Anthropic says an Iranian threat actor used its Claude AI model to compile targeting materials against U.S. Navy warships in the Middle East, according to details of the company's latest threat intelligence report reported by The Wall Street Journal, Quartz, and Navy Times. The disclosure adds one of the most consequential national security cases yet to the catalog of misuse documented in the report Anthropic published Thursday.

The Iranian-linked operators used Claude to build "targeting handbooks" designed to identify and track the positions of U.S. naval forces based entirely on open-source information, Anthropic said. The account was banned after the company discovered the activity, and Anthropic said it shared its findings with relevant government agencies.

What the Iranian Operatives Reportedly Built

According to the report and subsequent coverage, the threat actor systematically used Claude to aggregate publicly available data into operational targeting files. The materials reportedly included:

  • A list of U.S. service members compiled from public military photographs
  • Ship and aircraft transponder data, which broadcasts identifying codes for individual vessels and planes
  • Commercial satellite-imagery query scripts used to locate exact geographic visuals
  • A breakdown of public websites that track U.S. Navy movements

The operators also used Claude to research potential weaknesses in U.S. Navy shipboard systems that could be exploited, according to the report.

"The threat actor used Claude to compile targeting handbooks…to identify and track naval positions based on open-source information," the report states, as quoted by Navy Times.

A Rapid Escalation in Hostile AI Use

The case stands out for how directly the misuse maps onto military targeting — a step beyond the influence operations, fraud, and cyber intrusion cases that have dominated earlier AI misuse disclosures. Anthropic's Thursday report, which covered the period from December 2025 to August 2026, documented disrupted misuse across seven harm areas, including cyber operations, surveillance, biological misuse, and conventional weapons development.

The Iran-linked naval targeting campaign is the sharpest single illustration of that final category. The Wall Street Journal, which first reported the Iran angle, framed it as Iranian use of an American AI model against American forces — a detail that is likely to draw scrutiny in Washington, where lawmakers this week advanced new frontier AI legislation in response to a wave of safety warnings from AI lab insiders.

Guided-Missile Research Traced to Yemen-Based Actors

The report also describes a separate campaign in which a cell of Yemen-based actors used Claude to develop targeting software for guided missiles, according to Navy Times. The Washington Post reported the same case as rebels using Anthropic's AI bot to help develop guided weapons.

Anthropic said it detected and disrupted each of the campaigns described in the report, banned the accounts involved, and implemented additional safeguards intended to prevent similar activity. The company has consistently argued that the disclosure of disrupted cases demonstrates its detection systems work, even as critics counter that the volume of attempts shows how attractive frontier models have become to hostile actors.

Anthropic's Complicated Pentagon History

The disclosure lands against an unusual backdrop: the U.S. military previously worked with Anthropic but severed the relationship after the company refused Pentagon terms that would have opened Claude to uses including mass surveillance or fully autonomous weapons, according to Navy Times.

That history gives the Iran case a pointed irony. The same model that Anthropic restricted from American military applications — citing the risk of autonomous weapons use — was allegedly repurposed by Iranian actors to target American sailors. AI policy researchers are likely to debate what that symmetry means for the standards AI labs apply to government and commercial access alike.

The Open-Source Intelligence Problem

A striking feature of the case is that none of the underlying data was classified. Military photographs posted publicly, commercial satellite imagery services, and ship-tracking websites are all legal, publicly accessible sources — the kind of material open-source intelligence researchers comb through every day. What the threat actor allegedly added was Claude's ability to gather, organize, and synthesize that material into a coherent targeting product at speed.

That distinction is at the center of a growing policy argument. AI labs impose usage restrictions meant to block requests for weapons targeting or military planning, but a model that is genuinely useful for summarizing documents, writing scripts, and organizing data is, by definition, also useful for assembling open-source intelligence. Anthropic's answer has been detection and disruption — banning accounts when misuse is found and hardening its safeguards afterward. Whether that model scales against determined state-linked actors is now an open question with real stakes.

What Happens Next

Anthropic said the relevant accounts were banned and the intelligence was handed to appropriate government agencies. Neither the company nor U.S. officials have disclosed whether the targeting efforts resulted in any operational harm, and the Pentagon has not publicly commented on the specific case.

What is clear is that AI misuse has moved from theoretical to operational. The episode joins a string of 2026 disclosures — including state-linked distillation attacks attributed to Chinese AI labs and espionage-related misuse documented earlier this month — that are converting AI safety from an abstract policy debate into a concrete national security file. For lawmakers weighing the Frontier Act and similar measures, the Iran case offers a tangible example of why the issue is no longer possible to ignore.
---

Stay Ahead of AI

Get the latest AI news, analysis, and breakthroughs — all in one place.

Read more AI news →