Anthropic Blocks Iran’s Misuse of Claude for Propaganda and Surveillance

0
12

Key Takeaways

  • Anthropic’s September 11 threat intelligence report covers activity from December 2025 through August 2026.
  • The company says it blocked state‑linked users from Iran, China, and other nations who tried to use Claude for propaganda, surveillance, and influence operations.
  • Iranian cultural and propaganda bodies allegedly employed Claude to conduct “cognitive warfare,” including planning the funeral of Supreme Leader Ayatollah Ali Khamenei.
  • An MEK‑linked influence operation used a shared AI agent to impersonate real people, scraping over 500 social‑media channels to profile individuals inside Iran.
  • State actors reportedly built surveillance tools with Claude, such as a malicious Firefox extension and watch‑lists of opposition accounts.
  • Anthropic also claims criminals, researchers, and state institutions in Russia and China used AI models to design missiles, bombs, and deadly pathogens—these are allegations, not court‑proven facts.
  • The report highlights the growing need for AI safety measures, transparent threat‑intelligence sharing, and international norms to curb malicious model use.

Overview of Anthropic’s September 11 Threat Report
Anthropic released its latest threat intelligence report on September 11, detailing incidents observed between December 2025 and August 2026. The document asserts that the company disrupted multiple attempts by state‑aligned actors—particularly from Iran and China—to exploit its Claude large‑language model for propaganda, surveillance, and influence campaigns. According to the report, “Anthropic said it has disrupted attempts by Iran, China, and other countries from using its artificial intelligence (AI) models to disseminate state propaganda and spy on ethnic minorities and dissidents.” The authors also note that criminal groups, governmental agencies, and academic researchers in Russia and China were observed using AI models such as Claude and Gemini to pursue dual‑use research, including weapons and pathogen design. While the allegations are presented as company observations rather than adjudicated legal findings, they underscore a pattern of state‑level misuse of generative AI that Anthropic says it has actively countered through internal monitoring and mitigation actions.

Iranian State Institutions and Cognitive Warfare
The report singles out three Iranian entities—the Islamic Culture and Communications Organization, the Islamic Propaganda Office, and the Islamic Propaganda Organization—as users of Claude for what Anthropic terms “cognitive warfare.” These bodies, which operate under the Ministry of Culture and Islamic Guidance or as religious‑cultural groups, allegedly relied on the model to “build campaign plans, doctrine manuals, persona systems, target databases, and ministerial planning documentation.” A quoted passage explains, “Using the model in this manner allowed them to generate complex organizational frameworks and assets that would otherwise have required a fully staffed program office to produce.” In a specific instance, the Islamic Culture and Communications Organization used Claude to “complete organizational plans” for the state funeral of Supreme Leader Ayatollah Ali Khamenei that took place from July 3‑9, 2026. The report suggests that by automating the creation of doctrinal and logistical materials, these institutions could amplify regime narratives both domestically and abroad with significantly reduced manpower.

Details of the MEK Influence Operation
Anthropic also says it thwarted an influence operation linked to the Mujahedin‑e Khalq (MEK), an exiled opposition group designated terrorist by Tehran. The operation reportedly employed “a shared AI agent to impersonate real people and recruit inside Iran.” According to the report, “The operation successfully scraped over 500 social media channels to build detailed profiles of individuals inside Iran.” Those profiles were then segmented “by city, age, occupation, political alignment, and arrest history likely to help them tailor their messages to the specific audiences.” By leveraging Claude’s language‑generation capabilities, the MEK‑aligned actors could produce convincing personas and targeted messaging at scale, aiming to sow dissent within Iran while concealing their true origins. The company states that it disrupted the campaign after detecting the coordinated scraping and persona‑creation activity.

Surveillance Operations Enabled by Claude
Beyond propaganda, the report details surveillance efforts in which Iranian state‑aligned actors used Claude to build monitoring tools. One case involved the creation of “a malicious Firefox extension that harvested users’ identities from social media networks.” Another instance saw an Iranian actor employing Claude to “analyze hundreds of thousands of social media posts and chose 39 opposition accounts to monitor.” The report quotes Anthropic’s assessment: “The operators were state‑aligned organizations that targeted the same diaspora and dissident communities these regimes have historically targeted.” These findings indicate that generative AI was not only used to craft persuasive content but also to automate the identification and tracking of perceived threats, thereby lowering the technical barrier for conducting large‑scale social‑media surveillance.

AI‑Assisted Weapon and Pathogen Development
Anthropic’s allegations extend beyond information operations to the realm of dual‑use scientific research. The report claims that “criminals, state institutions, and scientists, including in Russia and China, were using AI models such as Claude and Gemini to design missiles and bombs as well as create deadly pathogens.” While the company provides no technical details or evidence of successful weaponization, it asserts that the models were consulted for tasks ranging from explosive formulation to pathogenicity prediction. The report emphasizes that these are “company allegations, not court verdicts,” and that no specific methodologies are disclosed. Nonetheless, the inclusion of such claims reflects growing concern among AI safety experts that large‑language models could accelerate illicit research and development by providing rapid access to specialized knowledge that would otherwise require extensive expert consultation.

Anthropic’s Mitigation Measures and Limitations
In response to the observed misuse, Anthropic states that it has implemented detection and interruption mechanisms aimed at curbing harmful model usage. The company did not elaborate on the exact technical controls—such as prompt filtering, usage‑policy enforcement, or monitoring of API calls—but emphasized that its threat‑intelligence team actively tracks patterns indicative of state‑linked or criminal activity. The report acknowledges that the actions taken are based on internal assessments and that the firm cannot guarantee cessation of all misuse, especially given the opaque nature of some actors’ operations. Anthropic’s approach mirrors a broader industry trend where providers rely on a combination of policy safeguards, usage monitoring, and threat‑intelligence sharing to mitigate abuse, while recognizing the inherent difficulty of fully policing model deployment across global jurisdictions.

Broader Implications for AI Governance and Security
The findings detailed in Anthropic’s report raise pressing questions about the governance of powerful generative AI systems. By demonstrating how state actors can harness models like Claude for cognitive warfare, surveillance, and even weapons research, the document underscores the need for robust international norms, export‑control considerations, and transparent accountability mechanisms. Experts cited in related discussions argue that voluntary self‑policing by companies must be complemented by regulatory frameworks that obligate providers to conduct rigorous risk assessments, share threat data with relevant authorities, and enable independent audits. As AI capabilities continue to advance, the balance between fostering innovation and preventing malicious exploitation will remain a central challenge for policymakers, technology firms, and civil society alike.


Note: All quoted passages are reproduced verbatim from the original article by Frud Bezhan.

https://www.eurasiareview.com/13092026-anthropic-disrupts-irans-use-of-claude-to-spread-propaganda-spy-on-dissidents/

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here