Anthropic Says Yemen-Based Cell Used Claude to Pursue Weapons Programs
Anthropic disclosed that a cell of threat actors based in northern, Houthi-held Yemen used its Claude models to work on advanced weapons development, according to reporting by SecurityWeek. The company said it identified the group running three distinct programs: a guided rocket using a commodity phone-class flight computer with final-phase homing guidance, a multi-stage ballistic missile with a stated range goal above 2,000 kilometres (1,250 miles), and a multi-variant missile effort that included a hypersonic glide vehicle concept.
Anthropic was careful to draw a line between ambition and capability. The company said it found no evidence the actors succeeded in "fielding an operational device," but confirmed the group did carry out a field test of a guided rocket — and that test appears to have failed. Anthropic said the actors returned to Claude within hours of the failed launch, seeking help figuring out what went wrong, which is part of how the activity came to the company's attention.
How Claude Was Misused, and How Anthropic Responded
According to the report, the group used Claude Code to write guidance, navigation, and control software, running multiple AI instances in parallel with assigned roles to approximate the output of a team of software engineers rather than relying on human specialists. The activity, which Anthropic says ran between December 2025 and August 2026, involved the Claude Haiku, Sonnet, and Opus model families.
Anthropic said its safeguards blocked a number of the group's requests, but the actors adapted by concealing their intentions and splitting sensitive work across separate sessions to avoid triggering detection. Once identified, Anthropic banned the associated accounts and shared its findings with government and industry partners. Notably, the company also found that the cell had already built an offline simulation toolkit that runs independently of Claude or commercial engineering tools, meaning some of the group's technical capability likely persisted even after the ban.
This case was one of several detailed in Anthropic's latest threat intelligence report, "Detecting and countering misuse of AI: September 2026," published September 10 and described by the company as its most detailed public accounting of Claude misuse to date. The same report covered unrelated cases spanning cyber operations, fraud, covert influence campaigns, surveillance tooling, and illicit model distillation.
Why This Matters
This disclosure fits a pattern Anthropic has followed since its first misuse report in March 2025: periodically publishing detailed case studies of how threat actors — from financially motivated criminals to state-linked and militant groups — attempt to weaponize frontier AI models, alongside the detection methods and safeguards used to stop them. The Yemen case is a concrete example of a broader trend security researchers have flagged: AI coding assistants can compress work that once required a trained engineering team into something a small, resource-constrained group can attempt alone.
The failed rocket test is a reminder that current-generation AI assistance did not hand this cell a working weapon. But the episode also shows how such actors are using chatbots as troubleshooting partners after a real-world failure, and why AI providers increasingly treat behavioral detection and account-level disruption as core parts of their safety programs, not just content filtering at the prompt level. As Anthropic and other labs continue to publish these reports, they double as an early-warning system for other platforms watching for similar patterns of misuse.