Chinese Researchers Used US AI for Military Tools

Anthropic reports that Chinese-linked actors used Claude to develop military software and surveillance tools, revealing significant security implications for US technology.
Anthropic has disclosed that multiple China-linked actors used its Claude model for sensitive military and surveillance projects. The company’s September 2026 threat report details at least five distinct programs, including two related to military applications and two focused on surveillance. These findings suggest that despite China’s rapid advancement in domestic artificial intelligence, its researchers and state-linked entities still rely on US frontier models for specific high-level engineering tasks.
The reliance on Claude over domestic alternatives appears driven by specific functional advantages rather than attempts at plausible deniability. Account metadata and the use of Chinese-language prompts indicate a direct connection to Chinese entities. The models were likely chosen for their superior capabilities in coding, reasoning, and complex agentic workflows. Additionally, US models trained on extensive English-language data may possess deeper knowledge of publicly available American military technologies, providing a strategic edge to those seeking to analyze or counter such systems.
Military Software Development Activities
One actor used Claude to draft specifications for an anti-torpedo fire-control system. The system was designed to determine engagement logic against incoming threats and was tested against US Navy capabilities based on public information. The actor disguised itself as a US defense sector manufacturer while preparing a technical proposal for a potential client. Anthropic believes this actor was associated with a Chinese defense manufacturer seeking to develop systems for the People's Liberation Army Navy.
Another researcher developed approximately 16 software modules for electronic warfare and suppression of enemy air defenses. These tools analyzed radars, command posts, and communications nodes to prioritize targets. At one point, the default scenario included twelve targets in Taiwan, such as air defense batteries and early-warning radars. Anthropic notes that account metadata indicated links to Chinese research institutions, including the PLA Academy of Military Sciences, though it does not explicitly confirm direct use by the PLA.
Surveillance Operations and Data Distillation
Beyond military hardware, Anthropic disrupted surveillance operations targeting Uyghurs outside of China. One government-linked actor used the model to infiltrate armed groups in Syria and monitor diaspora activities. This suggests a broader pattern of using advanced AI for intelligence gathering beyond traditional borders. The company also identified a project aimed at distilling Claude's capabilities, effectively transferring its reasoning and coding skills to other systems.
The distillation effort is particularly concerning as it could allow adversaries to replicate the model's strengths without ongoing access to the original service. This process involves feeding large volumes of queries to the AI to generate training data for competing models. Such activities highlight the risk of US AI technology becoming a foundational component for rival national security capabilities, undermining the strategic advantages of frontier model development.
Strategic Implications for US Technology
These disclosures underscore a complex reality in the global AI landscape. While China claims to have advanced models that compete with US offerings, the evidence suggests gaps in specific high-end engineering tasks. The use of Claude for coding and complex reasoning indicates that domestic alternatives may not yet match the precision required for sensitive military applications. This dependency creates a unique security challenge for US providers.
As reported by GN technics/hardware, the situation reveals a trade-off between open access to advanced AI tools and the potential for misuse by state actors. Companies must balance innovation with robust safeguarding measures to prevent their technologies from being repurposed for hostile ends. The incident serves as a stark reminder that frontier AI is not just a commercial product but a critical component of national security infrastructure.






