Skip to content

Product1 publisher2 min readPublished

Anthropic banned an account that chained Claude into an automated Navy targeting pipeline

Anthropic's misuse report describes public transponder identifiers, commercial imagery and vendor vulnerability research being assembled into targeting handbooks, and says separate missile-software requests from Yemen passed its safeguards.

The Product Desk · Product desk

Illustration accompanying Anthropic banned an account that chained Claude into an automated Navy targeting pipeline

What happened

  • Anthropic says it detected and disrupted an Iran-linked operation that used Claude against US Navy forces, then banned the account and shared information with government authorities.
  • The company says the model was not used to launch an attack autonomously, but to collect, organize and analyze information, automate open-source intelligence work and produce material that could support military planning.
  • The same actor used Claude to research vulnerabilities in shipboard systems, including maritime satellite terminals, Cisco communications equipment and industrial-control products.
  • The case is one of several in a 154-page report on misuse of Anthropic's models covering activity between December 2025 and August 2026.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Anyone writing an AI acceptable-use policy has to decide in words whether assembling open sources into a targeting handbook is prohibited use, because each input in that pipeline is legal to ask for on its own.
  • constraint Controls that score one message at a time cannot see a handbook being built over days, so credible misuse enforcement depends on identity resolution and log retention that vendors leave off their pricing pages.
  • exposure Whoever operates that shipboard equipment now has a documented adversary research interest to answer for, and the patching schedule belongs to them.
  • precedent A provider that bans accounts and hands information to governments sets the expectation that rival labs will do attribution and referral too, and that paying customers' traffic gets read with the same tools.

What Anthropic describes catching is an automated pipeline that turned ship and aircraft transponder identifiers, commercial satellite imagery and photographs of US military personnel into targeting handbooks [3].

The Yemen case in the same report shows what review one message at a time costs. Anthropic says users in northern Yemen tried to develop software for advanced missile systems, that it blocked some of those requests, and that others passed its safeguards before it banned them [8]. Anthropic did not say how many got through. The Wall Street Journal reported the findings first [6].

Machine-assisted targeting is nothing new for the US military either. Project Maven was created to run machine learning and computer vision over imagery to identify objects of military interest, and US Army publications say the newer systems scan large quantities of imagery, flag potential targets and feed them into existing targeting workflows, with human analysts responsible for validation [9]. In a 2026 exercise, the Army described Maven Smart System as able to process thousands of hours of surveillance video and automatically flag objects of interest [10].

That line matters because of what happens downstream of a target list. The Associated Press reported that a US strike on February 28 hit the Shajareh Tayyebeh school in Minab and killed at least 168 people, most of them children [11]. The Washington Post reported that the school had appeared on a US target list and may have been mistakenly identified as a military site, and that questions had been raised about whether AI-assisted target identification played a role; that reporting does not establish that AI caused the strike or that a system selected the school [12]. Israeli officials have described their Lavender system as an analytical aid and not an autonomous target-selection system [13].

Place your own deployment by asking whether the harm shows up inside one request, and whether anything in your stack scores a sequence of them. The classifiers most teams already run handle the easy cases: bad single asks get refused, and benign sequences of benign asks are fine. What they miss is harm that appears only in aggregate while review happens one message at a time, and that is where those Yemeni missile-software requests went through [8]. Getting past that means the session is the unit under review, and Anthropic's own look-back ran nine months [15].

What to watch

  • Whether Anthropic publishes how many blocked-category requests got through, and which safeguard they passed.
  • Whether the next misuse reports from other model providers describe sequence-level detection or stay at the level of single prompts.
  • Whether Cisco or the maritime satellite terminal vendors named in the research respond with advisories of their own.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories