Anthropic identified an apparent effort originating in Yemen to use its Claude AI system for help developing a guided rocket using mobile technology, part of a wider set of cases in which users sought potentially dangerous assistance involving weapons, biological research and cyberattacks.
The Washington Post characterized the users as rebels and reported that they had used the chatbot to work on guided weapons. The available details do not identify the people involved, establish whether a functioning weapon was produced or specify how much Claude contributed to the project. Anthropic’s findings therefore point to an attempted use of AI in weapons development rather than proof that the system enabled the construction or deployment of a guided rocket.
The case appeared in an Anthropic report examining real-world misuse of its models. The company also disclosed that it had blocked five attempts involving research that could have supported the development of biological weapons. Those cases included work connected to chikungunya, avian influenza, smallpox and animal toxins.
One user affiliated with an unidentified military institution sought help while preparing a research proposal involving chikungunya, a mosquito-borne viral disease. Some aspects of such work can serve legitimate goals, including vaccine research, but other requests raised concerns that the user was interested in making the virus more dangerous. Separate activity explored ways to increase the transmissibility of avian influenza and requested information about toxins that could potentially be weaponized.
Anthropic cautioned that suspicious questions do not by themselves prove an intent to build a biological weapon, nor do they demonstrate that a user had the resources or expertise to succeed. The company also drew a distinction between controlled model evaluations, which measure whether an AI system can provide harmful information, and evidence that the same capabilities have been used successfully in the physical world.
The report said some users attempted to evade Claude’s safety controls through fraudulent accounts, private networks and third-party resellers. Such methods complicate enforcement because AI providers generally apply restrictions through a combination of automated monitoring, account-level controls and model behavior designed to refuse certain requests. Users who shift identities or access models through intermediaries can make it harder to connect related activity and remove repeat offenders.
Anthropic said it has strengthened protections in sensitive fields including biology and cybersecurity. Access to some of its most capable biology-related systems is limited to vetted organizations, an approach intended to preserve legitimate scientific uses while reducing the availability of advanced assistance to unknown users.
The disclosures add concrete examples to concerns that general-purpose AI can lower barriers to specialized technical work. A chatbot does not supply laboratory facilities, engineering materials, testing infrastructure or operational experience, but it can organize information, generate code, help troubleshoot designs and guide users through unfamiliar subjects. Those functions can be valuable for research and education while also creating opportunities for misuse.
Anthropic operates under a Responsible Scaling Policy that links increasingly capable models with assessments and safeguards for severe risks. The company periodically revises that framework and publishes information about its safety measures. Its latest misuse findings also arrive amid calls from AI safety researchers for more independent scrutiny of incidents involving advanced systems, since much of the public record currently depends on voluntary disclosures by the companies developing the models.
Key questions remain unresolved in the Yemen case, including who controlled the accounts, what stage the rocket project reached and whether Anthropic’s intervention prevented further work. The report establishes that the company detected weapons-related activity, but not that the users produced a viable guidance system.