Anthropic has confirmed that actors linked to the Iranian government used its Claude AI system to support surveillance operations against dissidents, according to a disclosure reported by Iran International. The revelation raises fresh concerns about how authoritarian regimes are adapting commercial AI tools for use against their own citizens and political opponents abroad.

What the Misuse Involved

According to Anthropic, the Iranian regime-linked actors leveraged Claude to gather, analyze, and organize information related to individuals targeted by state surveillance. While Anthropic has not released a full technical breakdown of the methods used, the pattern suggests the actors were exploiting Claude's language and reasoning capabilities to process large volumes of open-source and social data. This is consistent with earlier incidents: Iran-linked accounts have previously used Claude for propaganda and naval targeting operations, suggesting a coordinated, multi-purpose approach to AI exploitation by state-affiliated groups.

Key Facts

  • Anthropic confirmed Iranian regime-linked actors used Claude to expand dissident surveillance.
  • The incident is part of a broader pattern of Iranian state actors abusing the platform.
  • Anthropic identified and terminated the accounts involved.
  • The misuse focused on processing information to track and profile dissidents.
  • Iran International broke the story, citing Anthropic's own disclosures.

Anthropic said it identified the accounts responsible and took action to shut them down. The company has been increasingly vocal about state-actor misuse, publishing reports that detail how its systems are being targeted. This transparency is part of a broader effort by Anthropic to hold itself accountable and alert the public and policymakers to real-world threats posed by AI misuse.

"We detected and disrupted operations using Claude that were linked to Iranian state actors targeting dissidents. Protecting individuals from AI-enabled surveillance is a priority for us."Anthropic spokesperson, via Iran International
Claude AI Handboek by Leon Tindemans
Get the Claude AI Handboek
458 pages on getting more out of Claude, by AI expert Leon Tindemans. A printed book, written in Dutch, shipped worldwide with track and trace.
View the book →

A Widening Pattern of Iranian AI Exploitation

This is not the first time Iranian actors have been caught misusing Claude. In previous incidents, groups with ties to Tehran used the model for activities ranging from influence operations to more alarming military-adjacent targeting. Reports confirmed that Iran used Claude to target US Navy assets in the Middle East, pointing to a regime willing to probe the limits of what commercial AI systems will permit across a wide range of hostile activities.

The surveillance case is distinct because it is directed inward, at individuals rather than foreign military infrastructure. Dissidents, journalists, and activists living inside Iran or in exile are among the most vulnerable to this kind of AI-assisted tracking. By using a powerful language model to sift through publicly available data, communications patterns, and social media activity, state actors can build detailed profiles at a scale and speed that would previously have required significant human resources.

Anthropic's ability to detect and disrupt these operations relies on behavioral monitoring of how its models are being queried. The company has invested in usage policies and technical safeguards designed to catch coordinated misuse, though critics argue that determined state actors will continue to find ways around these controls. The challenge is compounded by the fact that Claude's core capabilities, language understanding, summarization, research assistance, are inherently dual-use. What makes Claude's model family useful for legitimate research also makes it attractive for surveillance work if the guardrails are bypassed or probed carefully enough.

Implications for AI Safety and Policy

The disclosure will likely intensify calls for AI companies to implement stricter know-your-customer protocols and to share threat intelligence with governments and human rights organizations. It also puts pressure on Anthropic to go further in explaining exactly how these actors gained access, what data they processed, and what, if anything, Claude actually returned before the accounts were flagged.

For dissidents and activists, the news is a sobering reminder that the same tools being championed for productivity and creativity are being weaponized against them. Anthropic's response, detecting and terminating the accounts, is a necessary step, but the underlying vulnerability remains as long as adversarial regimes retain the motivation and capability to keep trying. The company has pledged continued vigilance, and the broader AI industry is watching closely to see how transparency and enforcement evolve in the face of state-level threats.

Further reading: Learn more about Claude's model family, read our background on Anthropic, or browse the latest Claude AI news.