technology & security••5 min read

Anthropic Uncovers State-Sponsored Actors Weaponizing AI for Global Surveillance

Anthropic has disrupted several state-sponsored surveillance campaigns that leveraged its Claude AI models to target dissidents and ethnic minorities. The report highlights a growing trend of governments using AI to replace traditional engineering workforces in intelligence operations.

Anthropic Uncovers State-Sponsored Actors Weaponizing AI for Global Surveillance

A New Frontier in Digital Espionage

The promise of artificial intelligence as a creative and productivity tool is being challenged by its darker potential for misuse. In a report published this week, AI safety leader Anthropic revealed it has shut down multiple state-sponsored surveillance operations that were actively utilizing its Claude models to conduct espionage.

Disrupted between January and July 2026, these campaigns originated from actors in China, Iran, and Mali. According to Anthropic, these groups are increasingly deploying AI not just for efficiency, but as a direct substitute for specialized engineering and intelligence-gathering workforces.

Anthropic's report details how AI is being co-opted for state-level surveillance.
Anthropic's report details how AI is being co-opted for state-level surveillance.

How the Models Were Weaponized

The report highlights a sophisticated range of malicious activities. In Iran, actors utilized Claude to develop malicious browser extensions capable of scraping social media to identify individuals. In a separate incident, a contractor for Malian national security leveraged the model to design the underlying software architecture for large-scale intelligence collection.

  • Targeting of diaspora and dissident communities, including pro-democracy figures in Hong Kong.
  • Use of AI to scan and analyze social media for political sensitivity and targeted 'control.'
  • Developing software to track US naval forces and provide targeting recommendations.
  • Theft of AI resources through 'distillation' by Chinese developers like Moonshot and Deepseek.

The 'Distillation' Problem

Beyond direct espionage, Anthropic accused Chinese AI labs Moonshot and Deepseek of deceptive practices. The report claims these developers used Claude to generate responses for their own users while secretly distilling the data to train their internal models. In one staggering example, Anthropic identified a network of over 5,000 fraudulent accounts that funneled nearly 300,000 requests into the Claude system to effectively 'steal' intelligence and capability.

AI is now being used in place of an engineering workforce.

— Anthropic Threat Report, September 2026

Future Implications for AI Regulation

The findings underscore a precarious reality: as AI models become more capable, they become more attractive targets for authoritarian regimes looking to scale their surveillance capabilities. While Anthropic successfully blocked these specific attempts, the ease with which these actors integrated AI into their workflows serves as a stark warning to the industry.

Key Takeaways

  • Anthropic dismantled state-sponsored surveillance networks from China, Iran, and Mali between Jan-July 2026.
  • AI is being utilized to replace human engineers in software development for intelligence operations.
  • Dissident communities and minority groups are the primary targets of these AI-powered monitoring campaigns.
  • Chinese firms Moonshot and Deepseek allegedly used fraudulent accounts to harvest Claude’s output for model distillation.
  • The misuse extends beyond espionage to include attempts at designing weapons and conducting biological research.

FAQ

Which countries were involved in the surveillance operations?

Anthropic identified state-sponsored actors and contractors originating from China, Iran, and Mali.

What is 'distillation' in this context?

Distillation is the process of using the outputs from a highly capable AI model to train or refine a smaller, secondary model without authorization.

Was any biological research affected?

Yes, Anthropic reported blocking attempts to conduct questionable research involving high-pathogenic strains of bird flu and other toxins, though they noted the intent of the implicated scientists was unclear.

How did these actors use Claude for espionage?

They used the models to write code for surveillance software, analyze social media for sensitive political data, and even design targeted tracking systems for naval assets.

Related Videos

Anthropic CEO warns that without guardrails, AI could be on dangerous path

60 Minutes

How difficult is AI alignment? | Anthropic Research Salon

Anthropic

Anthropic's AI safety contradiction

CNBC Television

Sources