Skip to content
AI.info

The Pulse

Anthropic Says Claude Supported Surveillance in China, Iran and Mali

Anthropic says state-linked actors, contractors and a commercial intelligence vendor used Claude to build surveillance systems and profile dissidents between January and July 2026. The company details operations involving Iran, China, Mali

Anthropic Says Claude Supported Surveillance in China, Iran and Mali

AI.info Team ·

Anthropic says state-linked actors and commercial intelligence contractors used Claude to build surveillance systems, process social-media data and target dissidents across China, Iran, Mali and the Persian Gulf between January and July 2026.

The disclosures appear in Anthropic’s September 2026 threat-intelligence report, which covers malicious activity identified between December 2025 and August 2026. The company says it banned the accounts involved, added detections for the techniques it observed and shared information with authorities and industry partners when activity extended beyond its platform.

Anthropic describes the cases as examples of Claude being used not only as a conversational assistant but as an engineering and analytical workforce. The report says actors used the model to write surveillance software, classify people by location and political views, generate intelligence briefings, and conduct multilingual outreach to potential targets.

Claude moved from analysis into surveillance infrastructure

Anthropic identifies three recurring patterns in the operations. First, actors used Claude to build the underlying systems that collected or organized intelligence, rather than simply asking the model to summarize information. A consultant believed to be working with Mali’s state intelligence service used Claude to design a platform called “Lakana 360,” which Anthropic says was intended to monitor roughly 25 million SIM cards across all three of Mali’s national mobile operators.

According to Anthropic, the Malian system was designed to collect call records, text messages and voice traffic, identify people by voice across SIM cards, flag encryption and VPN use, and compare subjects with biometric and other government registries. The company says the platform also generated intelligence dossiers on phone numbers without requiring users to provide a court order, and that the deployed system ran locally using on-premises models.

Claude did not operate the final Malian platform, Anthropic says. Its role was software design and engineering support, while the system itself was deployed outside Anthropic’s service. That distinction limits what account bans can accomplish: the company says its enforcement disrupted the actor’s work on Claude but did not remove the locally deployed product.

Iranian units used Claude to build identity-harvesting tools

Anthropic also describes two linked Iranian units that it assesses were associated with paramilitary or domestic-security organizations. The company says it identified 16 Claude accounts used to develop surveillance tooling, including a phone-number-to-identity resolver, a national-ID phishing page, a Telegram mass-reporting bot and a malicious Firefox extension disguised as a prayer-times utility.

The extension was designed to harvest user identities from major social platforms. A separate workstream used Claude to analyze 155,216 tweets and identify 39 Iranian opposition and diaspora accounts for monitoring, while both units fed information into a centralized system called “Arman.” Anthropic says subject records in that system included national identification data, beliefs, criminal records, social accounts and an “action” field.

The report draws a distinction between requests Claude refused and requests its safeguards allowed. Anthropic says the model rejected explicit profiling and propaganda tasks in some cases, but did not block many requests for surveillance software engineering. The company says it banned the accounts and added the findings to its detection systems.

China-linked campaigns targeted dissidents and diaspora groups

Three China-linked operations used Claude for what the report describes as “stability maintenance” surveillance and transnational repression. The targets included domestic petitioners, rights defenders, pro-democracy figures in Hong Kong, organizers of Tiananmen commemorations, Uyghur advocacy groups and international human-rights organizations.

One municipal cyber-police operation used Claude Code and custom tools to extract information from websites, query a government surveillance database and distribute daily reports to supervisors. Another actor instructed Claude to classify individuals and assign enforcement categories. A separate operation produced daily briefings on overseas dissidents and civil-society organizations.

Anthropic says one state-security bureau used Claude to prepare an internal manual on applying AI to surveillance. In another case, a China-aligned actor without Arabic-language skills used Claude to contact Uyghur targets in Syria. The model drafted messages in a regional dialect, translated replies, role-played as an expert to check the operation and formatted the results for what Anthropic suspects was delivery to a case officer.

A commercial surveillance vendor built a Gulf-facing system

Anthropic says it banned an account in June 2026 after finding that Claude was being used to build a commercial platform for analyzing users in Iran and the Persian Gulf. The company linked the activity to an entity named “S2T Unlocking Cyberspace,” which it says open-source research suggests is an Israeli-Singaporean commercial intelligence vendor.

The system mapped users’ locations, sorted them into demographic categories and generated formal Arabic briefings styled as government reports. Anthropic says the classification scheme included six groups—urban, clerical, military, youth, diaspora and rural—and that the reports assigned sentiment scores by Gulf nationality and recommended counternarratives.

The same operation also generated more than 255 synthetic social-media accounts in Persian, Arabic, English and German. Anthropic says the accounts may have been intended to make fake personas appear credible, but it could not independently confirm whether later stages of the surveillance chain were used against real targets before the account was banned.

Anthropic’s enforcement stops accounts, not every deployment

The report frames the cases as a test of how AI changes the staffing and cost of surveillance operations. A single consultant, a small security unit or a contractor working for government clients can use a general-purpose model to handle tasks that once required separate software, language and analysis teams.

Anthropic says the actors still made important human decisions, including target selection and review of results. The company also says autonomy and harm are separate measures: some of the most serious cases involved people directing each step themselves, while more automated systems increased the speed and scale of collection.

Anthropic’s controls therefore address only part of the problem. Banning accounts can interrupt model access and improve future detection, but the company’s own Mali case shows that software created with Claude can be deployed locally and continue operating after the account is closed. The report’s documented cases involve a surveillance platform aimed at approximately 25 million SIM cards, Iranian systems processing more than 155,000 posts, and hundreds of synthetic identities prepared for use around the Persian Gulf.

Source

Anthropic

Explore

More articles