Houthi-linked cell used Claude to write missile guidance software
Anthropic's September threat report has a weapons section, and it is the part carrying the fewest qualifiers: a group in northern Yemen used Claude in place of human software engineers, and Russia-linked freelancers built a drone that picks its own targets.
Anthropic says operators in northern Yemen used Claude — in place of human software engineers — to write missile-guidance and flight-control software, assigning different instances of the model separate engineering roles. The report, the company's fourth public threat-intelligence disclosure, covers both a guided rocket and a long-range ballistic missile, per the Financial Times' reporting, and says the operators appear to have conducted a test-fire that failed — within hours, they were back with Claude working out why. Anthropic says its safeguards blocked many individual requests, but the group got past them by obscuring intent and breaking the work across separate sessions, so no single prompt gave the operation away. Anthropic says it has no evidence the group fielded a working weapon, banned the accounts involved, and shared what it found with public- and private-sector partners.
That obfuscation detail is the real finding. The control that failed was not a weak classifier but the assumption that dangerous work arrives as one clearly-scoped request — a program split into a hundred innocent-looking sessions is a program no single-model filter ever sees end to end, and it is the same shape Anthropic describes in the report's biological cases, where researchers spent weeks on avian influenza adaptation and chikungunya gain-of-function work whose stated purpose was legitimate. Anthropic's own admission is blunter still: older models sat well below the level where they could meaningfully assist bioweapons work, and the company says that "is no longer a certainty with newer models" — which is why it added tighter dual-use bio filters to Claude Fable 5 and later. We covered the cyber half of this report this morning — Anthropic says lone hackers now run state-level cyber campaigns.
A separate cluster of Russia-linked freelancers used Claude Code to build an autonomous drone system that can select targets and issue detonation commands with no human in the loop. The report names it DronDoc (also tracked as Serafim): a first-person-view drone swarm with shared memory, guidance and attack logic, and an onboard model whose target classes include "person." Talks on lethal autonomous weapons have debated exactly this capability for a decade; what the report documents is a non-state group assembling it with a commercial coding assistant inside a single development cycle. Anthropic says it disrupted the activity and banned the accounts.
What to watch: whether Washington or Brussels moves on lethal-autonomous-weapons language now that the common denominator is a commercial coding tool rather than a defense contractor — and whether the split-task trick from the Yemen case turns up in someone else's telemetry next.
If safeguards break on split tasks rather than on bad prompts, is any single-model filter ever the right place to look? Tell us in the comments.
Sources: Anthropic — Detecting and countering misuse of AI: September 2026 · Financial Times — Houthis used Anthropic AI to try to build ballistic missiles · Al Jazeera — Anthropic claims Claude AI used for missile projects, global espionage · Ars Technica — Claude users found ways around safeguards for bioweapons research · Tech Times — Anthropic threat report: AI models near bioweapons threshold · The Register — Latest Anthropic horror story chills with tales of kamikaze drone swarms