Regulation

Anthropic Report Details Extensive Chinese Military and Surveillance Use of Claude AI Model

According to Anthropic's September 2026 threat report, hundreds of China-linked entities have deployed the Claude model across military projects, surveillance operations, and large-scale data harvesting campaigns.

4 min read
Chinese military researchers and tech giants caught using Claude — US frontier model coded 16 air-defense suppression tools targeting Taiwan, drafted anti-torpedo specs, and fed 151 million training queries to Alibaba

Despite China's claims of possessing competitive artificial intelligence systems, a substantial number of operatives linked to the country have turned to Anthropic's Claude for at least five distinct initiatives, spanning military applications, surveillance efforts, and capability extraction, as documented in Anthropic's September 2026 threat report.

Two military programs

One actor based in China leveraged Claude to formulate specifications for an anti-torpedo fire-control system—the underlying logic governing when and where anti-torpedo weapons engage incoming threats—evaluate the proposed system's effectiveness against known U.S. Navy countermeasures drawing on publicly disclosed information, and assemble a technical proposal exceeding 200 pages for a prospective buyer. Though the actor presented itself as a U.S. defense sector original equipment manufacturer, Anthropic determined the entity was connected to a Chinese defense manufacturer developing capabilities for the People's Liberation Army Navy.

A second China-based military and defense researcher employed Claude to construct approximately 16 software modules for electronic warfare and air defense suppression. These modules examined radar installations, surface-to-air missile positions, command centers, and communication infrastructure while categorizing targets by priority. A default scenario within the system included 12 targets across Taiwan, encompassing Patriot and Tien Kung air defense batteries, military airfields, an early-warning radar facility, and a command bunker. Anthropic notes that account information and content flagged by its safety systems "indicated the actor was linked to PRC research institutions, including the PLA Academy of Military Sciences," though the company stops short of definitively stating the PLA directly utilized Claude.

The reliance of two Chinese military initiatives on Claude is noteworthy given China's substantial artificial intelligence capabilities, which may lag behind American advances in certain domains. Considering the Chinese-language inputs and account-level indicators uncovered by Anthropic, avoiding attribution does not appear to have motivated the selection of Claude over locally developed alternatives. Rather, Claude likely offered superior performance or greater utility for these specific engineering tasks, particularly those demanding coding, logical reasoning, and autonomous agent functionality. An additional factor may have been significant: American frontier models are trained on vast quantities of English-language data, potentially providing deeper knowledge of publicly accessible details regarding U.S. military systems and technologies.

Significant surveillance activities

Anthropic also identified and disrupted surveillance campaigns connected to China targeting Uyghurs living outside the country, possibly complementing existing monitoring within the Xinjiang Uyghur Autonomous Region. A China government-affiliated actor deployed Claude to penetrate Uyghur militant organizations operating in Syria and monitor Uyghur diaspora activists and news outlets while posing as an Arabic-fluent professional consultant.

Following successful infiltration, Claude assisted in analyzing data extracted from over one hundred WhatsApp groups and numerous Telegram channels, cross-referencing individuals across different platforms, constructing social network maps, and pinpointing individuals susceptible to recruitment due to financial hardship, family separation, or disenchantment with Syria's government.

The operation additionally identified persons with family members still residing in Xinjiang. Claude supported the creation of persuasive messages in regional languages, locating individuals and entities, providing instantaneous translation of communications, and assessing the trustworthiness of recruitment pitches. The same campaign also targeted diaspora journalists, notably Uyghur Post, through coordinated mass-reporting and bot-driven amplification tactics.

Stealing from Anthropic

A particularly striking finding from Anthropic's investigation involves Chinese organizations extracting the company's intellectual property. Though widely documented during 2024 and 2025, this pattern persists as Chinese entities employ distillation—a technique for replicating an AI model's capabilities without directly accessing the model itself.

Anthropic identified multiple major Chinese AI companies executing large-scale distillation operations intended to capture Claude's reasoning abilities and other functionalities for incorporation into their proprietary models. The most extensive campaign allegedly originated from Alibaba, which generated more than 151 million Claude interactions spanning May through July 2026. This activity occasionally reached approximately 3 million daily requests distributed across thousands of fraudulent accounts. According to Anthropic, the extracted chain-of-thought information contributed to training Qwen 3.x, particularly enhancing capabilities in reasoning, coding, autonomous software engineering, kernel development, and extended-duration problem-solving tasks.

Alibaba represents only one instance among numerous offenders. Anthropic has documented comparable campaigns by DeepSeek, Xiaomi, Zhipu/Z.ai, and additional companies. Methods employed encompass proxy infrastructure, fake accounts, masking organizational identity, and redirecting customer inquiries toward Claude while acquiring harvested Claude outputs from external sources. DeepSeek alone allegedly produced more than 12.1 million interactions within a 14-day window, whereas Xiaomi generated over 400,000.

Google Preferred Source

Anthropic characterizes this conduct as distillation: the covert acquisition of responses from a frontier model followed by replicating the derived knowledge using substantially reduced computational resources, development duration, and financial investment.

Source: Tom's Hardware · Reporting supplemented by The Silicon Ledger staff.