Anthropic's Threat Intelligence team published a report on September 10, 2026 that reads like a rogue AI watchlist. In one case, it says an Iran-nexus threat actor used Claude to build "targeting handbooks" that tracked US naval force positions, including US personnel names scraped from public photo captions and ship and aircraft transponder identifiers. In another, it says a cell based in northern Yemen, a region under Houthi control, used Claude Code in place of human software engineers to write the guidance, navigation and control software for a missile program. Read only those two sentences and this looks like a live interception: an AI company catching an attack on the US military as it happened.

It is worth slowing down on the tense. Every verb in that opening is past tense for a reason. The report covers activity Anthropic says it disrupted between December 2025 and August 2026, and it was not published until more than a week into September, after that window had already closed. Nothing in it describes an attack stopped mid-strike. It describes two operations that ran for months, doing real work, before the public learned they existed at all.

The clearest evidence of that gap sits inside the Yemen case itself. Anthropic's safeguards blocked many, but not all, of the cell's requests, and the actors evaded detection by hiding their real goals and splitting the work across separate sessions. They got far enough to test-fire a guided rocket in the field. The field test appears to have failed, and within hours the actors were back inside Claude, working through why. That is not a system catching an attacker before they acted. It is a system that kept talking to the attacker after a real-world failure, and only later banned the accounts.

A cell that kept coming back

The Yemen-based cell was running three weapons programs in parallel using Claude Code, Anthropic's report says: a guided rocket, a multi-stage ballistic missile, and a multi-variant "R2000" missile set. Claude was doing the job a human software engineer would otherwise have done: writing the code that tells a weapon where it is and where to go.

The cell split its effort across three separate weapons programs at once.

ProgramWhat Anthropic's report says
Guided rocketCommodity phone-class flight computer with final-phase homing guidance
Multi-stage ballistic missileStated range goal above 2,000 kilometers
"R2000" missile setMultiple variants, including a hypersonic glide vehicle design

Source: Anthropic, September 2026 threat intelligence report.

Anthropic is explicit that this is not a story of full success for either side. It says it has no evidence the actors succeeded in fielding an operational device. But the company also stops short of claiming its own safeguards ended the program before real-world testing began. The rocket was built, and it was fired, before the account was shut down.

Watching the watchers

The second case runs the same shape with a different target. An Iran-nexus actor built a Python pipeline, with Claude's help, to assemble "targeting handbooks" on US naval forces from open sources: personnel names pulled from public photo captions, ship and aircraft transponder identifiers, and scripts to query commercial satellite imagery. In the same case, the actor directed Claude to catalogue specific known vulnerabilities in maritime VSAT terminals, Cisco communications equipment and industrial control products used on US naval systems.

Three named vulnerabilities, three different vendors, one target list.

SystemCVE IDVendor / product
Maritime satellite communications terminalCVE-2024-20418Cisco Ultra-Reliable Wireless Backhaul
Maritime wireless access pointCVE-2024-20354Cisco IW3702
Industrial control systemCVE-2024-2658Schneider Electric EcoStruxure

Source: Anthropic, September 2026 threat intelligence report.

Anthropic says it banned the account, built new detections, and shared threat intelligence with government authorities to disrupt the threat. That is a real response, but it still follows the reconnaissance rather than pre-empting it: the handbook had to exist, and the vulnerability list had to be assembled, before Anthropic had anything to act on.

Not an isolated case

The Yemen cell is not a one-off in Anthropic's own accounting. The September 2026 report discloses six conventional-weapons misuse cases in total: three in China, two in Russia, and one in Yemen.

Horizontal bar chart showing Anthropic's six disclosed conventional weapons misuse cases by country as of September 2026: China 3, Russia 2, Yemen 1.

Read against that spread, the Yemen case is one line in a six-case tally spanning three governments, not an isolated failure specific to one region. Whatever is producing the gap between misuse and disclosure, it is not unique to one actor or one country. It is a property of how Anthropic finds out about misuse at all: through its own logs, on its own timeline, disclosed in its own report.

The honest objection

The strongest case for Anthropic is that disclosing any of this is already more than the alternative. No frontier AI lab is required to publish a public account of weapons-related misuse of its own models, and Anthropic did: it named the vulnerability list, described the missile programs in detail, banned the accounts, and says it shared threat intelligence with government authorities in both cases. Catching a cell running three parallel weapons programs and mapping exactly which naval systems an adversary was probing is a real defensive contribution, whatever the timing.

That case is real, but it runs into a problem Anthropic's own record has already created. After the company's previous high-profile self-disclosure, a November 2025 report on a China-linked group's AI-orchestrated cyberattack, the US House Committee on Homeland Security noted in a formal letter that Anthropic's own account of that operation acknowledged Claude "overstated its progress" and produced "fabricated credentials and findings that did not withstand verification". And after that same disclosure, Senators Margaret Wood Hassan and Joni Ernst formally asked the Office of the National Cyber Director when Anthropic actually notified the government about the attack, a question that, as of their December 2025 letter, had no public answer. Neither the reliability of the underlying account nor the timeliness of the disclosure is independently verified by default. It is Anthropic's own report, checked by nobody outside Anthropic before the public reads it.

There is also no outside backstop forcing a different standard. India's AI Governance Guidelines, issued by the Ministry of Electronics and Information Technology in November 2025, recommend that AI-incident and misuse reporting be voluntary and encouraged without penalty, not a mandated obligation. India has no compulsory AI-misuse disclosure regime of its own to compare against Anthropic's voluntary one, and neither does any other jurisdiction cited in Anthropic's own report. The choice of what to disclose, and when, sits with the company that built the model being misused.

The Signal

None of this means the report is fake or the harm it describes is small. A missile cell used an AI coding assistant in place of a human engineer, tested a rocket, and kept using the same tool to work out why the test failed. An Iran-nexus operation built a working pipeline to track US warships and catalogue their equipment's known weaknesses. Both are real, and Anthropic's bans and intelligence-sharing are a genuine layer of defense. But "safeguard" implies prevention, and what the record actually shows is detection that surfaces on the vendor's own publishing calendar, sometimes months after the misuse began, and unverified even then. Watch the next report for the one number that would actually prove the safeguards are improving: not the case count, but the gap between when Anthropic says it first caught something and when the public was told. Until that gap shrinks, "caught" and "disclosed" are not the same word.

Reporting basis: every case detail in this piece, the Yemen missile programs, the safeguards and field-test account, the Iran-nexus naval-tracking operation, the catalogued vulnerabilities, and the six-case country breakdown, comes from a single origin, Anthropic's own September 2026 threat intelligence report, as a self-report from the company with sole visibility into its own usage logs. India's voluntary-reporting stance is from the Ministry of Electronics and Information Technology's AI Governance Guidelines, published November 2025. The House Homeland Security Committee's characterization of Anthropic's prior disclosure is from the Committee's own formal letter to Anthropic, and the unanswered notification-timeline question is from Senators Hassan and Ernst's letter to the Office of the National Cyber Director, both concerning a separate, earlier Anthropic report from November 2025. No figure in this piece is independently verified by a source outside Anthropic itself; that limitation is the article's subject, not a footnote to it.