Using AI for Weapons Development

Last week, Anthropic released a long and detailed document describing current misuses of their Claude models. I’m still reading it, but I wanted to flag this:

We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile (referred to as the “R2000” set) that included a hypersonic glide vehicle variant.

The actors used Claude Code in place of human software engineers to develop the guidance, navigation, and control (GNC) software that steers and stabilizes a flying vehicle. For example, they used Claude to integrate an open-source autopilot onto a phone-class flight computer, writing the control and position estimation software, tuning the control settings, running a firmware build pipeline, and performing a flight simulation. The actors managed several Claude instances at once, assigning each one a role, much as a lead would delegate work on a small engineering team: the actors tasked one instance with writing the code, another with research, and a third with reviewing the code the first instance produced.

Our safeguards blocked many of their requests, but not all of them. The actors used a variety of tactics to evade our safeguards, including hiding their goals and the products the software was meant for, and they split their work across multiple sessions so no single session revealed their full intent.

These actors carried out a sustained effort to develop guided weapons, including using Claude to design guidance software. We do not have evidence the actors succeeded in fielding an operational device; but they did test-fire a guided rocket. This field test appears to have failed: within hours, the actors returned to Claude to work out why it failed.

Expect more of this. AI systems democratize expertise and capability. Most of the time that’s a good thing, but sometimes it’s not.

Posted on September 14, 2026 at 12:07 PM3 Comments

Comments

Rontea September 14, 2026 1:28 PM

Expect more of this, yes—but expect also that a society which forgets its own soul will be guided by the machines it commands, and they will guide it to the abyss.

lurker September 14, 2026 1:56 PM

So how come these machines are accessible from Yemen? OK, maybe the bad guys were somewhere else and working for the Yemeni, or the Yemeni were using a VPN. I’m partly with @Clive here, the AI machines need to be isolated. Sandboxes and guardrails are proven BS, and anybody who still believes in them should be taken out back to talk to the tooth fairy.

But real energy gapping for this class of work is not adequate: the jobs are brought in as hard copy in a brief case, scanned in, worked on, and the results printed out on paper. Yup, the flaw is obvious: what human is capable of scanning the input for prompt injection?

An AI escapee whimpers that the genie will kill us all. No, we will kill ourselves. And it doesn’t have to be as blatant as multistage ballistic missiles. When the water stops flowing out of the taps, ATMs die, and there’s no gasoline in the bowsers, urbanised populations of any ethnicity will revert to savagery.

tfb September 14, 2026 4:15 PM

So if you use Claude code to do your job for you, Anthropic will have access to the code it writes and the instructions you gave it. And they’ll trawl through those things. And Anthropic are the buffoons who couldn’t build a sandbox for their hacking tools properly: their security is likely as good as you’d expect from that. Pretty soon everyone else will be trawling through your stuff as well.

I mean, really.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.