AI Firms Stop State Surveillance Campaigns

Anthropic reveals how its models were misused by state actors to spy on dissidents and minorities across three continents.
Anthropic announced that it has disrupted multiple surveillance operations conducted by state-aligned actors in China, Iran, and West Africa. The company stated that these campaigns used its artificial intelligence models to target diaspora communities, including pro-democracy activists in Hong Kong and ethnic minorities in Asia. The incidents were detected and blocked between January and July, highlighting a growing trend of governments leveraging AI for covert intelligence gathering.
According to the report, the surveillance efforts focused on groups that these regimes have historically monitored. In one specific case, Iranian actors developed methods to identify individuals through their social media accounts. In another, a contractor working for Malian national security authorities used the AI to design the underlying software necessary for intelligence collection. The company noted that AI is increasingly replacing traditional engineering workforce requirements for such sensitive tasks.
State Actors Exploit AI Tools
The misuse of these models represents a significant shift in how intelligence is gathered. By using AI, state actors can process large amounts of data and identify targets with greater efficiency than before. This development raises concerns about the potential for widespread surveillance against political opponents and minority groups. The ability to automate these processes lowers the barrier to entry for state-sponsored espionage, making it easier for governments to monitor their citizens and diaspora communities.
Distillation Practices Raise Privacy Concerns
Beyond surveillance, Anthropic accused Chinese developers of using its models to improve their own systems through a process known as distilling. This technique involves using one AI model to generate data that trains another. The company alleged that developers from Moonshot and Deepseek secretly relayed user requests to Anthropic to generate responses, which were then used to train their competing models. This practice effectively allows one company to leverage the resources of another without explicit permission.
In one instance, Moonshot relayed nearly 300,000 customer requests through a network of fraudulent accounts over ten days. Some of this data contained sensitive user information, potentially violating privacy agreements. Anthropic stated that it is unclear whether these companies notified their customers that their requests were being rerouted and exposed to a third party. This unauthorized use of data poses serious risks to user privacy and the integrity of the AI ecosystem.
Ambiguity in Biological Research Cases
The company also reported blocking attempts to design weapons and conduct questionable biological research. However, the intent behind these actions was less clear-cut. The individuals involved were identified as working scientists, and Anthropic did not assert that they intended harm. The research involved highly pathogenic strains of bird flu and other viruses, but the company chose not to identify the scientists to avoid exposing them to potential danger. This approach reflects the complexity of distinguishing between legitimate scientific inquiry and dangerous misuse of AI capabilities.
As AI models become more powerful, the line between beneficial applications and harmful misuse becomes increasingly blurred. Companies like Anthropic are taking steps to mitigate these risks, but the challenge of detecting and preventing state-sponsored abuse remains significant. The incident underscores the need for robust safeguards and transparency in the development and deployment of artificial intelligence technologies. Users and policymakers must remain vigilant to ensure that these tools are not exploited for surveillance or other harmful purposes.






