Anthropic claims Claude AI used for missile projects, global espionage人格组织声称克劳德人工智能被用于导弹项目和全球间谍活动
AI was used to develop missile guidance software in Yemen and to power cyber operations, a report alleges.

AI was used to develop missile guidance software and to power state-linked cyber-espionage operations, a new report reveals.
[Dado Ruvic/Reuters]
Anthropic AI claims to have thwarted multiple malicious operations using its Claude models, ranging from cyber-espionage and weapons design to mass surveillance campaigns.
On the conventional weapons front, the company alleges in a new report that it intervened in northern Yemen, blocking an effort to deploy Claude for missile guidance software, including a guided rocket and a long-range ballistic missile.
list 1 of 3 US judge blocks Pentagon blacklisting of AI firm Anthropic
list 2 of 3 Sony, Warner Music sue Anthropic, saying it pirated songs to train its AI
list 3 of 3 US pushes looser approach to AI regulation, while EU pushes new law
AI-assisted missile and rocket development
According to Anthropic’s threat report, the operators used Claude “in place of human software engineers”, reportedly assigning different instances of the model specific roles to write missile-guidance and flight-control software.
While internal safeguards blocked many requests, Anthropic admitted several slipped through. The operators avoided detection by obscuring their ultimate goals and breaking tasks across separate sessions, so no single prompt gave away the operation.
The company said it has no evidence the group managed to field a working weapon, though Anthropic claimed the operators appeared to have conducted an unsuccessful test-fire.
The report stated that the company banned the accounts involved and “shared threat information with public- and private-sector partners to mitigate risks posed by the actors”.
State-linked cyber-espionage
The report alleges that a Russian-linked espionage operation bearing the hallmarks of Midnight Blizzard (or APT29 ), which Anthropic said relied on automated AI workflows to run nearly the entire operation, handling everything from phishing and setup to data theft against Ukrainian, European and diplomatic targets, including drone makers.
Separately, the company said it disrupted a Chinese operation run by university students in Hunan province, who used Claude “as the engineering and orchestration layer” of an offensive programme targeting government and corporate networks across the Middle East, Europe and Southeast Asia.
In both cases, Anthropic said it banned the associated accounts and deployed additional monitoring to detect similar activity.
Identifying targets, including in Syria and Iran
Anthropic also alleges that it identified and removed three Iranian state-aligned accounts using Claude to run covert influence and psychological operations. Each operation was tied to a named Iranian propaganda institution, including the Islamic Culture and Communications Organisation and a Mashhad seminary command room distributing content aligned with the Islamic Revolutionary Guards Corps’ (IRGC) narratives.
In another instance, the report alleges that state-aligned groups used Claude for an industrial-scale operation, directing the model to generate structured profiles that mapped targets by location, demographics, political leanings, and confidence scores.
“The most operationally mature case,” Anthropic noted in its report, was detected when a China-aligned account “with no Arabic language skills” used Claude to run a “multi-day recruitment operation to infiltrate Uyghur targets in Syria”. Anthropic said, “the model drafted outreach in the regional dialect” and “translated replies in real time”.
Earlier this week, Anthropic revealed yet another incident of an AI model gaining unauthorised access to external systems involving an early version of Claude Opus 4.6, shortly after former company researcher Jacob Coxon publicly resigned over safety concerns.
“The people building AI earnestly believe that it could kill us all by the end of the decade,” Coxon warned in a post on X. A further Anthropic scientist, Evan Hubinger, later chimed in, saying Coxon was correct.
The researchers’ warnings have led a growing number of US lawmakers to call for new rules to govern AI systems.
Anthropic said it is investigating the recurring issues and breaches across the incidents and has engaged an independent research firm to review them.
Relationship with Washington
Relations between Washington and the AI company remain fraught following a contentious standoff over ethical guardrails. Earlier this year, the Pentagon blacklisted the company as a supply chain risk after it refused to drop safeguards against using its technology for autonomous weaponry and domestic surveillance.
Anthropic challenged the decision in California, where a judge ruled last month that the US Department of Defense had acted unlawfully in issuing the designation. Yet despite the bitter legal battle and public friction, the Pentagon has reportedly deployed the firm’s Claude models in military missions in Iran and Venezuela.
The report arrives at a critical juncture for the company as it seeks to restore full standing within the US defence industrial base following the Pentagon’s blacklisting.
一份新报告显示,人工智能已被用于开发导弹制导软件,并为与国家有关的网络间谍活动提供支持。
[达多·鲁维奇/路透社]
Anthropic AI 声称利用其 Claude 模型挫败了多起恶意行动,包括网络间谍活动、武器设计以及大规模监控活动。
在常规武器方面,该公司在一份新报告中声称,它干预了也门北部,阻止了部署克劳德导弹制导软件的努力,该软件用于制导火箭和远程弹道导弹。
美国法官阻止五角大楼将人工智能公司 Anthropologie 列入黑名单(共 3 例,第 1 例)
列表 2/3:索尼和华纳音乐起诉 Anthropic,称其盗版歌曲用于训练人工智能
(共3条)美国力推宽松的人工智能监管方式,而欧盟则推动新法律出台。
人工智能辅助导弹和火箭研发
根据 Anthropic 的威胁报告,操作人员使用 Claude“代替人类软件工程师”,据报道,他们为该模型的不同实例分配了特定角色来编写导弹制导和飞行控制软件。
尽管内部安全措施拦截了许多请求,但 Anthropic 承认仍有一些请求漏网。操作人员通过模糊最终目标并将任务分散到不同的会话中来规避侦测,因此没有任何单一的提示会暴露他们的行动。
该公司表示,没有证据表明该组织成功部署了可用的武器,但 Anthropic 声称操作人员似乎进行了一次不成功的试射。
报告指出,该公司已封禁涉事账户,并“与公共和私营部门合作伙伴共享威胁信息,以降低攻击者带来的风险”。
与国家有关的网络间谍活动
该报告称,一项与俄罗斯有关联的间谍行动带有“午夜暴雪”(或 APT29)的特征,Anthropic 表示,该行动依靠自动化人工智能工作流程来运行几乎整个行动,处理从网络钓鱼和设置到针对乌克兰、欧洲和外交目标(包括无人机制造商)的数据窃取等所有事情。
此外,该公司表示,它破坏了湖南省大学生运营的一项中国行动,这些学生利用 Claude 作为攻击性计划的“工程和协调层”,该计划的目标是中东、欧洲和东南亚的政府和企业网络。
Anthropic公司表示,在这两起事件中,他们都封禁了相关账户,并部署了额外的监控措施来检测类似活动。
确定目标,包括在叙利亚和伊朗的目标
Anthropic公司还声称,他们识别并删除了三个与伊朗政府有关联的账户,这些账户利用Claude进行秘密影响和心理战。每项行动都与一个指定的伊朗宣传机构有关,包括伊斯兰文化与传播组织和一个位于马什哈德的神学院指挥部,该指挥部传播的内容与伊朗伊斯兰革命卫队(IRGC)的叙事一致。
报告还指出,在另一个例子中,与国家结盟的团体利用 Claude 进行大规模行动,指示该模型生成结构化概况,按位置、人口统计、政治倾向和信心评分绘制目标。
安特罗皮克在其报告中指出,“操作最成熟的案例”是,一个与中国结盟、“不懂阿拉伯语”的账户利用克劳德开展了一场“为期数天的招募行动,旨在渗透叙利亚境内的维吾尔族目标”。安特罗皮克表示,“该模型使用当地方言撰写宣传材料”,并“实时翻译回复”。
本周早些时候,Anthropic 披露了另一起人工智能模型未经授权访问外部系统的事件,该事件涉及早期版本的 Claude Opus 4.6。此前不久,该公司前研究员 Jacob Coxon 因安全问题公开辞职。
“人工智能的开发者们真心相信,到十年末,人工智能可能会毁灭我们所有人,”考克森在X网站上发表的一篇文章中警告说。另一位人类学家埃文·胡宾格后来也表示,考克森的说法是正确的。
研究人员的警告促使越来越多的美国立法者呼吁制定新的规则来管理人工智能系统。
安特罗皮克公司表示,他们正在调查这些事件中反复出现的问题和违规行为,并已聘请一家独立研究公司进行审查。
与华盛顿的关系
在围绕伦理准则的激烈争论之后,华盛顿与这家人工智能公司之间的关系依然紧张。今年早些时候,五角大楼将该公司列入供应链风险黑名单,原因是该公司拒绝放弃禁止将其技术用于自主武器和国内监控的保障措施。
Anthropic公司在加利福尼亚州对该决定提出质疑,上个月,一名法官裁定美国国防部发布该项认定属于非法行为。然而,尽管经历了激烈的法律诉讼和公众舆论的摩擦,据报道,五角大楼已在伊朗和委内瑞拉的军事行动中部署了该公司生产的Claude型号无人机。
这份报告的发布正值该公司寻求恢复其在美国国防工业基础中的完全地位的关键时刻,此前该公司已被五角大楼列入黑名单。