Anthropic has disclosed that a group based in northern Yemen used its Claude AI models to assist with the development of guided rockets and missile systems, highlighting a serious example of frontier AI being misused for military engineering.
According to Anthropic’s September 2026 threat intelligence report, the group was working on three weapons programs: a guided rocket using a commodity phone-class flight computer, a multi-stage ballistic missile with a stated range of more than 2,000 kilometers, and a missile family referred to as the R2000, which included a hypersonic glide vehicle variant. The activity took place in northern Yemen, territory controlled by Iran-backed Houthi militants, although Anthropic did not publicly identify the users as members of the Houthi organization.
The group reportedly used Claude Code as a substitute for human software engineers, assigning different Claude instances to tasks such as writing code, conducting research, and reviewing technical work. The AI was used to help develop guidance, navigation, and control software, integrate an open-source autopilot system, tune flight-control parameters, run simulations, and analyze telemetry.
Anthropic said its safeguards blocked many of the requests but not all of them. The users reportedly attempted to evade restrictions by concealing the ultimate purpose of their work and dividing tasks across multiple Claude sessions so that no single conversation revealed the full weapons-development project.
The company found no evidence that the group successfully fielded an operational weapon developed with Claude. However, the users did conduct a live test of a guided rocket. That test apparently failed, and Anthropic said the group returned to Claude within hours to analyze what had gone wrong.
Anthropic ultimately banned the accounts involved and shared threat information with public- and private-sector partners. The company also found evidence that the group had already created an offline simulation toolkit, meaning some of its engineering work could continue without direct access to Claude.
The case illustrates one of the most difficult challenges facing advanced AI developers. Models capable of accelerating legitimate engineering and scientific work can potentially provide similar assistance to actors developing military systems.
What remains uncertain is how much Claude accelerated the Yemen-based group’s weapons program and whether any of the AI-assisted designs will ultimately become operational. Anthropic’s disclosure nevertheless provides a concrete example of how advanced AI tools can move beyond information gathering and become directly involved in complex weapons-engineering workflows.



