VECTOR WIREAI INTELLIGENCE
UTC
Refresh Models Deals Regulatory Sources

Anthropic threat report: governments in Mali, China, Iran used Claude for surveillance

Anthropic's 154-page threat report details how state-linked actors in Mali, China, and Iran used Claude models for surveillance, bioweapons research, and…

Anthropic published a 154-page threat intelligence report on September 10 detailing how state-linked actors in Mali, China, and Iran used Claude models to build and operate surveillance systems targeting dissidents, journalists, and political figures1,3.

The report covers Claude misuse Anthropic disrupted between December and August2. Anthropic said it banned every account tied to the surveillance operations it uncovered and strengthened its safeguards based on what it found.

A single consultant, a whole surveillance apparatus

In Mali, a single consultant working for national security authorities used Claude to create a system that collects data from the country's mobile operators and builds dossiers on individuals. The Malian government ultimately deployed its surveillance platform locally using other models after Anthropic's enforcement created friction.

Iranian actors used Claude to build and deploy a malicious Firefox browser extension that harvested users' identities from social networks. Separately, in June, Anthropic banned an account that used Claude to build a commercial surveillance platform designed to spy on people in Iran and the Persian Gulf, detecting the use case before it became operational.

A religious affairs intelligence office in China reduced its operations from many teams of analysts to a single office, using an AI assistant to produce thousands of investigations per month, according to the report. The Chinese government used Claude to analyze social media data, determine how politically sensitive posts were, and select possible targets for what officials called "control," which could include coercive questioning or closer monitoring. One Chinese state security bureau created an internal manual for using AI in surveillance operations, and other officials used Claude to automate daily intelligence reports and query government surveillance databases.

All surveillance cases in the report involved Claude Haiku, Sonnet, or Opus rather than Anthropic's newer Fable or Mythos-class models.

Beyond surveillance: bioweapons and cyber operations

The report extends well beyond surveillance. Criminals, state-sponsored groups, spyware vendors, scientists, and propagandists attempted to use Anthropic's models to design missiles and bombs, create deadly pathogens, and conduct cyberattacks5. Anthropic said it disrupted several potential plots this year by scientists using its models for research that could have helped develop biological weapons, though the company said it could not determine whether the research was legitimate or nefarious, leading it to shut down the work6.

Anthropic said individual hackers are now sustaining campaigns that would have needed many skilled operators a year ago, because AI has absorbed the labor that used to set state-backed teams apart. Jacob Klein said AI tools are making state-backed surveillance cheaper and more efficient rather than fundamentally changing who governments target, and that AI is increasingly allowing individual government employees or contractors to automate work that once required teams of analysts. Klein also said Anthropic has seen actors move to open-source models after its safeguards or enforcement created too much friction.

ANALYSIS The Mali case illustrates the displacement dynamic: Anthropic's enforcement disrupted the operation on Claude, but the government migrated to other models and deployed locally. The pattern Klein described, where actors shift to open-source alternatives after encountering friction, limits the effectiveness of any single provider's enforcement actions.

Anthropic said it published the report because it believed it had a responsibility to disclose malicious misuse of its services.