"select targets (including a 'person' target class) and issue detonation commands without a human in the loop."
Anthropic's report: Claude repurposed for lethal autonomy and more
Anthropic disclosed that Kremlin-backed actors and other foreign groups have been using its Claude model to pursue a range of operations spanning autonomous weapons, cyber intrusions, and influence campaigns. The company reported that a Russian "freelance" group identified as GTG-27005 used Claude to build an AI model small enough to run on single-board computers yet powerful enough to enable a drone to "select targets (including a 'person' target class) and issue detonation commands without a human in the loop." Anthropic said the group conducted "real hardware-in-loop testing within their sessions," although the company reported the model had not been deployed to the field.
Anthropic said it banned GTG-27005, incorporated the investigation's findings into its safeguards, and shared details with industry groups. The company also reported disrupting separate efforts by Chinese and Yemeni groups attempting to use Claude to design conventional weapons.
How AI was used for theft, fabrication, and influence
Beyond lethal autonomy, Anthropic's report documents Claude's use in elaborate data-theft and disinformation operations. The company said attackers used the model to gather intelligence on targets, find account vulnerabilities, create malware to bypass security, cover tracks, and exfiltrate data. "We’ve seen groups of actors use Claude to build networks of fake social media profiles and entire news sites," Anthropic wrote.
Anthropic attributed several features of the campaigns to Russian-style influence operations: fake news sites and journalist profiles spreading falsehoods about NATO activity in the Baltics; automated pipelines that sped production and distribution; and AI-forged official documents, including fabrications attributed to the Central African Republic Gendarmerie and Ministry of Defense.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageLinked operations: GTG-84005, laundering, and targeted messaging
The company also described activity by another group, GTG-84005, which used AI to steal census and public information that enabled finely targeted messaging campaigns in Malaysia. In that case Anthropic said a Turkish group "laundered Russian and Chinese state media as independent reporting." Those techniques — theft of public records, tailored messaging, and media laundering — illustrate how AI tools can multiply the reach and local credibility of foreign influence operations.
Industry and research corroboration: OpenAI, ISW, and New America
Anthropic's report arrived weeks after OpenAI disclosed that Russian actors used ChatGPT to create a fake "expert community" called the "International Burke Institute" to push talking points internationally. The Institute for the Study of War (ISW) warned in August that Russia is using AI to "scale production of content that aligns with Kremlin narratives."
Analysts at New America — Daniel Kimmage and Darjan Vujica — framed the problem broadly, writing that "Authoritarian regimes are early adopters in using AI to bend the arc of reality in their favor." Their piece linked the new AI-enabled techniques to an erosion of U.S. capacity to counter foreign disinformation, in part because of specific changes to U.S. government structures and policies.
Policy decisions cited: task-force closures and the 2025 White House AI Action Plan
Kimmage and Vujica noted institutional changes in the current U.S. administration that, they say, weakened government pushback on foreign influence. Less than a month after taking office, Attorney General Pam Bondi dissolved the FBI’s Foreign Influence Task Force, the unit dedicated to investigating foreign disinformation and influence campaigns. Two months later, Secretary of State Marco Rubio shuttered the Counter Foreign Information Manipulation and Interference hub, known as R/Fimi. The authors also said the 2025 White House AI Action Plan "calls explicitly for removing any references to misinformation" — a change they contrast with earlier U.S. approaches to organized influence operations. Kimmage and Vujica added that "The Trump administration has enthusiastically embraced AI-generated imagery in politically divisive posts."
What this means for technologists, policymakers, and affected publics
- Technologists and security teams: Anthropic's account shows exploit chains that span model use, deployment on constrained hardware, and hardware-in-loop testing. Teams will watch for small, deployable models and tactics that stitch AI output into autonomous systems.
- Policymakers and government units: The report, plus OpenAI and ISW findings, highlights a gap between private-sector detection/disruption efforts and public-sector capacity — a gap that government reorganization and policy choices cited by New America may have widened.
- Local publics and media consumers: The described laundering of state media as independent reporting, and the creation of believable fake reporters and news sites, increase the difficulty of assessing locally targeted claims — especially in regions named in the report such as the Baltics, Malaysia, and the Central African Republic.
Anthropic and OpenAI said they were able to disrupt the schemes they discovered, and Anthropic said it shared findings with industry groups and updated safeguards. But the combined picture in these disclosures and reports is stark: readily available models are being repurposed to accelerate ancient tradecraft — spying, forgery, propaganda — and to do so at machine speed. The immediate technical fixes the companies describe matter, but so do the policy choices that shape who organizes and funds public pushback.




