WASHINGTON/NEW YORK A weapons engineering cell based in northern Yemen used Anthropic’s Claude artificial-intelligence system to assist in the development of guided rockets and advanced missile systems, including a ballistic missile with a stated range of more than 2,000 kilometres, according to a new threat-intelligence report by the US technology company.
Anthropic said it identified a group operating three weapons-development programmes. The projects included a guided rocket equipped with a commercially available, phone-class flight computer and terminal-phase homing guidance; a multi-stage ballistic missile with a stated range exceeding 2,000 km; and a multi-variant missile programme known as the R2000, which included a proposed hypersonic-glide-vehicle variant.
The company said the actors used Claude Code in place of human software engineers to develop guidance, navigation and control software used to steer and stabilise airborne vehicles. Multiple Claude instances were reportedly operated simultaneously, with different instances assigned tasks such as coding, technical research and reviewing software generated by another instance.
Anthropic said the group also used the system for flight-control firmware, position-estimation software, control tuning, flight simulations and post-test analysis. The company said the activity demonstrated how advanced AI models can reduce the amount of specialised human engineering expertise required for certain weapons-development tasks.
Failed rocket test followed by AI-assisted troubleshooting
The most significant development was a live test of a guided rocket in Yemen. Anthropic said it had no evidence that the actors succeeded in deploying an operational weapon, but the group did conduct a test launch that appeared to fail.
Within hours of the failed test, the actors returned to Claude and sought assistance in determining why the rocket had failed, according to Anthropic. The episode indicates that AI was being used not only during the design and software-development stages but also as part of the post-test engineering and troubleshooting process.
Anthropic said its safeguards blocked many of the group’s requests, but not all of them. The actors allegedly attempted to circumvent the restrictions by concealing the intended purpose of their work and dividing their activities across multiple sessions so that individual interactions did not reveal the full weapons-development programme.
The company subsequently banned the accounts associated with the activity and shared relevant intelligence with public- and private-sector partners. Anthropic also said the group had developed an offline simulation toolkit, meaning some of its weapons-development work could continue without access to Claude or other commercial engineering platforms.
Possible Houthi link
Anthropic did not identify the group as Houthi and did not state that the individuals involved were members of the Houthi movement.
However, the company said the weapons cell was based in northern Yemen, much of which is controlled by the Iran-aligned Houthis. The location and nature of the programmes have led several reports to assess that the activity was likely connected to the Houthi military infrastructure. That connection remains an assessment rather than a confirmed attribution by Anthropic.
The disclosure comes amid heightened regional tensions involving the Houthis, Saudi Arabia and maritime security in the Red Sea and around the Bab al-Mandab Strait. The Houthis have an established missile and drone capability, and their military activity has raised wider concerns over the security of shipping through one of the world’s most strategically important maritime chokepoints.
Wider AI security concerns
The Yemen case was part of a broader Anthropic report examining the misuse of Claude in conventional weapons development, cyber operations, surveillance, biological research, influence operations and fraud.
Anthropic said its investigators had identified and disrupted six cases involving weapons development or related procurement and intelligence activity in China, Russia and Yemen. The company said the findings demonstrated that frontier AI models are increasingly capable of assisting with tasks that historically required teams of highly trained specialists.
The company has introduced additional safeguards designed to detect and block requests associated with weapons development and said it is sharing information with governments and industry partners to reduce the risk of AI-enabled military proliferation.
The Yemen case nevertheless highlights a growing security challenge: even when an AI provider blocks a malicious account, users may retain technical knowledge, software and offline simulation tools developed during their interaction with the model. That could make AI-enabled weapons research increasingly difficult to detect and contain once it moves beyond the provider’s platforms.

