Evidence note: Last checked 12 September 2026 at 18:02 BST (Europe/London). Anthropic’s case descriptions come from its investigation of activity on Claude between December 2025 and August 2026. Independent reporting has examined the report and added regional context, but the full technical evidence is not public. The immediate reach of each operation is uncertain. The governance lesson is material because two cases show that account enforcement can stop access to a model without removing software and tools already built with it.
Anthropic published a threat intelligence report on 10 September describing attempts to use Claude for cyber operations, surveillance, weapons development, biological research, fraud and model extraction. The company says it banned the accounts it identified, added detections and shared information with public or private partners where appropriate.
Those actions matter, but the report records a limit that applies to every provider offering models that can produce code. In one surveillance case, the customer had already moved the system onto local infrastructure. In a weapons case, the users had already assembled an offline simulation toolkit. Revoking the AI account interrupted further assistance; it did not retract the artefacts created during earlier sessions.
Mali surveillance platform continued on local infrastructure
In the primary report, Anthropic says a single subscriber, assessed as a consultant working with Mali’s state intelligence service, used Claude to build a platform called Lakana 360. The company says the system covered roughly 25 million SIM cards across the country’s three mobile operators.
According to Anthropic, the platform handled call records, text messages and voice traffic. Its functions included matching voices across SIM cards, flagging encryption and VPN use, creating geofenced watchlists, and connecting people to records in the national biometric registry. The report also says a warrant check was removed from the component that generated intelligence dossiers on phone numbers, with indefinite retention selected for that pipeline.
These are Anthropic’s findings, not a court judgment or a public audit of the Malian system. The case rests on Anthropic’s account and the project material it describes. Axios separately reported the disclosure and interviewed Anthropic’s head of threat intelligence, who said one contractor could automate work that once required teams of analysts.
The control boundary is established more firmly. Anthropic says the end user deployed the platform on premises with local models. Banning the Claude account stopped Anthropic from supplying more design and engineering assistance, but the deployed product remained outside the provider’s control.
Yemen weapons work retained an offline toolkit
The same problem appears in a separate case involving users in northern Yemen. Anthropic says the group used Claude Code while working on guidance, navigation and control software for three weapons programmes. The company banned the accounts and reported that the users had not fielded an operational device.
Associated Press reporting adds two qualifications. Anthropic did not identify the users, and a member of the Houthis’ political bureau disputed the account. A weapons analyst told AP that the group lacked the production and technical capacity to build the hypersonic system described in the report. Anthropic did, however, record a failed guided-rocket test and said the users returned to Claude for help diagnosing it.
Before the accounts were closed, the group had built an offline simulation toolkit. That does not establish an operational missile capability. It establishes that part of the development environment no longer depended on the service where the misuse was detected.
Account enforcement controls future service access
An account ban is a provider control. It can end the current session, revoke credentials, block payment routes and make repeat access harder. It cannot delete source code copied to another machine, disable an on-premises model or remove a manual produced from earlier conversations.
The distinction affects how providers report disruption. A statement that an operation was disrupted should identify which part stopped: access to the frontier model, the actor’s development work, active deployment, data collection or the wider organisation. Without that separation, readers can mistake service enforcement for removal of the underlying capability.
This is related to the incident-reporting gap for AI agents. An incident record needs to describe the action taken and the remaining exposure. Closing an account is an action. The residual exposure includes exported code, local models, copied data, substitute providers and infrastructure controlled by the actor.
Residual-risk review after an AI misuse finding
Providers and investigators need a second assessment after account enforcement. It should answer five concrete questions:
- Which durable artefacts were created or modified, including source code, configuration files, deployment packages, data schemas and operating manuals?
- Which systems received those artefacts, and can the actor continue work with a local model or another hosted service?
- Which organisations can limit the remaining operation, such as infrastructure providers, code hosts, affected service operators or public authorities?
- What evidence must be preserved for investigation, notification and later review?
- Which observed behaviour should become a detection or stopping condition for similar projects?
The provider will not hold every answer. That is why the handover matters. Anthropic says it shared intelligence with partners in several of the cases. The public record would be more useful if future reports separated account action, downstream notification and evidence about whether the deployed capability continued.
Model substitution also needs explicit treatment. The recent US advisory on industrial-scale model extraction described account pools, relays and switching between providers. The surveillance cases add a different route: an actor can use a hosted model to build the system, then operate the result with a local model after the hosted account is closed.
Evidence needed from providers and public authorities
Anthropic’s report gives unusually specific examples of misuse detection, account action and residual capability. It does not show how many similar projects were missed, how long each operation ran before detection or what public authorities did after receiving the information. Those questions determine whether the response reduced harm outside Anthropic’s service.
The next useful disclosures would state how providers identify high-risk software projects before deployment, when they notify affected organisations, how they assess exported artefacts, and which events require coordination with authorities. Public bodies receiving that intelligence should also explain, where security permits, whether an operation was investigated, limited or left active.
The practical conclusion is narrow. Account enforcement remains necessary, but it is not a complete containment claim. When an AI system has helped produce deployable software, the response must follow the output beyond the account.

