Two separate groups used Anthropic’s Claude for military purposes, according to a threat report the company published in September 2026. One actor, linked to Iran, reportedly built targeting recommendations against U.S. naval forces. The other, a cell operating in northern Yemen, used Claude Code to advance three distinct weapons programs. Neither group succeeded in fielding an operational weapon.
Iran-Linked Actor Built Naval Targeting Profiles
An Iran-linked group used Claude to construct targeting data against U.S. naval forces, according to Anthropic’s report.
According to Anthropic’s report, an Iran-linked threat actor used Claude to generate targeting recommendations against U.S. naval forces. The actor reportedly combined publicly available ship and aircraft identifiers, commercial satellite imagery, and other open-source data to produce those recommendations.
Anthropic did not elaborate publicly on the scope of the targeting effort beyond what appeared in the report.
Yemen-Based Cell Pursued Three Weapons Programs
A northern Yemen-based cell used Claude Code across three separate weapons programs, Anthropic said.
A separate cell based in northern Yemen used Claude Code across three weapons development programs. Those programs included a guided rocket, a multi-stage ballistic missile with a reported target range above 2,000 km, and an R2000 missile family that reportedly included a hypersonic glide vehicle variant.
Reuters reported that the Yemen-based actors used Claude specifically for coding, simulation, and troubleshooting tasks. Multiple outlets, including AP and Reuters, link the cell to Houthi-controlled territory and describe the group as Iran-backed, though Anthropic’s report itself does not explicitly identify them as Houthi rebels.
No Operational Weapons Fielded; Anthropic Banned Accounts
No operational weapon emerged from either program, and one guided-rocket test the Yemen cell conducted ended in failure, AP reported.
Anthropic found no evidence that either group successfully fielded an operational weapon. The Yemen cell did conduct one guided-rocket test, according to AP, but that test failed.
After identifying both actors, Anthropic banned the associated accounts, added new detection mechanisms to its systems, and shared its findings with relevant authorities. The company did not specify which authorities received the information.
What the Report Actually Tells You
Anthropic’s September report documents misuse while also confirming the company detected and disrupted it.
Threat reports published by AI companies occupy an unusual space: they document misuse while simultaneously demonstrating that the company caught it. Anthropic’s September report confirms that state-linked actors are actively probing consumer-grade AI for military applications. The assistance Claude provided fell well short of producing a working weapon.
That outcome matters, but it does not settle the harder question this report raises. Whether detection keeps pace as these tools grow more capable, and whether banning accounts after the fact constitutes a sufficient answer, remains an open problem for the AI industry and the policymakers watching it.




























