Anthropic has disclosed that an Iran-linked group used its artificial intelligence model, Claude, to support an intelligence-gathering operation targeting U.S. Navy warships. The company said it disrupted the activity, revealing how advanced AI systems can be repurposed for military reconnaissance, weapons research and other operations that pose national security risks.
The disclosure was included in Anthropic’s latest threat intelligence report, which examines the growing use of AI by adversaries to develop weapons, track dissidents, conduct cyber operations and support espionage. The report offers a glimpse into how AI is changing the methods used by state-linked groups and other malicious actors.
The company said the Iranian operation involved collecting publicly available information about U.S. naval forces and organizing it into intelligence material that could support military targeting.
AI Used to Track U.S. Naval Forces
According to Anthropic’s account, the Iran-linked actor used Claude to gather and analyze information about U.S. Navy ships operating in the Middle East. The operation reportedly focused on creating a targeting handbook containing details about naval assets and their movements.
The group used publicly available sources, including information from ship and aircraft tracking systems, commercial satellite imagery and other online resources. By combining these sources, the actor sought to develop a more detailed understanding of the location and activities of American military forces.
Anthropic said the group also compiled information about U.S. military personnel by extracting names from captions attached to public military photographs. Such activity demonstrates how information released through ordinary public communication channels can be aggregated into intelligence databases.
The company further reported that Claude was used to research potential vulnerabilities in shipboard systems, including maritime satellite communications equipment, Cisco networking products and industrial control technologies.
The disclosed activities indicate that AI can help adversaries accelerate the collection and organization of information that would otherwise require considerable time and human effort.
Anthropic Disrupts the Plot
Anthropic said it detected the misuse of Claude through its internal monitoring and investigation systems. After identifying the activity as a violation of its policies, the company banned the account associated with the operation.
The company also said it developed additional detection mechanisms and shared relevant information with government authorities to support efforts to counter the threat.
The disruption highlights the role AI developers are increasingly playing in identifying and preventing the misuse of their systems. Companies developing advanced models face growing pressure to ensure that their technologies are not used to facilitate military attacks, espionage or other harmful activities.
However, the incident also demonstrates the difficulty of identifying malicious intent. Requests to analyze satellite imagery, research software vulnerabilities or collect publicly available information may have legitimate applications. When combined into a coordinated intelligence operation, the same capabilities can become part of a potentially dangerous military workflow.
A Broader Pattern of AI-Enabled Military Activity
The Iranian naval operation was one of several cases described in Anthropic’s report. The company said other groups had attempted to use Claude for weapons development, cyber operations, surveillance and political influence.
In Yemen, a group reportedly associated with the Iran-backed Houthi movement used Claude in efforts to develop software for guided weapons, including rocket and missile-related systems. Anthropic said the activity involved technical research and attempts to analyze testing outcomes.
The report also described Russian-linked activity involving autonomous drone systems and Chinese-linked operations involving military technology and surveillance. These cases suggest that AI is being explored across multiple stages of military development, from engineering and software creation to intelligence gathering and operational planning.
Anthropic emphasized that the activities described did not necessarily result in successful weapons deployments or completed attacks. Nevertheless, the cases demonstrate the potential for AI to lower the technical and organizational barriers involved in sophisticated operations.
Implications for U.S. National Security
The disclosure has raised concerns about the vulnerability of publicly available military information. U.S. defense organizations routinely publish photographs, announcements and other material that support public communication. While such information is not necessarily classified, it can be collected and analyzed by adversaries.
AI systems make this process faster by allowing users to search, summarize, categorize and connect information from different sources. An operation that once required teams of analysts could potentially be supported by automated tools capable of processing large quantities of data.
The incident also highlights the importance of protecting military communication systems and addressing software vulnerabilities. Research into publicly documented weaknesses can be useful for defensive cybersecurity, but it can also be exploited by actors seeking to identify potential attack targets.
For the U.S. Navy, the episode underscores the need to consider how open-source intelligence and AI-assisted analysis could be used against deployed forces.

The Growing Challenge of AI Governance
Anthropic’s report arrives as governments and technology companies debate how advanced AI should be governed. AI models are increasingly capable of performing complex research, writing software and assisting with specialized technical tasks.
These capabilities offer substantial benefits in science, industry and defense. They also create opportunities for misuse by organizations seeking to conduct espionage, develop weapons or target individuals.
Anthropic has introduced safeguards intended to restrict harmful applications of its models. Yet the Iranian case illustrates that preventing misuse requires more than blocking individual requests. Developers must also identify patterns of activity in which multiple seemingly ordinary tasks contribute to a harmful objective.
The company said it would continue improving its monitoring systems and working with authorities to respond to emerging threats.
The revelation that Claude was used in an operation targeting U.S. Navy warships adds to growing evidence that AI is becoming an important tool in modern security competition. While the technology did not independently conduct a military attack in this case, it reportedly assisted in the intelligence and preparation stages.
As AI capabilities continue to advance, the ability to detect and disrupt such activities will become increasingly important for governments, technology companies and military organizations worldwide.



