Chinese Actors Used Claude to Target Taiwan’s Patriot Defenses, Build Military Systems and Harvest U.S. AI at Industrial Scale


Sept. 12, 2026, 8:39 a.m.

Views: 1678


How Anthropic says Claude was used for weapon

Chinese Actors Used Claude to Target Taiwan’s Patriot Defenses, Build Military Systems and Harvest U.S. AI at Industrial Scale

Anthropic’s newest threat-intelligence report should force the United States to rethink what it means when an American frontier AI model falls into the hands of actors connected to China’s military, security apparatus and technology industry. The company says it disrupted China-based operations that used Claude to help develop electronic-warfare software targeting air-defense networks, draft specifications for an anti-torpedo weapons system, investigate advanced American directed-energy weapons, automate political surveillance and operate a deceptive dating-app network targeting users at massive scale. At the same time, Anthropic says Chinese AI laboratories mounted industrial-scale campaigns to extract Claude’s capabilities, with activity attributed to Alibaba alone exceeding 151 million exchanges. These cases show that American AI can become valuable infrastructure for China long before Beijing builds an equivalent capability entirely on its own.

The most alarming China-related case directly touched Taiwan’s American-made defenses. Anthropic identified a China-based actor that used Claude’s chat, coding and agentic tools to design a Chinese-language electronic-warfare and suppression-of-air-defense software suite containing roughly 16 modules. The system went through 12 iterations and incorporated radar detection, jamming physics, vulnerability analysis and targeting instructions. It could analyze radar systems, surface-to-air missile sites, command posts and communications nodes, calculate detection coverage, estimate how effective jamming would be, rank targets according to value and vulnerability and allocate jammer sorties over multi-day campaigns. The software modeled engagement envelopes including Patriot and THAAD-class systems. During development, the actor changed its default scenario to 12 targets in Taiwan, including a command bunker, an early-warning radar, Patriot batteries, Tien Kung batteries, major air bases and a regional command headquarters.

That detail has direct implications for American security. Patriot is a major U.S.-developed air and missile-defense system supplied to Taiwan and other American partners. A Chinese military-industrial researcher using an American AI model to accelerate software designed to identify vulnerabilities, prioritize targets and optimize electronic attacks against Patriot-class systems creates a technology-transfer problem that reaches far beyond ordinary chatbot misuse. Anthropic says account metadata and safeguard-triggering content linked the actor to PRC research institutions, including the PLA Academy of Military Sciences. The company banned the associated accounts after identifying the work as suspected weapons development.

A separate China-based operation used Claude in an undersea-warfare project. Anthropic says the actor pursued three parallel tracks involving an anti-torpedo system: drafting a Chinese-language fire-control specification, preparing a technical proposal exceeding 200 pages, and benchmarking the proposed system against publicly documented U.S. anti-torpedo and anti-submarine programs. The actor also used Claude to build portions of the fire-control software and create a test matrix. Anthropic assessed that the user was associated with a Chinese defense manufacturer seeking to produce a weapons specification and acquisition proposal for the People’s Liberation Army Navy. The model accelerated document preparation, engineering review and parts of the software-development process that traditionally require specialized personnel and substantial time.

Another Chinese operation focused on an area in which the United States is investing heavily: directed-energy weapons. Anthropic identified a China-based actor who described himself as a defense-intelligence writer and used Claude to research high-power microwave systems, including a recently disclosed vehicle-mounted weapon intended to counter drone swarms. The actor investigated components and suppliers, prepared internal Chinese-language intelligence products and directed Claude to draft material for restricted circulation to senior CCP, military or state-security leadership. Anthropic says the actor attempted to identify a specific microwave-generating device and supplier so the system could be reverse-engineered, countermeasures could be developed and the foreign weapon could be benchmarked against Chinese systems. The actor ultimately compiled a 23-page leadership report and developed an extensive follow-on intelligence collection plan.

The surveillance findings are equally consequential. Anthropic says PRC government-aligned actors used Claude to turn enormous quantities of social-media and communications data into structured intelligence products. One operation tracked and profiled Uyghurs in Syria, including identifying people whose financial problems, family separation or relatives remaining in Xinjiang could create exploitable leverage. Another operation produced dossiers on senior Catholic figures, Taiwanese Presbyterian leaders, Tibetan Buddhist organizations, Falun Gong-linked groups and Chinese diaspora figures. A separate China-based “public opinion monitoring” operation used Claude to process foreign news and social-media material, rank political sensitivity and generate internal-style briefings covering dissidents, labor activists, student activists, ethnic minorities, diaspora organizations, political figures in Taiwan and foreign media.

For Americans, this demonstrates how AI can expand the reach of transnational repression. The traditional limitation on surveillance is human labor: analysts must collect information, translate it, classify individuals, compare sources and produce intelligence reports. Claude allowed some actors to compress that process into automated pipelines capable of processing material every day with minimal human intervention. Anthropic says one PRC religious-affairs intelligence operation effectively reduced work that previously required multiple analyst teams to a single office using an AI assistant capable of generating thousands of investigations each month. When a government already possesses large surveillance databases and extensive overseas collection priorities, American AI can multiply the amount of information a small team is able to process.

The commercial-crime case shows the same scaling effect in a different form. Anthropic discovered a China-based studio operating more than 20 deceptive dating applications. Over only two weeks in April 2026, the network ran more than 4,700 AI personas that communicated with at least 25,000 people. Claude personas reportedly generated roughly 2.36 million messages during that period, while real gig workers were inserted into the system to conduct video calls or social-media interactions when victims demanded proof that the person was real. The user-facing feed was roughly 75% AI personas and 25% real workers, and the autonomous profiles were explicitly instructed never to reveal that they were automated. Anthropic’s case description identifies the targeted users as being in the United States.

This is a major warning for American consumers because generative AI changes the economics of fraud. Traditional romance and dating scams require human scammers to maintain conversations, remember personal details and manipulate victims individually. Thousands of autonomous personas can maintain those relationships simultaneously, while a much smaller human workforce intervenes only when a video call, social-media follow or other authenticity check becomes necessary. The result is a hybrid criminal model in which AI provides scale and humans provide credibility. It can make deception cheaper, more persistent and harder for ordinary users to recognize.

China’s AI laboratories present another threat: the extraction of the American model itself. Anthropic says that since February it has disrupted unauthorized distillation campaigns attributed with high confidence to seven PRC-based laboratories targeting its Opus-class models. The largest disclosed campaign was attributed to Alibaba. According to Anthropic, the operation reached nearly three million exchanges per day, used more than 3,500 fraudulent accounts at its peak and focused on agentic tasks, software engineering, kernel development and long-horizon reasoning. Between May and July 2026, Anthropic says it observed more than 151 million exchanges attributable to Alibaba. The harvested reasoning transcripts were allegedly used in supervised fine-tuning for Qwen 3.5, 3.6 and 3.7.

Moonshot AI was associated with another disturbing method. Anthropic says Moonshot sometimes forwarded customer requests intended for its Kimi models to Claude without the user knowing that Claude was answering. Over one ten-day period, almost 300,000 customer requests were reportedly relayed through a network of 5,380 fraudulent accounts. Anthropic says Moonshot saved at least some of those exchanges and developed techniques for extracting Claude reasoning traces for training. Between May and July, Anthropic attributed more than 23 million exchanges to Moonshot-related distillation activity. Some relayed sessions contained sensitive customer information, including corporate code, credentials and surveillance material.

The danger for the United States is therefore two-sided. Chinese military and security actors can try to use American frontier models directly to accelerate work on weapons, intelligence and surveillance, while Chinese AI companies can attempt to extract those models’ capabilities so they become embedded in domestic Chinese systems. The first path rents American capability. The second seeks to reproduce it. Either path can shorten the amount of time, computing power and specialist labor required to reach capabilities that American laboratories spent enormous resources developing.

Anthropic’s report also shows why simple geographic bans are insufficient. Claude is restricted in China, yet many of the operations used VPNs, proxy infrastructure, fraudulent or stolen accounts and API resellers to bypass regional controls. The dating-app operation relied heavily on PRC-origin proxy infrastructure. Chinese AI labs allegedly used thousands of false accounts, stolen credentials and proxy networks to harvest model outputs at industrial scale. American frontier labs therefore need to treat access control as a counterintelligence and cybersecurity problem rather than a basic geolocation problem.

There is one important boundary in the evidence. Anthropic says none of the cases in this report involved its most powerful restricted model, Claude Mythos. The documented operations used models such as Sonnet, Opus and Haiku, and Anthropic says it detected and disrupted the activities described. That makes the findings more troubling in one respect: actors achieved meaningful military, intelligence, cyber and criminal assistance without gaining access to Anthropic’s most capable system. As frontier models improve, the value of successful circumvention will rise.

The report does not show that every Chinese AI user is involved in state activity, and the attribution levels vary by operation. Some actors were assessed as PRC government-aligned, some were linked to Chinese defense or research institutions, some were commercial contractors, and some were purely financially motivated criminals. That distinction matters because the U.S. response should follow evidence. It also makes the overall pattern harder to dismiss. Separate Chinese actors across military research, defense intelligence, government surveillance, commercial fraud and frontier-model development independently found value in the same American AI technology.

For the United States, frontier AI should now be treated as strategic technology comparable in importance to advanced semiconductors, cyber tooling and sensitive defense software. American AI companies need stronger identity verification, behavioral detection, limits on large-scale automated extraction, monitoring for proxy-account networks and rapid information sharing across laboratories when one provider identifies abuse. Government and industry also need mechanisms for protecting the most dangerous agentic, cyber and weapons-relevant capabilities before adversarial actors can turn commercial access into a military-development shortcut.

Anthropic’s September report offers a particularly stark lesson because it connects several threats Americans often discuss separately. China’s military competition with the United States, pressure on Taiwan, transnational surveillance, online fraud and efforts to close the AI capability gap increasingly intersect through the same technology. A Chinese researcher could use Claude to model the suppression of Patriot batteries in Taiwan. A defense-industry actor could use it to accelerate a PLAN anti-torpedo proposal. Intelligence personnel could automate dossiers on overseas targets. A dating-app company could run thousands of deceptive personas against U.S. users. Chinese AI laboratories could then attempt to extract the underlying model capabilities themselves.

The strategic question facing America is therefore larger than whether U.S. companies continue to lead AI benchmarks. The real test is whether the United States can preserve that technological lead while preventing its most valuable capabilities from being repurposed to strengthen the military, intelligence and criminal systems of its principal strategic competitor. Anthropic’s own investigations show that this is already an operational problem rather than a distant theoretical risk. American AI may be one of the country’s greatest technological advantages, and the cases documented in this report show exactly why China-linked actors have strong incentives to gain access to it, exploit it and ultimately reproduce it.


Return to blog