AI Safety

Anthropic says Claude users in Houthi-held Yemen tried to build missile software

A new AP report and Anthropic threat intelligence findings show how users in northern Yemen attempted to use Claude Code for advanced weapons development before being blocked.

Published Updated
AnthropicClaudeAI SafetyMilitary AI

Anthropic's latest threat disclosures have moved from abstract warnings about AI misuse into the sharper territory of battlefield technology. The Associated Press reported on September 12 that users in Houthi-held northern Yemen attempted to use Claude to support advanced missile development before Anthropic identified and blocked the accounts. The company did not say the users succeeded in fielding an operational weapon, but it said the activity included work on guidance, navigation and control software and a failed guided-rocket test.

The Yemen case comes from Anthropic's September 2026 threat intelligence report, which covers misuse investigations from December 2025 through August 2026. According to the report and AP's coverage, the actors pursued three weapons programs, including a multi-variant missile designed to accept different warheads and guidance systems, a hypersonic glide concept and a warhead that would use mobile-phone hardware to maneuver during flight. Anthropic said the users relied on Claude Code instead of human software engineers for parts of the guidance software effort and had built an offline simulation toolkit before the accounts were banned.

One detail made the case especially concrete. Anthropic said it knew a guided rocket test had failed because the users returned to Claude with questions about why it did not work. That does not prove the group had the industrial base to produce advanced missiles, and AP quoted outside weapons specialists who were skeptical that the Houthis could build true hypersonic systems. Still, the episode matters because AI can lower the cost of experimentation for groups that already have access to drones, rockets, electronics and open-source military knowledge.

The Houthis, who control much of northern Yemen and have used Iranian-made missiles and drones, denied that they would depend on open sources for military development. A Houthi political official told AP that the group's weapons are used for self-defense and argued that its forces already have accumulated modern capabilities. Independent analysts, however, told AP the group has become more technologically sophisticated than many outside observers assume, especially as conflict around the Red Sea and Bab al-Mandeb Strait raises the strategic value of long-range and anti-ship weapons.

For AI companies, the case illustrates a difficult moderation problem. A model that can help engineers write and debug code can also help actors design simulations, organize technical documents and iterate on control systems. The same pattern appears across Anthropic's broader report, which discusses cyber operations, influence campaigns and biological-risk cases alongside the Yemen incident. The company says it shared findings with public and private partners and incorporated lessons into enforcement and safeguards.

The broader implication is not that a chatbot can manufacture a missile by itself. It is that AI systems are becoming capable enough to accelerate pieces of dangerous workflows when used by people who already possess domain knowledge or physical resources. That is why the Yemen case is likely to feed policy debates about model access, usage monitoring, export controls and coordinated disclosure. It also shows why frontier AI safety is increasingly inseparable from ordinary geopolitical security.