AI developer Anthropic has reported that a militant group in northern Yemen used its Claude AI model to help develop missile weapons. While the company does not directly name the group as the Houthis, both the Associated Press and the Financial Times link it to that movement, which controls a large part of northern Yemen.
According to Anthropic, the group was simultaneously working on three projects: a guided missile, a multi-stage ballistic missile with a claimed range of over 2,000 kilometers, and a missile family designated R2000, which was meant to include a hypersonic glide weapon.
Anthropic notes that Claude was used as more than just an advisor — it was effectively put in the place of software engineers, tasked with developing the missile's flight control and stabilization systems. The militants ran several sessions of the model in parallel: one wrote code, another conducted research, and a third checked the first one's results. The company compares this to the work of a small engineering team, with a manager distributing tasks among staff.
The AI helped build software for flight control, navigation and guidance, and was also used in modeling and other stages of development. According to Anthropic, its built-in safeguards blocked some of the requests, but not all of them. Users deliberately disguised their true purpose by splitting tasks into numerous separate conversations, so that no single fragment revealed that the end product was a weapon.
The most alarming episode came when development moved from computer simulations to real-world testing: the militants carried out a trial launch of a guided missile in Yemen. Anthropic says there is no evidence that a complete, deployable weapon was ever finished or fielded, and the test itself appears to have failed.
Just a few hours after the test, the same users returned to Claude with questions about the cause of the malfunction — meaning the model was used not only at the design stage, but also to analyze the results of an actual launch. Anthropic subsequently blocked the accounts linked to the group and shared the information with partners in the public and private sectors.
It later emerged, however, that before the accounts were blocked, the militants had already built their own autonomous offline simulation tool, independent of Claude or any other computing service. This highlights the limits of simply cutting off access to a single AI model: doing so may slow certain stages of development, but the bad actors were simultaneously building up their own technology and expertise.
The Yemen episode is just one part of a much larger Anthropic report, published in the early hours of Friday. Running to more than 150 pages, the document describes cases of AI misuse in cyberattacks, propaganda, surveillance of individuals, fraud, biological research, conventional weapons development, and unauthorized acquisition of AI capabilities — covering the period from December 2025 to August 2026.
Anthropic stresses that these are not ordinary chatbot policy violations, but rather the most serious and recent cases its teams have managed to detect and stop. This suggests that the real scale of AI misuse in practice is considerably higher.
Source: novinky.cz