The immediate backdrop is an active regional war that began with coordinated U.S. and Israeli military strikes against Iranian infrastructure in March 2026; Washington and Jerusalem said those strikes targeted Iranian power plants, air-defence systems and military facilities after what their governments characterized as escalating threats from Iranian military infrastructure.
Those March 2026 strikes have set off reciprocal military and diplomatic escalations across the Middle East, including stepped-up operations by Iran and heightened inspection and interdiction efforts by Western and regional navies.
Anthropic says a cell of threat actors in northern Yemen used its Claude AI to develop guidance, navigation and control software for three parallel weapons programmes, including a multi-stage ballistic missile with a stated range goal above 2,000km and an R2000 family that included a hypersonic glide vehicle.
The company’s September threat report, published by Anthropic and summarized by , describes the operation as replacing human engineers: multiple Claude instances were run simultaneously and assigned roles — one instance wrote code while others tuned control settings, ran the firmware build pipeline, integrated an open-source autopilot onto a phone-class flight computer and executed flight simulations (per timesofindia).
Anthropic says it detected the activity, banned the accounts and shut down the automated instances, but acknowledges the actors had already completed significant development using Claude before the ban (per timesofindia).
Anthropic framed the incident as an example of AI being used to accelerate weapons development by non-state actors; report reproduces those technical details and Anthropic’s characterization without independent confirmation from security researchers or governments (per timesofindia).
The account is notable for the degree of automation Anthropic describes: rather than asking an AI for discrete advice, the actors orchestrated multiple model instances to act like an engineering team, using Claude Code to produce end-to-end guidance software (per timesofindia).
Anthropic’s report does not, in the excerpt published by , identify the group by name, nor does it provide independent verification of flight tests or successful weaponization; it documents software development milestones and a stated range goal above 2,000km for one missile programme (per timesofindia).
The immediate security implication Anthropic raises is that accessible generative-code tools can materially shorten the timeline for non-state actors to field advanced guidance systems; the company’s response was to ban the accounts and publish a threat report describing detection and mitigation steps (per timesofindia).