When AI becomes the weapon: China’s model race, Russian spying, Mali surveillance and Yemen missiles
A new report from Anthropic shows how the AI is increasingly being pushed into far more sensitive areas — from stealing the capabilities of rival AI models and conducting espionage to mass surveillance and weapons development
Artificial intelligence is no longer being used only to write emails, generate images or answer questions. A new report from Anthropic shows how the technology is increasingly being pushed into far more sensitive areas — from stealing the capabilities of rival AI models and conducting espionage to mass surveillance and weapons development.
The cases documented by Anthropic between December 2025 and August 2026 offer a glimpse of how quickly AI is becoming part of the machinery of governments, intelligence operations, defence programmes and cybercrime. The company says it disrupted the activity it identified and used the findings to strengthen its safeguards.
What makes the cases striking is not simply what AI was asked to do, but how much work it was able to take over. In several operations, AI was used not as a simple chatbot but as an assistant that could research, write code, analyse information and help coordinate multiple tasks.
China’s AI race takes a new turn
One of the most significant parts of the report concerns what Anthropic describes as illicit “distillation” — essentially, using one powerful AI model to help improve another.
Anthropic says Alibaba used thousands of fraudulent accounts and proxy networks to send enormous numbers of requests to Claude. At its peak, the operation generated nearly three million exchanges a day. The aim was to collect Claude’s responses and reasoning-related data and use them as training material for Alibaba’s Qwen models. Between May and July 2026, Anthropic observed more than 151 million exchanges it attributed to Alibaba.
DeepSeek and Xiaomi also feature in the report. Anthropic says DeepSeek used techniques to extract Claude’s reasoning traces and, in some cases, quietly routed customer requests to Claude. More than 12.1 million exchanges were observed over 14 days in July.
Xiaomi, meanwhile, allegedly replayed conversations between its users and its own MiMo models through Claude to generate training data. Anthropic observed more than 400,000 requests across more than 1,500 accounts.
The larger message is clear: AI models themselves have become valuable targets. Their capabilities can be copied, studied and turned into training material for competing systems.
Russian espionage gets an AI boost
The report also describes an operation attributed to an actor whose activity is consistent with Russian state-linked espionage and has been publicly linked to Midnight Blizzard.
AI was used across almost the entire operation — from researching targets and creating phishing infrastructure to maintaining access and stealing data. The targets included Ukrainian and European governments, diplomatic organisations, defence bodies and people connected to US foreign policy.
The worrying part was the ability of the AI system to react to defenders. When malware was detected, AI agents could modify and rebuild it, with the process continuing until the malicious software was no longer detected. Anthropic said more than 20 organisations were targeted in the operation.
In other words, AI was not simply helping a hacker write code. It was helping run the operation.
In Yemen, AI reaches the missile programme
Perhaps the most dramatic example comes from Yemen.
Anthropic says a group involved in weapons development used Claude to design guidance software for a guided rocket. The group conducted a live test of a guided rocket and, after the test appeared to fail, returned to Claude within hours to analyse what had gone wrong. Anthropic says it has no evidence that an operational weapon was successfully fielded.
The same activity included work on ballistic-missile simulations and flight-control optimisation. The report says the actors also built an offline simulation toolkit, meaning some of the resulting capability could operate without Claude.
The implications extend beyond Yemen. Anthropic identified six conventional-weapons cases involving actors in China, Russia and Yemen, covering missiles, drones, bombs, electronic warfare and other military systems.
Mali shows the surveillance risk
If the Yemen case shows how AI can enter weapons development, the Mali case shows its potential impact on ordinary citizens.
Anthropic says an actor working with Mali’s state intelligence service used Claude as an engineering aid to build “Lakana 360”, a national surveillance platform covering roughly 25 million SIM cards across the country’s three mobile operators.
The system was designed to collect call records, text messages and voice traffic. It could also track people across SIM cards, identify the use of VPNs and encryption, create watch lists and connect information to biometric and other government databases.
Importantly, Anthropic says the final platform operated locally using an on-premises model. That means banning the user from Claude did not take the already-built surveillance system offline.
The biological question is even harder
The report also raises a different kind of concern: biology.
Anthropic says newer AI models are increasingly capable of assisting with complex scientific research. While the company says there is still no proof that such systems will be used to develop biological weapons in the real world, it says the earlier confidence that models could not meaningfully assist sophisticated users with dangerous biological research can no longer be maintained.
That uncertainty is itself the warning.
Across these cases, the common thread is not that AI has suddenly become autonomous and uncontrollable. Humans were still directing the operations. The change is that AI can dramatically reduce the time, expertise and manpower needed to carry out sophisticated work.
That may be the biggest lesson from Anthropic’s report: the AI race is no longer only about who builds the smartest model. It is increasingly about who can use those capabilities — and who can stop them from being misused.
Credit: Source link