Anthropic says China-linked actors used Claude in reported military engineering, surveillance and model-distillation operations between December 2025 and August 2026. The cases include an anti-torpedo project, electronic-warfare software, an operation targeting Uyghurs in Syria and large-scale extraction of Claude outputs. They do not establish direct use of Claude by the People’s Liberation Army or the People’s Liberation Army Navy.

What Anthropic says it found

Anthropic’s September 2026 threat-intelligence report describes several kinds of misuse. In the military cases, Claude was allegedly used to advance weapons-system development and software for electronic warfare and suppression of enemy air defenses. In the surveillance case, Claude helped analyze and translate material connected to tracking, profiling and attempted recruitment of Uyghurs and Uyghur armed formations in Syria.

Anthropic says it identified and disrupted the activity, banned associated accounts and strengthened its safeguards. The umbrella period covers multiple cases; it is not the duration of any single operation.

Two reported military workflows

The first case, identified as GTG-17001, involved a China-based actor using Claude to prepare a Chinese-language anti-torpedo fire-control specification. Anthropic says the work included benchmarking against U.S. anti-torpedo and anti-submarine programs and a technical proposal exceeding 200 pages.

Anthropic assesses that the project was associated with a Chinese defense manufacturer seeking a potential People’s Liberation Army Navy customer. It does not identify a specific manufacturer, a completed military contract, a delivered weapon or combat deployment.

The separate GTG-17002 case involved about 16 modules for electronic warfare and air-defense suppression. Anthropic says the modules were iterated through 12 versions. A simulated scenario was changed to include 12 Taiwan targets, a detail reported alongside the company’s findings. Those targets were part of a simulation—not 12 documented attacks.

Anthropic assesses that the electronic-warfare actor was a China-based defense researcher. Account metadata and content indicated links to research institutions including the PLA Academy of Military Sciences. That is an assessed institutional link, not proof that the institution directly operated Claude.

Reported operationActivityReported output or scalePeriod or condition
Anti-torpedo projectDevelopment support for a fire-control specificationChinese-language specification and proposal exceeding 200 pagesReported activity covered by Anthropic’s December 2025–August 2026 investigation period
Electronic-warfare projectSoftware for electronic warfare and air-defense suppressionAbout 16 modules, iterated through 12 versionsSimulated scenario changed to 12 Taiwan targets
Uyghur-related operationTracking, profiling and attempted recruitmentClaude analyzed and translated collected materialOperation described in relation to Syria
Alibaba-linked operatorsLarge-scale Claude output extractionMore than 151 million exchangesMay–July 2026; nearly 3 million requests per day at peak
DeepSeek-linked activityClaude exchange activity attributed by AnthropicMore than 12.1 million exchanges14 days in July 2026
Xiaomi-linked activityClaude exchange activity attributed by AnthropicMore than 400,000 exchanges20 days in March and April 2026

Surveillance and attempted recruitment in Syria

Anthropic says a China-linked operation tracked and profiled Uyghurs and Uyghur armed formations in Syria, while attempting to recruit them. The operation processed material from more than 100 WhatsApp groups and dozens of Telegram channels, according to the reported account.

Claude’s described role was analytical: it helped process and translate material collected by external infrastructure. That does not mean Claude itself entered or harvested those groups. Anthropic says it could see attempted recruitment, but not whether recruitment succeeded.

The company assesses with low confidence that the operation involved a contractor working for PRC state security rather than a state organ directly. That qualification matters: a reported connection to state security is not the same as proof of direct government operation.

Distillation is not automatically theft

Distillation is a training technique in which a smaller or different model learns from the outputs of a larger “teacher” model. The technique itself can be legitimate. It does not inherently require transferring the teacher model’s source code or weights.

Anthropic’s allegation concerns how the outputs were obtained and used. The company says the campaigns involved covert or policy-violating extraction, including fraudulent accounts, proxy networks and other methods intended to bypass controls. The reported activity therefore raises access and authorization questions; it does not, by itself, prove that Claude’s source code or model weights were transferred.

That distinction is easy to lose in a dramatic headline. Asking a model millions of questions is not the same technical act as copying its parameter files. The scale can still matter: repeated output collection may provide training material for another system, even when the underlying model remains inaccessible.

The reported exchange totals

Anthropic attributed more than 151 million Claude exchanges to Alibaba-linked operators between May and July 2026, with activity approaching 3 million requests per day at its peak. More than 3,500 fraudulent accounts described that peak campaign; they are not a count of unique users or of every account in the broader activity.

The other reported figures are separate measurements, not pieces of one combined total. Anthropic attributed more than 12.1 million exchanges to DeepSeek-linked activity over 14 days in July 2026, and more than 400,000 exchanges to Xiaomi-linked activity over 20 days in March and April 2026. Anthropic says its investigation did not indicate that Xiaomi served Claude’s responses to its own users.

What the allegations do—and do not—show

The report presents Anthropic’s threat-intelligence findings about misuse of Claude. It does not establish that the PLA, the People’s Liberation Army Navy or the PLA Academy of Military Sciences directly operated Claude. Nor does it establish a court finding that Alibaba, DeepSeek, Xiaomi or another named company committed theft or violated a specific law.

The practical takeaway is narrower and more useful: frontier AI systems can be repurposed for military research, surveillance analysis and model training at very different levels of institutional connection. Anthropic’s response is to disrupt accounts and tighten safeguards, while the reported cases show why the boundary between ordinary model access and large-scale extraction has become a security issue.