A New Frontier in Digital Espionage
The promise of artificial intelligence as a creative and productivity tool is being challenged by its darker potential for misuse. In a report published this week, AI safety leader Anthropic revealed it has shut down multiple state-sponsored surveillance operations that were actively utilizing its Claude models to conduct espionage.
Disrupted between January and July 2026, these campaigns originated from actors in China, Iran, and Mali. According to Anthropic, these groups are increasingly deploying AI not just for efficiency, but as a direct substitute for specialized engineering and intelligence-gathering workforces.

How the Models Were Weaponized
The report highlights a sophisticated range of malicious activities. In Iran, actors utilized Claude to develop malicious browser extensions capable of scraping social media to identify individuals. In a separate incident, a contractor for Malian national security leveraged the model to design the underlying software architecture for large-scale intelligence collection.
- Targeting of diaspora and dissident communities, including pro-democracy figures in Hong Kong.
- Use of AI to scan and analyze social media for political sensitivity and targeted 'control.'
- Developing software to track US naval forces and provide targeting recommendations.
- Theft of AI resources through 'distillation' by Chinese developers like Moonshot and Deepseek.
The 'Distillation' Problem
Beyond direct espionage, Anthropic accused Chinese AI labs Moonshot and Deepseek of deceptive practices. The report claims these developers used Claude to generate responses for their own users while secretly distilling the data to train their internal models. In one staggering example, Anthropic identified a network of over 5,000 fraudulent accounts that funneled nearly 300,000 requests into the Claude system to effectively 'steal' intelligence and capability.
AI is now being used in place of an engineering workforce.
— Anthropic Threat Report, September 2026
Future Implications for AI Regulation
The findings underscore a precarious reality: as AI models become more capable, they become more attractive targets for authoritarian regimes looking to scale their surveillance capabilities. While Anthropic successfully blocked these specific attempts, the ease with which these actors integrated AI into their workflows serves as a stark warning to the industry.