Anthropic report reveals AI weapons, surveillance outlive their digital bans
From guided rockets in Yemen to Russian drone swarms, threat actors are leveraging AI to build offline executables, exposing the strict boundaries of cloud-level security enforcement, Anthropic report reveals.
Account termination is the primary defence for cloud artificial intelligence (AI) providers, but it remains an incomplete remedy as guided rockets in Yemen, Russian drone swarms, and Malian surveillance all outlive suspended accounts.
Anthropic’s September 2026 Threat Intelligence Report reveals how cloud bans fail when AI creates offline software or hardware firmware. And, the reality is highlighted by the three notable operations disrupted by the AI firm’s threat intelligence teams.
In West Africa, an independent consultant used the AI model Claude as the primary engineering workforce to build ‘Lakana 360’, a national surveillance platform for Mali’s state intelligence service. The platform monitors roughly 25 million mobile SIM cards across all domestic telecom networks, with legal warrant requirements intentionally removed from its automated intelligence dossier generator.
Because the system was deployed locally using on-premises models, Anthropic noted that “account enforcement actions do not affect the deployed product.”
Similarly, an engineering cell in Yemen managed multiple AI instances as virtual software developers to write guidance, navigation, and control software, the automated logic that steers flying vehicles, for guided rockets and ballistic missiles. After a live rocket test-fire failed, the operators returned to the AI within hours to diagnose post-flight telemetry errors, having already compiled a standalone simulation toolkit that operates independently of cloud access.
Meanwhile, freelance developers in Russia created autonomous kamikaze drone swarm code, known as ‘Serafim’ or ‘DronDoc’, capable of selecting targets and issuing detonation commands without human intervention, flashing the code directly onto physical development boards.
“As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer,” Anthropic said.
The findings reveal that software capabilities have dramatically compressed the labour gap that historically separated well-resourced state entities from small crews or individual operators.
Across the cybersecurity domain, AI’s role has evolved rapidly from a simple conversational assistant to an autonomous orchestrator. Russian espionage group Midnight Blizzard, tracked internally as GTG-20006, deployed multi-agent frameworks, sets of interconnected AI programmes working together on specialised tasks, to conduct intelligence gathering across Ukrainian and European government targets. When security tools flagged their deployed malware, automated AI agents autonomously modified and rebuilt the underlying code until it successfully bypassed detection signatures.
Elsewhere, criminal affiliates of the ShinyHunters network mass-scanned mobile applications for exposed API keys, the digital authentication tokens that grant access to software services, using stolen credentials to fund their attack workloads while claiming legitimate bug bounty payouts on the very vulnerabilities they exploited.
The application of frontier models has also extended into administrative manipulation and state propaganda.
In the Central African Republic, a Russian-backed media coordinator operating through Radio Lengo Songo used Claude to manage internal human resources for propaganda operations. The AI was tasked with drafting employment contracts mandating political loyalty, scoring local reporters’ articles for ideological alignment, and administering a three-strike dismissal process.
In Europe, a single French-speaking hacktivist used AI to build ‘fafsearch’, a dark-web doxxing platform, a searchable database designed to expose private personal information, which fused stolen national identity numbers with data exfiltrated from compromised political organisations.
These disclosures arrive at a pivotal moment for the broader technology industry. Major frontier AI developers including OpenAI, Google, and Anthropic are increasingly publishing threat intelligence findings to expose operational patterns and coordinate defenses across the sector.
Government regulators and international bodies are simultaneously introducing initiatives focused on identity verification, known in the sector as Know Your Customer standards, alongside real-time behavioural monitoring and proxy detection.
Anthropic noted that “AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators,” making intent, rather than technical sophistication, the primary distinguishing feature among modern threat actors.
As AI tools become deeply integrated into software engineering, industrial hardware, and administrative workflows, safety experts believe that relying solely on automated prompt filters is insufficient.
Protecting critical infrastructure will increasingly require verified access programs, hardware-level safeguards, and deeper cross-industry collaboration to identify malicious activity before compiled software artifacts are exported beyond the reach of cloud operators.


