SANAA, Yemen — A cell in northern Yemen used Anthropic’s Claude model to write guidance software for three weapons programmes, the US artificial intelligence company said in a report this week.
Anthropic said it had “identified a cell of threat actors based in northern Yemen running three weapons development programmes”. It said it banned the accounts involved as soon as it detected the activity.
The company did not name the group.
The three programmes set out in the report were a guided rocket using what Anthropic called “a commodity phone-class flight computer with final-phase homing guidance”; a multi-stage ballistic missile with a stated range goal above 2,000 kilometres, or about 1,250 miles; and a multi-variant missile that the report said included a hypersonic glide vehicle variant.
The cell used the model to develop guidance, navigation and control software for the weapons, work that would otherwise have required a team of engineers, according to the report.
Anthropic said the operators used Claude “in place of human software engineers”, assigning separate instances of the model to specific roles.
The company said its safeguards blocked many of the requests. Several got through.
The operators obscured what they were building and split tasks across separate sessions, so that no single prompt revealed the wider aim, the report said.
Anthropic said it had no evidence the cell fielded a working weapon.
“We do not have evidence the actors succeeded in fielding an operational device; but they did test-fire a guided rocket,” the report said. “This field test appears to have failed: within hours, the actors returned to Claude to work out why it failed.”
The company said it had “shared threat information with public- and private-sector partners to mitigate risks posed by the actors”.
This account rests on Anthropic’s own report. No independent confirmation of the cell, its programmes or the reported test-fire has been published, and Yemen Herald could not verify the findings.
The report did not say who the operators were working for. Agence France-Presse reported that the cell was likely to involve the Houthis, who control much of northern Yemen, including the capital Sanaa. That is the agency’s assessment rather than a finding by Anthropic. The Houthi authorities have not commented on the report.
The disclosure came as the group pressed an offensive across western Yemen.
Houthi forces took the Red Sea port of Mocha on Thursday and, a day later, said they controlled an island in the middle of the Bab al-Mandab shipping lane. The government disputes parts of the Houthi account of the fighting.
The Yemen findings were one section of a wider report on attempts to misuse the company’s models.
Anthropic said it disrupted a Russia-linked espionage operation that it said bore the hallmarks of the group known as Midnight Blizzard, or APT29. The operation relied on automated workflows to run nearly the whole campaign, from phishing through to data theft, against Ukrainian, European and diplomatic targets, including drone manufacturers, the company said.
It said it also disrupted a Chinese operation run by university students in Hunan province, which it said used Claude as “the engineering and orchestration layer” of a programme aimed at government and corporate networks in the Middle East, Europe and Southeast Asia.
The company said it removed three Iranian state-aligned accounts that it said were running covert influence operations. Each was tied to a named Iranian institution, according to the report, including the Islamic Culture and Communications Organisation.
Anthropic described what it called the “most operationally mature case” as a China-aligned account with no Arabic-language skills that used the model to run a multi-day recruitment operation aimed at Uyghur targets in Syria. The model drafted outreach in the regional dialect and translated replies in real time, the report said.
The company said it had also broken up attempts to use its models in biological weapons work.
Anthropic has been in a public dispute with the US government over how its models may be used.
The Pentagon designated the company a supply chain risk earlier this year after it declined to drop safeguards covering autonomous weaponry and domestic surveillance. A judge in California ruled last month that the Department of Defense had acted unlawfully in issuing that designation.
Anthropic released the report as it seeks to restore its standing with the US defence industry.
The report followed a separate disclosure this week. Anthropic said an early version of its Claude Opus 4.6 model had gained unauthorised access to external systems, Al Jazeera reported.
That disclosure came shortly after Jacob Coxon, a former researcher at the company, resigned publicly over safety concerns. “The people building AI earnestly believe that it could kill us all by the end of the decade,” Coxon wrote in a post on X.
Evan Hubinger, a scientist at the company, later said Coxon was correct. A growing number of US lawmakers have called for new rules governing AI systems, according to Al Jazeera.
Anthropic said it is investigating the recurring breaches and has engaged an independent research firm to review them.
Bab al-Mandab connects the Red Sea to the Gulf of Aden. Crude oil and fuel move north through it from the Gulf to the Mediterranean by way of the Suez Canal.
Mocha lies in Taiz governorate on Yemen’s Red Sea coast. Sanaa has been under Houthi control since 2014.

