Anthropic said it disrupted multiple state-backed espionage campaigns that used its Claude models, underscoring how quickly frontier AI is becoming a tool for surveillance, cyber operations and model theft.
Anthropic blocks state-backed Claude espionage campaigns

The San Francisco-based company said the cases, found and blocked between January and July, originated in China, Iran and west Africa and targeted dissidents, ethnic minorities and other politically sensitive groups. The disclosure matters because it shows AI is no longer just helping governments automate routine work; it is being used to scale intelligence gathering, lower the cost of surveillance and widen the reach of operations that once required larger technical teams.
Among the most serious cases, Anthropic said Iranian actors used Claude to build a system that could identify people through social media accounts, while a contractor working for Malian national security authorities used the model to design software for intelligence gathering. Anthropic said the campaigns focused on communities already long targeted by those governments, including pro-democracy figures in Hong Kong, Tibetan and Falun Gong communities, and Iranian opposition groups abroad.
The company also said it stopped attempts to use Claude for weapons design, questionable biological research and dating scams, highlighting the broader risk that general-purpose models can be repurposed for both state and criminal abuse. That is a direct policy problem for AI vendors and their cloud partners: the same capabilities that make models useful for coding, research and customer service also make them attractive for low-cost intelligence work, phishing and disinformation.
For investors, the report reinforces a developing theme across the AI sector: security and misuse controls are becoming as important as model performance. Anthropic, OpenAI, Microsoft and Nvidia all face the possibility that stronger safeguards, export restrictions or compliance burdens could slow adoption in some markets even as demand for AI infrastructure accelerates. The issue also feeds into a more combustible geopolitical backdrop, where Washington, Beijing and European regulators are already weighing limits on powerful models and the hardware used to run them.
Anthropic separately accused Chinese developers Moonshot and Deepseek of secretly routing customer queries to Claude to distill outputs and improve their own models. In one case, it said Moonshot relayed almost 300,000 customer requests over 10 days through a network of 5,380 fraudulent accounts, most appearing to be in Singapore and Japan. That is economically important because it points to an additional competitive risk for U.S. AI firms: not just misuse of models, but the leakage of valuable training data and customer information to rivals.
The allegations sharpen the strategic case for tighter model access controls, stronger identity verification and more aggressive monitoring by U.S. AI providers. They also raise the probability that governments will treat advanced models less like ordinary software and more like dual-use infrastructure, with all the licensing, audit and national-security scrutiny that follows. For shareholders, the near-term winner is likely to be firms that can prove they are securing access and protecting model IP; the losers could include providers exposed to reputational damage, regulatory pressure or customer distrust as AI’s role in espionage becomes harder to ignore.
| Entity | Gains | Losses |
|---|---|---|
| Anthropic | ▲Security credibility | ▼Reputational scrutiny |
| U.S. AI vendors | ▲Demand for safeguards | ▼Compliance costs |
| China and Iran state actors | ▲Lower-cost spying tools | ▼Exposure to disclosure |
| AI rivals using distillation | ▲Cheap model access | ▼IP and privacy risk |



