Technology

How Claude is being used by bad actors to build weapons

Jamie McKane 4 min read
How Claude is being used by bad actors to build weapons

Key Points

  • Anthropic has published a comprehensive threat report which details how its Claude AI has been misused by threat actors.
  • The report looked at seven harm areas, which included the development of conventional weapons.
  • Anthropic said a cell in Yemen used Claude to try and build guidance for ballistic missiles.
  • Claude was also used by threat actors in China to document anti-torpedo systems and by threat actors in Russia to develop kamikaze drone swarms.

Anthropic, the US-based company which operates Claude, said that its AI has been used by bad actors across the world to try and develop missiles, military drones, and other weapons systems.

In a threat intelligence report published this month, the company said it had identified and disrupted operations in which threat actors tried to use Claude for malicious activity. It said that in each case it has discovered, it disrupted this activity, strengthened its safeguards, and shared intelligence with authorities where appropriate.

The report look at activity across seven harm areas, including cyber operations, influence operations, and conventional weapons development, and found that Claude Haiku, Sonnet, and Opus models were used in these cases of misuse.

“The cases we share here aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date,” Anthropic said.

“We’re publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer.”

Developing software for weapons

Anthropic said it identified a ‘cell of threat actors’, reported by the Financial Times to be the Houthis, which used Claude to develop guidance, navigation, and control (GNC) software that is used by flying vehicles such as drones.

The cell used Claude to integrate an open-source GNC onto a phone-class flight computer, and the threat actors relied on several Claude instances running at once, assigning each a role within a virtual AI engineering team.

“Our safeguards blocked many of their requests, but not all of them,” Anthropic said.

“The actors used a variety of tactics to evade our safeguards, including hiding their goals and the products the software was meant for, and they split their work across multiple sessions so no single session revealed their full intent.”

The same cell also used Claude to design guidance software for guided missiles, Anthropic said. It said that from these sessions, it learned that the actors test-fired a guided rocket in a failed field test. Claude was used to develop flight control firmware, terminal guidance, and to diagnose telemetry from the failed test.

Claude was also used by these actors to build an offline simulation toolkit for ballistic missile simulation.

Claude Weapons
Source: Anthropic

Yemen wasn’t the only region in which threat actors used Claude to attempt to develop conventional weapons systems.

Anthropic said it identified a threat actor in China which used Claude to draft documentation for an anti-torpedo weapons system and to compare this system against similar US programmes.

The company also disrupted freelance threat actors in Russia who were trying to build a full-stack autonomous kamikaze drone swarm. Claude Code was used to write and test the code involved and save it directly into their project files.

In this case, Claude was used to build the core software required for the drone swarm and its target selection.

AI threats continue to mount

Conventional weapons development is an alarming misuse of a cutting-edge AI model, but it is just one of seven categories of misuse Anthropic published in its comprehensive threat report.

Anthropic noted that cyber attacks are becoming increasingly prevalent and dangerous due to AI, and they no longer require sophisticated attackers.

“The cybersecurity skills of AI models means that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators,” Anthropic said.

“As models continue to evolve and improve, we assess that more actors, from lone wolves to organized entities, will continue to adopt AI frameworks to enable more sophisticated cyber attacks at greater speed and scale.”

An overarching theme of the analysis is the increasingly autonomous way AI is being used in cyber operations. These include multi-agent frameworks deployed against multiple victims in parallel for up to days at a time.

“In economic terms, AI autonomy compresses the cost side of attacker ROI calculations, lowering the skill threshold and labor required per campaign, while leaving potential payoffs largely unchanged,” Anthropic said.

Essentially, almost all types of attacks are becoming cheaper thanks to AI models, making them easier to apply more widely and with less direction.

Now read: The UK government used AI to count its own red tape and found 7,000 rules