Anthropic’s September 2026 threat-intelligence report says human-directed actors used Claude inside propaganda, surveillance and influence operations identified between December 2025 and August 2026. The company describes Claude as a tool for software engineering, content production, profiling, dossier preparation and distribution—not as an autonomous political actor—and says it disrupted the activity it identified.
The report covers seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and illicit model distillation. It describes nine influence-operation cases originating across Russia, Iran, Turkey, the Gulf, South Asia, Africa and Europe, with intended audiences on six continents.
What Anthropic’s September 2026 report says
Anthropic published the report on September 10, 2026. Its central message is less cinematic—and more consequential—than the idea of an AI independently launching a covert campaign: people used a capable model to scale work that humans had already organized.
Anthropic says Claude Haiku, Claude Sonnet and Claude Opus appeared in the documented misuse cases. The company also says most of the influence content it discovered generated little or no authentic engagement. That matters because a large content pipeline is not the same thing as a large audience, and neither one proves a change in public opinion or political outcomes.
The company says the identified activity violated its Usage Policy or terms of service. It says it removed or banned accounts involved in the cases, improved safeguards and shared intelligence with authorities and industry partners where appropriate.
Claude was part of a human-led pipeline
The reported workflows put Claude closer to an extremely fast technical and editorial workforce than to an independent decision-maker. Human operators supplied the objectives and used the model to generate or rewrite political material, create personas, prepare dossiers, fabricate biographies, draft testimony and help build distribution infrastructure.
That distinction answers the most important question: Claude did not independently run the propaganda or surveillance campaigns described by Anthropic. The company’s account presents people and organizations as directing the operations, with Claude assisting particular tasks inside them.
Anthropic describes Lakana 360 as a platform built for Mali’s state intelligence service, monitoring roughly 25 million SIM cards across all three national mobile operators. One reported Mali operation illustrates the difference between designing a system and operating it. Anthropic says Claude provided software design and engineering support for Lakana 360, while the deployed platform runs on local models on-premises. In other words, Claude’s account enforcement does not affect that reported system once it is deployed. The distinction is technically important: banning an online account is not the same as disabling software that uses local infrastructure.
Mali, the Central African Republic and Sudan
The three cases below show how the same model family could be used for very different jobs.
| Operation or setting | Reported use of Claude | Reported scale or target |
| Mali — Lakana 360 | Software design and engineering support for a surveillance platform; Anthropic says the deployed system uses local models on-premises. | Mobile communications and intelligence dossiers |
| Central African Republic | Production of pro-government, pro-Wagner and anti-France content; surveillance of opposition figures; forged documents; and scripts for senior officials. | Radio Lengo Songo and a broader influence operation |
| Sudan-related network | Fake social-media personas, profiling, dossiers, a copied Swiss human-rights organization identity and ghost-written testimony intended for the United Nations Human Rights Council. | About 300 fake accounts; dossiers involving 18 European Parliament members, journalists and UN special rapporteurs |
For the Central African Republic, Anthropic attributes the operation to Russian state-aligned actors and says it used Radio Lengo Songo to distribute daily content. The company also links the activity to Politology and describes an effort to make a foreign-run operation appear to originate in Bangui.
For Sudan, Anthropic says the network was linked with high confidence to UAE government officials.
A separate commercial campaign attributed by Anthropic to the France-based LKM Company shows the production problem at a different scale. The company says LKM used Claude to distribute at least 8,913 fabricated articles through approximately 70 fake news websites in about 20 languages. The number describes output, not the number of people who believed or even saw the material.
Scale is not the same as influence
AI changes the economics of fabrication. A small team can produce more text, images, profiles and translations than it could manually. But speed and volume do not automatically create attention.
Anthropic says most of the influence content it identified produced little or no authentic engagement. That finding applies to the discovered content as a group; it does not prove that every campaign failed to reach real people. It does, however, put a useful brake on sensational readings of the numbers. Thousands of articles can coexist with a very small genuine audience.
The more durable concern is the workflow. Claude can help connect tasks that used to require separate specialists: drafting persuasive language, translating it, generating fictional identities, analyzing targets and building software to distribute the result. Human control remains central in the reported cases, but the model can reduce the time and expertise needed to assemble an operation.
What Anthropic did in response
Anthropic says it disrupted the accounts and activity it identified, strengthened its safeguards and shared intelligence where appropriate. It also says threat actors tested those safeguards with measures such as VPNs, foreign phone numbers, rotated accounts and third-party services that masked their identities.
Those actions address misuse of Anthropic’s services. They do not amount to a universal off switch for every system built with Claude’s assistance. The Mali example makes that boundary concrete: Anthropic says Lakana 360 runs on local models on-premises, so account enforcement does not affect the deployed product.