Anthropic recently revealed that a “cell of threat actors based in northern Yemen,” most likely linked to the Houthis, utilized Claude in an effort to build out missile capabilities. The one field test Anthropic documented appears to have failed, and the company has since banned the accounts involved. Still, the revelations add a new variable to both the Anthropic narrative and the ongoing conflict in the Middle East.
September has been a busy month for Anthropic public relations. Amid a flurry of releases, including new interactive tools and an essay by CEO Dario Amodei arguing for a slowdown of AI development, Anthropic also published a threat intelligence report on September 10.
The report, which recounts nefarious actors’ attempts to use Claude for research that could support biological weapons, cyber espionage, surveillance operations and influence operations, also details how Anthropic’s technology is being used to build conventional weapons.
Most news outlets picked up on the Houthi story and emphasized it in their reporting. However, in the same report, Anthropic also lists a China-based actor using Claude to draft fire control software for undersea warfare, and likely freelance Russia-based actors using Claude Code to engineer an autonomous kamikaze drone swarm.
Three Programs, One Failed Launch
The Anthropic users in Houthi-controlled Yemen, whose identities are unknown, used Claude for three separate programs. The first was a guided rocket built around a commodity, phone-class flight computer, with homing guidance for the final phase of flight. The second was a multi-stage ballistic missile with a stated range goal above 2,000 kilometers. The third was a family of missiles, dubbed the “R2000” set, that included a hypersonic glide vehicle variant.
Anthropic says the cell used Claude Code “in place of human software engineers” to write the guidance, navigation and control software that steers a weapon in flight. The operators ran several Claude instances at once, one writing code, one doing research and one reviewing the work, much like a lead engineer delegating to a small team.
The cell hid its intent by concealing what the software was for and splitting its work across multiple sessions, so no single session revealed the full picture. Anthropic says its safeguards blocked many of the cell’s requests, but not all of them. By the time Anthropic banned the accounts, the cell had already built an offline simulation toolkit that runs without Claude or engineering software such as MATLAB.
Six Cases, Three Usual Suspects
What’s notable about Anthropic’s threat report is what’s not shared. In the introduction to its conventional weapons section, Anthropic says it has “investigated and disrupted multiple threat actors who used Claude.” It chooses to detail six of them, while keeping the public in the dark about the rest.
All six originate in places that are adversarial to the United States: Houthi-controlled Yemen, China and Russia. It’s conceivable that threat actors in countries ostensibly allied with the United States, or in the United States itself, are also enlisting American AI. But we are not privy to that information.
Disrupting, or Aiding?
The section covering the Houthi missile work is titled: “Disrupting a Yemen-based guided weapons engineering cell using Claude to develop guidance software.” It’s an interesting choice of words. One could swap out “Disrupting” for “Aiding” and it would be just as factually accurate.
Anthropic did eventually flag the accounts and ban them, but not before the cell had test-fired a guided rocket. Within hours of that apparently failed launch, the cell was back on Claude, working out what went wrong. Anthropic says it found the activity through internal investigations into suspected weapons development. Its summary of the case doesn’t say when.
Several news outlets ran headlines saying that Anthropic foiled a Houthi plot, or disrupted it. Anthropic’s own account is messier. The report covers activity disrupted between December 2025 and August 2026, and it gives no start date for the Yemen cell. What it does make clear is that the cell had time to write guidance software, run flight simulations, test-fire a rocket, diagnose the failure, and package a simulation toolkit that survived the ban. For perspective, that window opens nearly three months before the war in Iran began on February 28.
Revenge of the Idea Guys
Claude and its competitors are marketed as tools that don’t require technical know-how to use. In fact, the lack of technical expertise needed is one of the frontier models’ main selling points.
In a May conversation with Stripe CEO Patrick Collison, Sam Altman, CEO of OpenAI, said that the rapid advancement of AI coding abilities meant “all of a sudden it’s like revenge of the idea guys.”
Altman explained that at Y Combinator, the startup accelerator he ran before becoming OpenAI’s full-time CEO, they used to make fun of people who lacked the technical skills to build out their ideas. The thinking went that without the technical expertise, ideas weren’t all that valuable. But now, with the proper prompts, AI models can tackle the technical requirements.
In Altman’s view, this presents a paradigm shift in which technical skills matter less than a person’s ideas. The problem for AI labs is that they can’t control or predict what “ideas” their users want to develop. It could be an app that sells athleisure wear, or it could be a biological weapon, or ballistic missiles in Yemen. In Yemen, the idea guys wanted a guided rocket, and Claude Code stood in for the engineers.
Anthropic and Its Many Masters
Anthropic competes with frontier labs in the United States and, increasingly, with open-source AI coming out of China. The Claude maker has emphasized the need for safety guardrails much more than its competitors, but has done little in the name of safety that has slowed its own progress.
As the AI lab barrels toward an October IPO that its investors expect to value it at $2 trillion or more, it’s hard not to see all the safety talk, at least partially, as a form of marketing. In Anthropic’s words:
“Historically, this kind of work has been uncovered by governments, United Nations panels, and outside investigators, who piece it together from recovered hardware and public sources. But as a frontier model provider, we can identify this activity ourselves if we detect threat actors violating our Usage Policy and terms of service.”
While this may be true, Anthropic’s response is far from instantaneous. And while the AI lab may have tightened its safeguards in light of threat actors’ use of Claude, the list of threat actors is only growing. The same report details an Iran-linked actor that used Claude to compile targeting handbooks on U.S. naval forces in the Middle East.
Half a Dozen Engineers and $9 Billion
Anthropic isn’t acting alone, either. The National Security Agency (NSA) may have fallen behind the technical wizardry of American frontier models, but it is making up for lost time. In May, the White House approved a secret $9 billion request, still pending in Congress, for the chips U.S. spy agencies need to run frontier models on classified networks.
This month, the agency launched its most extensive restructuring in at least a decade, with AI among five new organizations. And its push has been aided by roughly half a dozen Anthropic engineers embedded at the agency to help deploy Mythos, the company’s restricted cyber model.
The Chokepoint Changes Hands
Meanwhile, after a major military offensive over the past few weeks, the Houthis have seized nearly all of Yemen’s western coast, including Perim Island in the middle of the Bab al-Mandab Strait, the chokepoint in and out of the Red Sea. Government forces say they have retaken some ground near the strait. Saudi Arabia, the world’s biggest oil exporter, relies heavily on the Red Sea, especially since the war in Iran began.
With the Red Sea under threat and the fighting around Iran continuing, Brent crude climbed back over $100 a barrel on September 10, and the Iran-aligned Houthis have gained significant leverage. Saudi Crown Prince Mohammed bin Salman called President Donald Trump twice on September 10, urging U.S. strikes on the Houthis and was turned down, according to Axios, though Washington has stepped up intelligence and targeting support for the Saudi campaign. Other Middle East powers are rethinking their strategies and relationships with international partners.
The Houthis’ weapons capabilities have grown significantly since the 2022 truce. While Anthropic might have banned one northern Yemen cell from using Claude, it’s certainly possible other threat actors are using similar tactics.
Or perhaps they have moved on to open-source Chinese AI, whose technology is increasingly distilled from American frontier models like Claude. On September 8, the NSA, CISA and the FBI issued a joint advisory warning of as much, naming six Chinese companies, including DeepSeek and Alibaba.
The Toolkit Outlives the Ban
Anthropic calls this its most detailed threat report to date, and it deserves credit for putting the cases on the record. It is also a study in what a ban can and can’t do. The Yemen cell split its work across sessions, hid what its code was for, test-fired a rocket and left with a simulation toolkit that runs without Claude. Anthropic’s safeguards blocked many of its requests. The program went ahead anyway.
Every weapons case the company chose to publish traces back to Yemen, China or Russia. Those are the cases the public gets to see, weeks before an IPO its backers expect to top $2 trillion, and in the same season its engineers are helping the NSA put Mythos to work. What the report can’t tell anyone is how many cells are still doing the same work, on Claude or on the Chinese models distilled from it.
Anthropic banned the accounts. The toolkit doesn’t need them.
Author: Tim Tolka
See Also:
“We Must Pace the Frontier”: Who Is For It, and Who Is Against It?
Anthropic IPO Valuation at $2tn: Who Prices It, Who Regulates It?

