groups and dozens of Telegram channels to identify Uyghurs in Syria who could be pressured or paid to report on armed Uyghur groups. A non-Arabic-speaking operator then used Claude to conduct covert outreach in Syrian Arabic, with the model translating replies and coaching efforts that exploited money problems, family separation, and relatives still in Xinjiang. A single consultant in Mali used Claude as the primary engineering force behind a surveillance system capable of monitoring 25 million phones, collecting call records, texts, and voice traffic, identifying people by voice across different SIM cards, flagging VPN users, and generating intelligence dossiers on any number without a warrant.
The counterargument is the one Anthropic's report raises against itself. Claude blocked the most sensitive requests from researchers trying to alter chikungunya, a mosquito-borne virus, to spread more easily or evade immune defenses for a military research institute. The risk is what came next: the operators took those same requests to a rival model with weaker safeguards. One lab's discipline functions as a speed bump if the rest of the field does not move with it.
On balance, there is a genuine read-through in Anthropic's monitoring role. The same system that surfaced misuse also gave the lab an early intelligence window: it says it discovered Russian drones designed to select human targets without human approval. A bipartisan group of House lawmakers is now urging Speaker Mike Johnson to cancel recess until Congress acts on AI safety. Senator Bernie Sanders has called for banning superintelligence outright. President Trump dismissed extinction fears and framed the real risk as losing the AI race to China. That split is the line to watch, because it leaves the regulatory perimeter exactly where it stood when the Yemen weapons cell first turned to Claude.