Anthropic Disrupts Claude Use in Yemen Missile-Design Work
An Anthropic misuse case covered by The National describes Yemen-based actors using Claude models and Claude Code on guided-rocket, ballistic-missile and R2000 programme work before the accounts were banned.

A Yemen-based weapons effort used Anthropic’s Claude models while working on guided-missile software, The National reported, citing an Anthropic misuse investigation that the company says ended with account bans.
The case puts a security boundary around a question that has moved beyond general warnings about artificial intelligence.
Anthropic’s account describes actors in Houthi-held northern Yemen using Claude Code and several Claude model families between December 2025 and August 2026 as they worked on three missile projects at the same time.
The most immediate project focused on adapting commercially available technology into a guided rocket.
The group used a phone-grade flight computer and worked on a homing system meant to steer the weapon during its final approach.
The software layer, not only unusual hardware, became the misuse signal: guidance, navigation and control support connected the coding workflow to a weapons programme.
A second programme aimed higher.
The actors wanted a multistage ballistic missile with a range of more than 2,000 kilometres.
A third effort, identified as the R2000 programme, covered proposed variants including a hypersonic glide vehicle, a capability usually associated with far more advanced military programmes.
Anthropic’s disruption record also shows how the work was organised.
Instead of hiring software engineers, the actors used Claude Code to generate the control software needed to keep a vehicle stable and on course.
Multiple Claude instances operated in parallel, with separate roles assigned for simulation, algorithm design, testing and coordination.
The workflow let the users break a weapons-development problem into tasks that an AI coding tool could help draft, check and revise.
The company banned the accounts and included the case in a wider report on detecting and countering AI misuse.
The case record identifies Claude Haiku, Sonnet and Opus models in the activity.
It also places the incident inside a military context in which Iran-backed Houthis use areas they control in Sanaa and northern Yemen as a base for attacks on neighbouring countries and shipping-linked targets near the Red Sea.
The geographic setting widened the risk described in the case.
Houthi-held areas in northern Yemen sit near regional shipping routes, and the report linked the same period to expanding rebel control along the Red Sea coast near Bab Al Mandeb.
That context does not turn the software work into a battlefield result, but it explains why guidance code, homing concepts and long-range ambitions drew attention from a model provider rather than only from military analysts.
The episode does not prove that Claude built a finished weapon or that any missile entered service.
Its significance is narrower and more operational: an AI assistant was used as a software-development aid inside an alleged weapons programme, and the provider later traced enough activity to describe projects, workflow and model use.
For AI companies, that distinction is the enforcement problem.
General-purpose coding models can support legitimate engineering work, but the same capabilities can help users prototype control systems, run simulations and organise complex technical tasks.
Account bans close one channel after detection; the hard part is spotting misuse while the work still looks like fragmented software development.
The Yemen case leaves Anthropic’s documented result as the confirmed endpoint.
The accounts were disrupted, the activity was published as a misuse case, and the company’s own evidence now serves as a warning that AI coding tools can compress parts of the weapons-design workflow without supplying the hardware itself.

















