A cell in northern Yemen used Claude to write guidance software and run simulations for missile programs, not to field a working weapon. A separate case in the same report has an Iran-linked actor compiling targeting recommendations on U.S. Navy ships from open-source data.
Anthropic disclosed on Sept. 10 that a weapons-development cell it identified in northern Yemen used its Claude models to write guidance, navigation and control software for three missile programs, in a case the company's threat intelligence team labeled GTG-87001. The findings come from Anthropic's own threat intelligence report, which covers activity the company tracked between December 2025 and August 2026.
Anthropic did not name the Houthis. The report identifies only "a cell of threat actors based in northern Yemen," territory the Houthi movement controls. Several outlets, including Al-Monitor, infer a Houthi link from that geography and from programs that resemble past Houthi public claims. That inference is widespread, but it is still an inference. Nobody has independently identified the operators.
Three Programs, Different Levels of Proof
According to Anthropic, the cell pursued a guided rocket built around a commodity phone-class flight computer with terminal-phase homing, a multi-stage ballistic missile with a stated range goal of more than 2,000 kilometers, and an R2000 missile family that included a hypersonic glide vehicle variant. Claude was used to integrate an open-source autopilot with the flight computer, write control and position-estimation software, tune control parameters, run a firmware build pipeline and perform flight simulations.
Those three programs are not equally advanced. The guided rocket is the only one Anthropic ties to an actual hardware event, a live test-fire. The ballistic missile's 2,000-kilometer range and the hypersonic glide vehicle variant appear in the report as stated goals and simulation work, not as vehicles anyone has demonstrated. Treating all three as equivalent "missiles Claude helped build" overstates the hypersonic piece in particular. Weapons analyst Trevor Ball told reporters the Houthis lack real production capacity for that kind of system even if they are exploring it by asking Claude questions.
The cell still ran the operation itself. Humans assigned the work, hid its true purpose from Claude, split it across separate sessions, test-fired a guided rocket, and compiled the offline toolkit described below. Anthropic's report does not say who machined the airframe or loaded the motor. Within that human-run structure, the cell ran multiple Claude instances at once, split into roles that mirrored a conventional engineering team, one producing code, one handling research, one reviewing the work. Anthropic's own report describes the setup as the group using Claude Code "in place of human software engineers," meaning the software-engineering role specifically, not the organization behind it.
A Failed Test, Inferred From the Chat Logs
Anthropic's evidence that a test failed is not wreckage, telemetry or a Houthi admission. It is that the same users came back to Claude within hours asking it to help diagnose what had gone wrong after a guided-rocket test-fire. That is a strong inference from Anthropic's own logs, not an independently confirmed field event. Combined with the broader pattern of requests, it is what surfaced the activity during an internal Anthropic investigation into suspected weapons development.
The cell had tried to stay under the radar by hiding the true purpose of individual requests and splitting the work across separate sessions, so no single conversation revealed the full scope of the project. Anthropic said its safety systems blocked many of the cell's requests but not all of them. Once the pattern became clear, Anthropic banned the accounts involved and shared its findings with government and industry partners.
One detail limits how much banning the accounts actually accomplished: the group had already built a standalone, offline simulation toolkit that runs without Claude or any commercial engineering software, a finding that comes directly from Anthropic's own report. That toolkit persists on its own, independent of whatever access to Claude the cell has now lost. Anthropic said it has no evidence the group succeeded in fielding an operational weapon.
A Separate Case: Iran-Linked Naval Reconnaissance
The same report includes a second, unrelated case. Anthropic's own summary says the actor researched vulnerabilities in maritime VSAT terminals (Very Small Aperture Terminal) Terminals are compact satellite communication systems designed to transmit and receive voice, video, and broadband data through satellite networks. Networking equipment and industrial-control products relevant to U.S. naval forces in the region. The report does not establish that those specific products were fitted aboard the ships being tracked. The specific brand names circulating in coverage, Cobham Sailor, Cisco and Schneider Electric EcoStruxure, come from outlets reporting on the report, not from an independent read of Anthropic's own document.
Anthropic also found the actor combined publicly available ship and aircraft transponder data with commercial satellite imagery and pulled the names of military personnel from captions on public photos. That is open-source work an intelligence shop could do without an AI model, but the interesting part isn't that the pieces existed already, it's that Claude appears to have sped up the work of turning them into targeting handbooks and recommendations, not a claimed firing solution or a confirmed exploit of the equipment researched. The company said it banned that account as well, added new detection methods and shared its findings with government authorities.
What the AI Actually Bought Them
Ball's comment was specifically about hypersonic production capacity, not a general verdict on whether operators in northern Yemen can field the other systems; he separately suggested the broader motive is likely reducing dependence on Iranian shipments. Yemen analyst Adam Baron, also speaking to reporters rather than in Anthropic's own report, pushed back on treating the episode as a stereotype-confirming surprise, arguing it instead reflects a deepening level of institutional technical sophistication in the movement controlling that territory.
Anthropic's own framing lands in a similar place. Claude answered engineering questions and ran simulations. By the company's own account, it did not produce a missile that worked. The gap between those two things is the story worth holding onto here: an AI model can meaningfully speed up the unglamorous engineering work behind a weapons program, tuning parameters, debugging a failed test, standing in for scarce guidance-software talent, without that program actually succeeding. Both facts are true at once, and neither cancels the other out.
Anthropic has not said whether the Yemen cell or the Iran-linked account had any connection to each other. The report treats them as two distinct disruptions, published together because both surfaced in the same monitoring window, not as one connected plot.
What's Still Unknown
Several questions the available reporting cannot answer: who the Yemen users actually are, a Houthi military unit, a contractor or someone else operating on Houthi-controlled territory; whether any Claude-assisted code has flown on anything besides the rocket Anthropic says was test-fired; whether the offline simulation toolkit is competent engineering or a rougher stand-in for real calibration; and whether the Iran-linked targeting material was ever put to operational use. Readers should treat this as a documented case of Claude accelerating weapons-adjacent engineering work, not as proof that Yemen fielded a Claude-built missile or that Iran used Claude to carry out an attack on a U.S. ship.
Sources:
Countering misuse of AI: September 2026 — Anthropic
Users in Houthi-held Yemen tried to develop advanced weapons with AI, Anthropic says — SecurityWeek
Yemeni Cell Used Anthropic's Claude 'In Place of Human Software Engineers' To Develop Missile Guidance Systems — IBTimes UK
Coverage of the Yemen and Iran cases in Anthropic's report — Tom's Hardware
Claude AI used for missile, influence projects in UAE, Iran, Yemen: Anthropic — Al-Monitor
Have a correction or tip? See our
corrections policy or contact the newsroom.