Military engineers are now assisted by LLMs. (Oxana Chorna/Global Images Ukraine/Getty)


Peter Frankopan
Sep 16 2026 - 12:03am 6 mins

Over the past year, the AI community has become increasingly worried over the behavior of autonomous agents. Over the past week, that worry has hardened into panic — not least given the chatter, if vague and hard to verify, about a significant advance in recursive self-improvement at one of the world’s biggest frontier firms. Yet amid rumors and counter-rumors, and the recent suggestion by Donald Trump that “whoever wins AI wins”, one document may offer answers — less about the existential dangers of AI, and more about the threat it poses in the here-and-now.

Over 154 pages, a new report by Anthropic details some of the ways in which its Claude model has been misused over the past several months. With its talk of cyber-attacks, espionage and propaganda, it makes for terrifying reading, especially given how many actors — from Russian hackers to Chinese spies to Iranian propagandists — are now using the technology. As for Anthropic, it is able to monitor and assess how its systems are being used in real time, allowing the firm’s threat-intelligence team to track how Claude is being used.

One of the most eyebrow-raising examples comes from Yemen, particularly striking given the Houthis have established a presence on Perim Island, a strategically important position in the Bab al-Mandab Strait. Control of the island could strengthen the militants’ ability to threaten shipping through this narrow southern gateway to the Red Sea and Suez Canal, the primary maritime corridor linking Asia and Europe.

It’s striking, then, that Anthropic’s team identified a weapons-engineering cell in the north of the country that used Claude to work on three distinct programs, including a guided rocket and a ballistic missile with a range exceeding 2,000 kilometers. Tracking this activity made it possible to reconstruct the militia’s engineering workflows.

To put simply: the Houthis — or their affiliates or hired helpers — effectively used Claude Code as a substitute for software engineers, getting it to help develop guidance, navigation and control systems; integrate an open-source autopilot into a flight computer; tune controls; and even run simulations. Several Claude operations ran at once: one coding, another researching, and a third checking the first agent’s work. This was not mere experimentation by geeks with laptops. After all, it apparently resulted in the test-firing of a guided rocket. When this seemingly failed, the results were quickly plugged back into Claude to diagnose what had gone wrong.

“This was not mere experimentation by geeks with laptops. After all, it apparently resulted in the test-firing of a guided rocket.”

Anthropic says it has no evidence that an operational weapon was ultimately fielded, but the episode exposes an uncomfortable weakness in the way AI safety controls currently work. It is worth noting that Claude would not simply agree to design a missile on request; in fact, Anthropic says its safeguards blocked many of the Houthi cell’s requests. Still, they did not block all of them. By disguising the purpose of individual requests, and distributing the work across multiple sessions, the engineers were able to bypass controls.

Next stop: Iran. Here, we’re shown evidence of how Claude has been used to support propaganda, espionage and domestic repression. Again, this was not simply a matter of asking a chatbot to knock out a few inflammatory posts. Anthropic describes three operations in which Claude helped construct the machinery of an influence campaign: including writing campaign manuals; designing fake online personas; and compiling databases of people and organizations to target.

In one example, official intelligence bulletins were fed into Claude and transformed into content for different audiences — from Farsi to Arabic, Urdu to English — with the tone shifting alongside the language.

Iran also used Claude to disguise government narratives as the work of foreign writers. One network produced material intended for more than 100 online Iranian channels, including ones linked to the IRGC. More than that, Anthropic found evidence that Iranian propaganda was being camouflaged, falsely attributing arguments and findings to respected Western institutions like CSIS or the Brookings Institute.

More specific examples of Iranian AI-built propaganda are just as disturbing. Tehran-linked actors have been using Claude to build detailed profiles of hundreds of Israelis, and members of the Jewish diaspora, installing malicious software to steal people’s usernames, passwords and other login details. Elsewhere, Claude built a system to track US naval forces, securing personnel information from military photographs, among other sources.

The implications here are stark. Iran is hardly a superpower — and the Houthis certainly aren’t either — yet AI allows both to develop systems that would once have taken armies of engineers, programmers, analysts and linguists. That, in turn, opens the door to further disruption by non-state actors, causing chaos on the cheap. If the war in Ukraine shows how drones and other simple gadgets can nonetheless hamstring a well-armed opponent, AI could now do the same for espionage, cyber-warfare, propaganda and weapons development.

It’s telling, here, that even serious powers are learning these lessons too. After all, Anthropic’s tools have also been extensively used in Russia, despite the latter already boasting a formidable espionage apparatus of its own. That, however, hasn’t stopped Moscow from using Anthropic’s tech to make its activities better, faster and harder to tackle. That’s clear enough in the case of Midnight Blizzard, a hacking group closely linked to, or indeed part of, Russia’s SVR foreign intelligence service.

In practice, the hackers seemingly used Claude to make phishing attacks more convincing, while also helping them break into computer systems more effectively. For instance, hackers used the AI to double-check whether security software had spotted newly installed malware and, if it had, rewrite the code and try again until it slipped past the defenses. These tools were then deployed against a swathe of targets outside Russia: including government ministries, intelligence and defense bodies, think-tanks, and more. Perhaps unsurprisingly, Ukraine and its drone industry feature prominently.

It has been fascinating, too, to see Claude turning up in the toolkit of another major power: China. Again, the examples here are remarkable in their scope, with an outfit likely based in central China using Claude to spy on roughly 50 organizations worldwide, spanning industries from energy and healthcare to finance and technology.

One obvious question is why China would plump for the foreign-made Claude, not least given the People’s Republic has DeepSeek, Qwen, Kimi and other domestic AI tools to choose from. Though Anthropic’s report does not address this, the obvious explanation is that, for some jobs — not least a Chinese police-surveillance project — China thought Claude was the best option: particularly for coding, technical research, and coordinating complicated tasks.

According to Anthropic’s report, Chinese companies have also attempted to scale and distill Claude’s capabilities. Again, China hardly lacks engineers, data or computing power. But, just as a pace-setter is invaluable in a marathon, so too can Anthropic be exploited by its rivals, another reason to doubt Trump’s latest claims.

Nevertheless, it would be a stretch to conclude, as Trump has done, that America is winning, let alone has “won”, the AI race. If anything, indeed, the episode illustrates the peculiar nature of that contest. American companies may build the most capable models — but once those capabilities exist, the US’s adversaries can use them to their own advantage.

In a broader sense, meanwhile, these varied use cases put a subtler spin on all that breathless talk of AI collapse. The technology has hardly invented espionage, or propaganda, or ballistic missiles. But it is reducing the amount of expertise, labor and time required to do them all. Whatever the claims of looming extinction, the technology is being used, in nefarious ways, by a variety of flesh-and-blood actors right now. Rather than mass suffering and death, we should perhaps be more immediately worrying about our credit-card details being sold and our accounts drained — not by AI agents, but by human criminals a lot like us.

In an open letter published around the same time as his company’s report, Dario Amodei, chief executive of Anthropic, seems to acknowledge that the threat architecture has changed — and fast. Building AI too quickly is dangerous, he writes, but failing to build it risks placing the most powerful technology of the age “in the hands of authoritarian powers”. Any attempt to slow AI and tech development in the US is a threat: if the democratic world slows down, Amodei argues, “CCP-associated projects will pull ahead, creating significant national security risk”.

Among other measures, Amodei is therefore demanding tighter restrictions on the sale of advanced AI chips and semiconductor manufacturing equipment to China; a crackdown on chip smuggling and remote access to overseas data centers; and measures to stop Chinese companies distilling the capabilities of American frontier models. If these measures work, Amodei adds, they could “widen America’s lead significantly over the next 3-5 years.”

Seen in another light, though, Amodei’s proposals look a little more complicated. As CEO of a company preparing one of the largest flotations in history, arguing that its technology is so dangerous that the government needs to intervene in the market around it is unusual. He wants tighter controls on advanced chips; stronger restrictions on the dissemination of frontier capabilities; measures to stop competitors catching up; and government assistance to overcome antitrust problems. In all, it looks like a bid towards establishing a monopoly, rather than simply a concern with the consequences of new technologies. The longer the furor over the monopoly persists, anyway, the longer foreign misuse of Claude will remain obscured: to the West, if not its enemies.

This is a field that is moving extraordinarily fast, reason enough to take the warnings seriously. But the last few days have raised more questions than they have answered: about how immediate the dangers really are, who should decide how quickly AI develops, and about where safety and national security end and commercial self-interest begins. The risks are plainly enormous, as are the opportunities. What is less clear is whether we are witnessing genuine panic among those closest to the technology, or the opening moves in a struggle over who gets to control it. It may well be both.


Peter Frankopan is the author of The Silk Roads (2015), The New Silk Roads (2018), and The Earth Transformed (2023). He is also a Professor of Global History at Worcester College, Oxford.