Iran used Anthropic's Claude AI system to conduct targeting research against U.S. Navy warships operating in the Middle East, according to reporting from QZ and details disclosed by Anthropic. The revelation positions Claude at the center of one of the most concrete examples yet of a nation-state exploiting a commercial large language model for military intelligence purposes.
The incident fits a pattern that Anthropic has previously flagged involving Claude's use in missile-related research and espionage operations. Taken together, these cases suggest that adversarial actors are actively probing the limits of AI guardrails, sometimes successfully, to extract operationally useful information.
What the Targeting Operation Involved
Accounts linked to Iranian operators used Claude to research vessel movements, naval infrastructure, and related intelligence that could support targeting decisions against American warships. The sessions were identified and terminated by Anthropic after the company detected policy violations. Anthropic said it subsequently shut down the accounts involved and reported its findings, a process the company has increasingly formalized as misuse incidents have multiplied.
Key Facts
- Iranian-linked accounts used Claude to gather intelligence on U.S. Navy warships in the Middle East region.
- Anthropic detected the violations, terminated the accounts, and disclosed the activity.
- The incident is among the most serious known cases of a state actor using a commercial AI model for military targeting.
- Anthropic has separately reported Claude being used in missile research and propaganda operations.
- No confirmation has been given as to whether the information obtained influenced any specific military action.
It remains unclear whether the intelligence gathered through Claude was used to inform any actual operation. What is clear is that the queries went far enough to constitute a significant policy breach. Iranian-linked accounts have also used Claude for propaganda generation alongside the naval targeting activity, pointing to a broader, coordinated effort to weaponize the tool across multiple fronts.
"We terminated the accounts involved and are continuing to improve our ability to detect and prevent this kind of misuse."Anthropic spokesperson, via QZ
Anthropic's Response and the Wider Misuse Problem
Anthropic has been unusually transparent about disclosing these incidents, a stance that distinguishes it from many peers in the AI industry. The company publishes reports on misuse and cooperates with government agencies when state-actor involvement is identified. Still, the pace of incidents is testing that transparency. In recent months alone, Claude has been cited in cases involving fake identity creation, malware deployment, and now naval targeting by a foreign government.
The question of how much responsibility falls on the model maker versus the platform is one the industry has not resolved. Anthropic's CEO has previously acknowledged uncertainty about the precise role Claude played in at least one Iran-linked incident, underscoring how difficult attribution can be even for the company building and operating the system. Claude's safety architecture includes classifiers and filters designed to block dangerous queries, but determined actors with time and resources can sometimes find paths around them.
The naval targeting case will likely intensify pressure on AI companies to implement stricter identity verification for API access, tighter monitoring of sensitive query categories, and faster escalation paths when government actors are suspected. Regulators in Washington have been watching these incidents closely, and this latest disclosure may accelerate legislative conversations about mandatory reporting requirements for AI misuse involving national security.
For Anthropic, the challenge is sustaining an open, commercially viable platform while preventing it from being turned into an intelligence tool by adversarial governments. That balance is getting harder to maintain as AI capabilities grow and the strategic value of these systems to state actors becomes more apparent.