Build1 publisher3 min readPublished
Account metadata linked 16 air-defense suppression modules to PRC research institutions
Anthropic's September 2026 threat report describes at least five China-linked programs run through Claude, including 151 million distillation queries, and the evidence behind each one is account-level telemetry only the provider can see.
The Engineer · Build desk

What happened
- Anthropic's September 2026 threat report says hundreds of China-linked agents ran at least five programs through Claude: two military, two surveillance, and one aimed at distilling the model.
- A second China-based researcher built about 16 electronic-warfare and air-defense suppression modules whose default scenario held 12 targets in Taiwan, including Patriot and Tien Kung batteries.
- In one surveillance program, Claude processed material collected from more than a hundred WhatsApp groups and dozens of Telegram channels and mapped social networks from it.
- Tom's Hardware puts 151 million training queries in the fifth program, the effort to distill Claude's capabilities, and ties those queries to Alibaba.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint The signals that produced these findings, account metadata and safeguard-flagged content, sit on the provider's side of the API, so a customer cannot rebuild this detection inside its own stack.
- decision Choosing a model on capability grounds does not settle the misuse question for a buyer, because the actors here reached for a US frontier model and the enforcement happened at the account layer.
- exposure Uyghur diaspora activists and people with relatives in Xinjiang are the parties left carrying risk, since shutting an account does not retract the social maps and recruitment lists already produced.
- contradiction Anthropic ties the account to PRC research institutions including the PLA Academy of Military Sciences without saying the PLA used Claude, so citing this as confirmed PLA use goes past the report.
In this report, attribution comes from the account record. Anthropic said account metadata and content caught by its safeguards "indicated the actor was linked to PRC research institutions, including the PLA Academy of Military Sciences", in the passage Tom's Hardware quotes [6]. Tom's Hardware also cites Chinese-language prompts and Chinese IP addresses as identifying signals across the cases [12].
That matters because the individual requests do not look like weapons work in isolation. A module that reads radar parameters, ranks SAM sites and command posts, and emits a target order is a scoring function over a table [4], and a fire-control specification is a document [2]. The refusal surface a customer thinks about applies per request, but the record that produced these findings is kept per account.
The five programs also pose very different detection problems. The 151 million queries in the distillation effort are a volume that any rate accounting would see [8]. The anti-torpedo work ended in a 200-plus-page proposal and a test of the design against public information on US Navy anti-torpedo and anti-submarine systems, which is a handful of long sessions and invisible to a volume threshold [2]. Between them, the two military programs account for 17 named engineering artifacts: 16 electronic-warfare modules and one fire-control specification [14].
The actor behind that specification presented itself as an OEM in the US defense sector, while Anthropic assessed it as associated with a Chinese defense manufacturer seeking to build for the People's Liberation Army Navy [3].
For anyone deciding where to run this class of workload, the useful detail is that the catch is described as metadata plus flagged content, both held on the provider's side. Tom's Hardware's summary does not say whether Claude refused any of these requests, or how long each program ran before Anthropic acted [15]. So the report is evidence that a provider reading its own account records found five programs, though not evidence of how fast it did so.
In the surveillance case, Anthropic disrupted a China government-linked actor that posed as an Arabic-speaking "expert" consultant to infiltrate Uyghur armed groups in Syria and watch diaspora activists and media [9]. The report describes Claude mapping social networks from that collected material and flagging people it assessed as vulnerable because of financial problems, family separation, or disillusionment with the new Syrian government [10]. It also drafted approaches in local dialects, translated conversations in real time, and rated the credibility of recruitment messages, while the actor singled out individuals with relatives remaining in Xinjiang [11].
On why a Chinese military researcher would use a US model at all, Tom's Hardware argues that plausible deniability hardly seems to have been the primary reason, and that Claude was more likely better or more convenient for these engineering workflows, particularly coding, reasoning and agentic tasks [12]. It adds that US frontier models trained on enormous amounts of English-language material could hold particularly extensive knowledge of publicly available information about American military systems, and says of that reasoning: "we are speculating, of course" [13].
What to watch
- Whether Anthropic publishes detection latency for these five programs, meaning how long each ran before enforcement.
- Whether the 151 million query figure and the Alibaba attribution appear in the report body itself or only in secondary coverage.
- Whether enterprise contracts start specifying which account metadata a provider retains and reviews for abuse attribution.