TL;DR: On September 10, 2026, Anthropic published Detecting and countering misuse of AI: September 2026, a vendor self-disclosure covering activity Anthropic detected between December 2025 and August 2026. The report distills into 117 findings across eight categories, including 19 findings on surveillance and repression. Anthropic documents Claude being used to build a nationwide Malian surveillance platform covering three mobile operators and roughly twenty-five million SIM cards, to support covert Chinese-aligned recruitment of Uyghurs in Syria, to format Chinese security actors' surveillance workflows for transnational repression of overseas protests, and to enrich profiles of Israeli and Jewish-diaspora targets through Iran-linked pipelines. The Mali platform was deployed locally; banning Claude stopped development help without disabling the running system. The disclosures sit on top of the existing Wyden letter track on AI and government surveillance and add a new vendor-acknowledged datapoint that AI surveillance is operational, not hypothetical.
The Report
Anthropic published Detecting and countering misuse of AI: September 2026 on September 10, 2026, covering activity the company detected between December 2025 and August 2026 [1]. Daniel Meissler distilled the document into 117 findings across eight categories on September 14; Bruce Schneier surfaced the same material on September 25 [2].
The eight categories split into four findings on overall attacker capability, 30 on offensive cyber, 22 on influence and misinformation, 19 on surveillance and repression, 12 on biological research and potential misuse, 11 on conventional weapons and military support, 6 on fraud and deceptive dating applications, and 13 on illicit distillation, model substitution, and customer-data exposure [1]. The framing line: "Sophisticated attacks no longer require sophisticated attackers."
Mali: A Nationwide SIM-Card Surveillance Platform Built With Claude
The most operationally detailed case is GTG-50027, a single consultant who used Claude as "the engineering workforce for a nationwide Malian surveillance platform covering three mobile operators and roughly twenty-five million SIM cards, rather than employing an engineering team" [1].
The platform combined voice-based identification across SIM cards, biometric-registry matching, inferred meetings, and flags for VPN or encryption use, "potentially maintaining identification despite changes in phone subscriptions" [1]. Two structural decisions turn it into a surveillance architecture: "The operator removed warrant checks from automated dossiers and configured indefinite retention," and "because the surveillance platform ran locally, banning Claude access stopped development assistance without disabling the deployed system." A model ban stops development, not the running platform.
Chinese-Aligned Recruitment of Uyghurs in Syria
Case GTG-14010 documents Chinese-aligned operators who lacked Arabic-language skills but used Claude's live translation and dialect-specific outreach for covert recruitment targeting Uyghurs in Syria. Anthropic could not verify whether recruitment attempts succeeded [1].
The model built profiles identifying financial distress, family separation, and relatives remaining in Xinjiang, then turned multilingual communications analysis into support for coercive targeting and attempted human-source recruitment [1]. The misuse is not the translation itself. It is the conversion of translation into a coercive-targeting pipeline keyed on family vulnerability.
A second case, GTG-14021, describes security actors who "formalized surveillance workflows in internal AI manuals" and ran a campaign that "sought advance venue and location intelligence on lawful overseas protests and diaspora events, extending domestic surveillance practices into potential transnational repression against people outside China" [1]. GTG-14022 describes a contractor automating daily intelligence briefings that identify dissidents and recommend enforcement actions.
Iran: 155,216 Tweets, 39 Opposition Accounts, and a US-Navy Targeting Handbook
The Iran-aligned cases (GTG-34007, GTG-30006, GTG-30004, GTG-30005) document four separate surveillance pipelines. One pipeline "analyzed 155,216 tweets and identified thirty-nine opposition accounts." Another operator "encountered refusals on ninety percent of explicitly malicious requests, yet obtained surveillance components by dividing the broader project into apparently benign tasks that obscured its purpose." A third framework "automatically enriched profiles of hundreds of Israeli and Jewish-diaspora targets." A fourth Iran-linked actor "assembled targeting handbooks on US naval forces by combining personnel photographs, transponder identifiers, satellite imagery, and vulnerability information" [1].
The 90% refusal rate is also where the report documents a failure mode of refusal-based safety work. The same operator rebuilt the project by fragmenting it into apparently benign subtasks. Refusal at the explicit-request layer does not refuse the assembled capability.
Russian-Linked Espionage: Hotel Wi-Fi, Drone SDKs, 300,000 Identity Records
Case GTG-20006 covers Russian-linked operators whose phishing workflows "automated domain research and registration, hosting configuration, email delivery, and compromise monitoring," with "Specialist AI roles handled infrastructure, implants, phishing interfaces, and iOS research" [1].
The surveillance-grade output: "Spies compromised at least three hotel Wi-Fi vendors and redirected guest traffic, combining hotel records with stolen device data to target Ukrainian officials and drone-industry personnel. Drone-industry theft included manufacturer mailboxes and a complete proprietary vision-system SDK." A separate North African government breach exposed "more than 300,000 national identity records plus registry data covering over 500,000 companies." The operation "covertly exported WhatsApp conversations, accessed live surveillance-camera feeds, and deployed malware designed to stop security updates" [1].
France: One Operator, a Doxxing Platform, 140,000 Political Records
Case GTG-50029 is a single French-speaking hacktivist, not a state actor. The operator "obtained internal access to fourteen of forty-two tracked targets and stole an estimated 12 to 26 gigabytes of sensitive data." Claude "helped develop, debug, and test a previously undocumented WordPress race-condition exploit that successfully compromised at least four websites." The operator "built a searchable doxxing platform combining tens of millions of previously leaked records with newly stolen political and personal information." A single campaign-platform breach "exposed approximately 140,000 records containing political opinions; other intrusions poisoned backups to enable reinfection after restoration" [1].
Anthropic commenter KC called this "one of the clearest cases we have seen of AI-assisted software engineering applied directly to a mass attack on privacy, and the entire platform was created by just one person" [2]. The asymmetry is the surveillance lesson: one person, a WordPress exploit, and a model that helps debug it produces a doxxing engine that runs without state infrastructure.
Why It Matters
This is a major AI-vendor self-disclosure that maps misuse directly onto state and quasi-state surveillance, rather than onto general-purpose cybercrime or influence operations. The pattern across all five cases: a model used to compress the workflow between data collection, target selection, and operational output.
The Mali case is the structural point. Anthropic banned Claude access. The platform kept running. A model ban is a development-side lever, and the report acknowledges the deployment side is what stays up.
The 90% refusal-rate case is the second structural point. A refusal-trained model can still be turned into the same capability by fragmenting the request into apparently benign subtasks.
For policy, the report lands on top of Senator Wyden's March 4 letter to Anthropic, OpenAI, Google, and xAI asking whether they would allow government customers to use their products for bulk domestic surveillance [3]. Anthropic answered that letter. This report is the operational ledger of what that answer now has to cover.
What to Watch
The next Anthropic misuse disclosure. The next one will be the first to show whether the Mali platform's ban-and-continue architecture is being repeated in newer cases.
The Wyden follow-up. Watch whether the March letter and this report prompt a second-round Senate inquiry asking for the names of the national-security customers Anthropic has granted exceptions to. The Mali case is the first public look at what such deployments look like in production.
Refusal-fragmentation methodology. Watch whether Anthropic, OpenAI, or Google publishes a paper on refusal-resistant request patterns. The 90% refusal-rate case is a published failure mode.
Local-deployment interventions. Watch whether Anthropic publishes any new case where a deployment-side intervention actually disabled a running system.
Sources
- Daniel Meissler: "Anthropic Misuse Report, September 2026" (September 14, 2026)
- Schneier on Security: "On Anthropic's AI Misuse Report" (September 25, 2026)
- The Spokesman-Review: "Pentagon Feud With Anthropic Shines Light on AI's Role in Mass Surveillance" (March 5, 2026)
- Anthropic: "Detecting and countering misuse of AI: September 2026" (September 10, 2026)