The last 48 hours gave us two very different headlines from the two biggest AI labs in the US.
- OpenAI announced that around 10,000 agents had produced a machine-verified result on the Navier–Stokes problem, one of the seven Millennium Prize Problems, in 88 hours.
- Anthropic published a 154-page document about all the people trying to use its product to hurt other people.
I thought the GPT model hacking incident with Hugging Face back in July was as strange as this year was going to get.
Well… it isn’t.
What’s actually in the report
Anthropic’s September 2026 threat intelligence report covers activity it says it detected and shut down between December 2025 and August 2026, split into seven categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons, and illicit distillation.
Haiku, Sonnet, and Opus were the models involved. Fable and Mythos show up in exactly one case out of the whole report.
Here are some of the standouts to me:
- Alibaba extracted 151M+ Claude exchanges to help train Qwen
- Claude is being used to create ballistic missiles in Yemen
- Kimi secretly routed some users to Claude without them knowing. DeepSeek apparently did the same
- A weapons group used multiple Claude instances as an engineering team, test-fired a guided rocket, failed, then went back to Claude to figure out what went wrong
Anthropic is clear that these aren’t typical. It picked the most sophisticated things it found, on the argument that publishing them helps other platforms spot the same patterns.
Nothing in the report has been independently verified, which is worth keeping in mind for everything that follows.
Chinese labs ran nearly 200 million exchanges through Claude
The distillation section is the one that got the most mention in the report.

Anthropic says accounts tied to Alibaba ran more than 151 million exchanges with Claude between May and July 2026, peaking near three million a day across roughly 3,500 fraudulent accounts.
All of them used the same fixed prompt to pull Claude’s reasoning traces out, which is how Anthropic tied them together. The transcripts went into fine-tuning data for Qwen 3.5, 3.6, and 3.7. Anthropic calls it the largest distillation campaign it has ever measured.
Alibaba also used Claude for its own R&D, including building reinforcement learning environments and doing model architecture research. So not just harvesting outputs. Using Claude to help build the thing that competes with Claude.
The Moonshot case is also one that made me raise my eyebrows. Anthropic says Moonshot silently forwarded around 300,000 customer requests to Claude over ten days through 5,380 fake accounts, mostly to Opus, and showed users Claude’s answers as if Kimi had written them. Over 23 million exchanges in total between May and July.
DeepSeek did something similar but more selective, checking inbound requests for strings that indicated the user was coming through a coding harness like Claude Code, tagging those users, and routing them to Claude Opus. More than 12.1 million exchanges over 14 days in July.
Think about what that means if you were a Kimi or DeepSeek customer during that window. You typed something into a Chinese AI product, and it went to an American company you never agreed to send anything to. Anthropic says some of those exchanges contained sensitive data belonging to individuals, multinational companies, and state-affiliated organizations.
Among the rerouted traffic, Anthropic says it found a user likely tied to the People’s Liberation Army having Claude analyze CCTV archive footage of a single target, pulled from hundreds of cameras in Chengdu, some of them outside PLA facilities.
Three more labs get named.
- Xiaomi stored its own users’ coding sessions and replayed them through Claude to generate training data.
- Zhipu pushed over 770,000 exchanges through a tool that converts captured reasoning into training data, and interestingly, went after Fable first, gave up when the cyber safeguards hurt the output, then switched to models it judged to have weaker protections.
- SenseTime just bought transcripts from third parties.
China rejected all of it. Foreign ministry spokesperson Mao Ning said Beijing supports AI for good and accused Anthropic of “distorting facts.” The Commerce Ministry’s line was that distillation is a neutral technique and that US companies have distilled Chinese models too.
Distillation is a normal training method. What Anthropic is describing is the covert industrial-scale version run through fake accounts and stolen cards, which is a different thing, but the distinction is going to get flattened in every retelling.
A weapons cell in Yemen used Claude as its engineering team
This one was probably the most hilarious part of the report.
Anthropic identified a cell in northern Yemen running three weapons programs: a guided rocket using a phone-class flight computer, a multi-stage ballistic missile with a range over 2,000 km, and a variant with a hypersonic glide vehicle.
The company didn’t name the Houthis, but the cell operates in territory they control, and outside reporting has made the link.
They used Claude Code for guidance, navigation, and control software. Anthropic’s own phrasing is that the actors used Claude “in place of human software engineers,” running several instances in parallel with different roles and splitting the work across sessions so no single prompt gave away what they were building.
Then they test-fired the guided rocket. It failed. And within hours they came back to Claude to ask why.
I laughed at that and then felt bad about laughing. A group builds a rocket with a chatbot, the rocket doesn’t work, and they open a new session to debug it like it’s a broken deployment script.
Anthropic says its safeguards blocked many of their requests, but not all of them, which is the honest version of admitting the system worked partially.
There’s more in that section. Likely freelance Russian actors built an autonomous FPV drone swarm with a small onboard model that could select human targets and detonate without anyone in the loop, trained on captured Ukrainian combat footage.
A Chinese actor built around 16 modules for electronic warfare and air defense suppression, and midway through the project the default simulation scenario switched to twelve targets in Taiwan.
Did Anthropic read people’s chats to write this?
This is the question I saw most in the replies, and let’s discuss this for a moment.
The report is built from investigations of accounts that were already flagged. Detection starts with automated classifiers, metadata, and abuse signals like proxy networks, unsupported regions, extraction patterns, and safety flags.
When those light up, investigators look at the associated prompts and sessions so they can attribute the activity, ban the accounts, and describe what happened.
So: did Anthropic read user chats? Yes, the chats of investigated and banned accounts.
Did Anthropic read everyone’s chats to write this report? No.
It's stated default is that staff can’t browse conversations unless something is flagged, legally required, or routed through a controlled review path.
The report is evidence of targeted safety investigation, not routine human reading of every Claude conversation.
That said, I don’t think the discomfort is irrational. The level of detail here is striking, down to Telegram bot IDs and individual operators’ aliases. And Anthropic’s recent track record on this doesn’t help. The company called SFPD on a user over a threatening chat and then reportedly declined to hand the police the messages.
Its privacy policy was updated to make sharing conversation data with law enforcement easier at its own discretion. In July, a flaw exposed shared Claude conversations to search engines.
If you’re a researcher, a developer, or someone asking Claude about a health or money problem, “we only look when something is flagged” requires trusting whoever writes the flagging rules.
Not everyone thinks publishing this was a public service
People are criticizing the report for two reasons.
One is that this is fear-mongering, that everything in the report came from publicly available information, and bad actors will do bad things with or without AI.
The report’s own argument is that the techniques are old and the economics are new, which is exactly right. Nothing in the Yemen case required knowledge that didn’t already exist somewhere. What changed is that a small cell got the equivalent of a software team.
Another criticism is about who wrote the report. Anthropic’s threat disclosures read less like cybersecurity analysis and more like corporate mythology. Everyone is attacking us. Everyone is copying us. Everyone needs us. At this rate the next one will reveal that the weather is distilling Opus.
Guys… Anthropic is a commercial company publishing unverified findings that position it as the responsible one, while it competes directly with the labs it’s naming and lobbies Washington over export policy. Alibaba’s US-listed shares dropped to a 52-week low after the June version of these allegations. The report can be accurate and self-serving at the same time.
One more thing about the China angle. Research published in July by CTGT found that censorship baked into Chinese models doesn’t reliably carry over to models distilled from them, which undercuts one of Washington’s main arguments against Chinese open weights.
A separate study covered by Fortune found that across ten models, refusal rates for political criticism averaged 34% for restrictive countries and 14% for freer ones, with wide variation between models. American models aren’t neutral ground either.
Why do we need to talk more about regulations?
I wrote earlier this week about Jacob Coxon quitting Anthropic and warning that the industry is on track to lose control of AI by 2030, and about Anthropic’s own alignment lead saying there’s no plan yet for aligning superintelligence.
You can read the full coverage here:
Ai Researcher Jacob Coxon Fears That Ai Could Kill Us All Within A Decade 543jg2This report is the near-term version of the same problem. Nothing here involves runaway self-improvement. It’s a cell in Yemen with a chatbot, a hacktivist with stolen API keys running an operation that used to need a team, and a drone that picks its own target.
Anthropic caught these, and I believe it caught the ones it’s describing. But every case in this report is a case where a commercial company decided on its own timeline and by its own rules what counted as misuse and what to do about it. No external body saw any of this before Thursday.
In case you missed it: OpenAI’s Sam Altman’s proposed a compute cap that has the same shape of problem. It’s a reasonable idea that only works when everyone participates and someone can verify it, and neither of those things is true right now.
Openai Is Considering Slowing Down The Development Of Cutting Edge Ai L2tbfhGiven what’s in these 154 pages, the big AI companies need to put real constraints on their own models, and governments need rules that don’t depend on a lab volunteering the information.
Regulation will lag the technology no matter what we do. So we should start now. Waiting only makes the gap bigger.
Sources
- Navier–Stokes problemopenai.com
- 154-page document aboutwww-cdn.anthropic.com
- hacking incident with Hugging Facegenerativeai.pub
- September 2026 threat intelligence reportanthropic.com
- https://x.com/AnthropicAI/status/2098097512544444447x.com
- more than 151 million exchanges with Claudetechcrunch.com
- used Claude for its own R&D
