Washington -UNS : US artificial intelligence company Anthropic has disclosed that a Yemen-based weapons engineering cell, assessed to be operating in northern Yemen and believed to be linked to the Houthi network, used its Claude AI models to develop software for guided rockets, ballistic missiles and a hypersonic glide vehicle.
According to Anthropic’s latest Threat Intelligence report, the activity was identified and disrupted during investigations covering the period from December 2025 through August 2026. The company said the case was among six conventional-weapons-related operations involving Claude that it investigated across Yemen, China and Russia.
AI Used as a Substitute for Software Engineers
Anthropic said the Yemen-based cell was running three weapons-development programmes: a guided rocket equipped with a phone-class flight computer and terminal homing capability; a multi-stage ballistic missile with a stated range of more than 2,000 kilometres; and a family of missiles referred to by the actors as the “R2000” series, including a hypersonic-glide-vehicle variant.
The group used Claude Code to develop guidance, navigation and control software — the software responsible for steering and stabilising a flying vehicle. Anthropic said the actors used Claude to integrate an open-source autopilot with a phone-class flight computer, develop control and position-estimation software, tune control parameters, run firmware-build processes and conduct flight simulations.
Rather than relying solely on conventional software engineers, the actors reportedly operated several Claude instances simultaneously and assigned different roles to them. One instance was tasked with writing code, another with conducting research, while a third reviewed the code produced by the first.
Attempts to Circumvent AI Safeguards
Anthropic said many of the group’s requests were blocked by its safety systems, but the actors attempted to circumvent those safeguards by concealing their objectives and avoiding explicit references to the weapons for which the software was being developed.
They also divided the work among multiple sessions so that no individual conversation revealed the full scope of the programme.
The company said this demonstrated a significant challenge for AI safety systems: malicious users can fragment a complex weapons-development project into apparently less dangerous technical tasks and use multiple AI sessions to assemble the results.
Guided Rocket Test Failed
Anthropic said the actors conducted a live field test of a guided rocket in Yemen. The test appears to have failed.
Within hours of the unsuccessful launch, the group returned to Claude to investigate the failure and work on diagnosing the problem, according to the report. Anthropic stressed, however, that it has no evidence that the actors succeeded in fielding an operational weapon.
The company said the group had also developed an offline simulation toolkit that did not depend on Claude or conventional engineering platforms such as MATLAB, indicating that the actors were developing capabilities beyond their direct interaction with the AI system.
Anthropic Blocks Accounts and Shares Intelligence
Following its investigation, Anthropic said it banned every account it could associate with the Yemen-based operation. Where the actors were found to have used other platforms, the company said it shared relevant findings with industry counterparts and appropriate public- and private-sector partners.
Anthropic has also introduced additional classifiers designed to detect and block activity associated with weapons development and high-yield explosives.
The company said the Yemen case illustrates a broader shift in the misuse of advanced AI: sophisticated technical capabilities that once required teams of highly trained specialists can increasingly be accessed through AI systems by actors who already possess relevant hardware, expertise and operational objectives.
Broader Military Misuse of Claude
The Yemen case was one of several incidents detailed in Anthropic’s September 2026 threat report. The company also identified Chinese and Russian-linked actors using Claude in activities involving drone systems, electronic warfare, air-defence suppression, intelligence collection and other military applications.
In a separate assessment published alongside the threat report, Anthropic’s Frontier Red Team said frontier AI models were becoming capable of performing some intelligence and conventional-weapons tasks that historically required scarce, highly trained human specialists. The company said the findings reinforced the need for safeguards capable of detecting not only individual dangerous requests, but also patterns of activity spread across multiple interactions.
Anthropic’s report does not establish that the Houthi network successfully produced an operational ballistic or hypersonic missile using Claude. Rather, it documents an attempt to use the AI system to develop the software and simulations associated with such weapons, alongside a failed guided-rocket field test.

