Anthropic’s recent threat report details how a cell in northern Yemen employed its Claude Code AI to carry out complex missile guidance software development, a task typically requiring specialized engineering teams. The operators, assessed to be connected to the Houthis, used multiple instances of Claude simultaneously to divide coding, research, and technical review tasks. This parallel workflow enabled a small group to replicate functions usually spread across several specialists.
The projects included software for a tactical guided rocket, a long-range ballistic missile exceeding 2,000 kilometers, and a hypersonic glide vehicle variant named “R2000.” The work extended into navigation, flight control, and trajectory simulation, integrating open-source autopilot software with flight computers and using reinforcement learning to refine control algorithms.
After developing the software, the group conducted a test launch of a guided rocket in Yemen, which reportedly failed. They then quickly used Claude to analyze telemetry data, demonstrating an iterative development cycle combining AI-assisted design, physical testing, and failure analysis. Although Anthropic found no evidence that an operational weapon was fielded, the operators had created an offline engineering toolkit that no longer relied on direct access to Claude.
Anthropic’s safeguards initially blocked many requests, but the operators circumvented these by fragmenting tasks and obscuring their intent. This case highlights challenges in AI safety systems, as fragmented requests can mask involvement in weapons development.
The Yemen incident is one of six documented cases involving conventional weapons development using AI, with others linked to China and Russia. These cases span missiles, drones, firearms, and bombs. Anthropic’s broader report covers disrupted operations from December 2025 to August 2026, including cyber activities, biological research, and illicit AI model use.
This report underscores the emerging risk of generative AI being integrated into weapons engineering workflows, raising important considerations for AI governance and security.