From Uyghurs to a prayer-times app Anthropic AI faces a surveillance crisis

Photo: © AP Photo

By Çağla Üren, Euronews Türkçe | September 11, 2026

Turkistan Times translation

Anthropic says it has identified cases in which actors linked to China, Iran and West Africa, as well as commercial spyware companies, used Claude to develop surveillance systems.

Artificial intelligence company Anthropic has published a comprehensive report summarizing cases in which its Claude models were misused for political manipulation, disinformation and surveillance. A significant section of the report focuses on the use of AI in state surveillance operations.

According to the company's new threat-intelligence report, numerous operations were recorded between January and July 2026 in which actors linked to China, Iran and West Africa, along with companies offering surveillance services for payment, made use of Claude.

Anthropic's usage policy prohibits using Claude to monitor or profile people without their consent or to violate fundamental rights and freedoms. The company said it had closed the accounts involved in every case covered by the report, updated its detection systems and, where necessary, shared its findings with industry partners and the relevant authorities.

The report says AI's role in state surveillance is not limited to data analysis. In some operations, Claude was also used as a software engineer, intelligence analyst, translator and operational planner.

One person could do the work of an engineering team

One of the most important trends identified by Anthropic was AI's ability to replace a conventional software or engineering team.

In one example provided by the company, a single consultant working for Mali's national security agencies used Claude to develop a surveillance system capable of monitoring communications across the country.

In another case, Iran-linked actors developed a malicious Firefox extension designed to collect the identities of social-media users.

In China, an intelligence unit working on religious affairs was reportedly able to carry out, with a single office and an AI assistant, work that had previously required numerous teams of analysts, enabling it to generate thousands of investigations per month.

Anthropic said this development shows that AI is becoming increasingly integrated into state security bureaucracies.

AI is also selecting targets

The second trend highlighted in the report is that AI is being used not only to build technical infrastructure but also to identify people for surveillance.

In one operation, large batches of social-media posts were uploaded to Claude, and the model was asked to create records about users' locations, demographic characteristics and political leanings.

Another unit in Iran analyzed hundreds of thousands of social-media posts and placed 39 opposition accounts on a watchlist.

China-linked actors were also reported to have had news reports and social-media posts scored for “political sensitivity” and to have flagged certain individuals for “control.”

China-linked operation targeted Uyghurs in Syria

One of the report's most striking cases involved a China-linked operation targeting Uyghurs in Syria.

Anthropic said an actor it assessed to be connected to the Chinese government used Claude to track and profile Uyghurs and Uyghur armed groups in Syria, and to recruit some individuals as sources of information.

The targets included Uyghur militants who had joined the newly established Syrian army. The Chinese government classifies these formations as terrorist organizations.

The actor fed Claude messages obtained from more than 100 WhatsApp groups and dozens of Telegram channels, using them to prepare Chinese-language intelligence files. The files examined individuals' identities, connections and vulnerabilities.

People facing financial hardship, those separated from their families and those thought to be ideologically disillusioned were singled out as potential targets.

Anthropic noted that particular attention was paid to recording whether individuals had family members living in the Xinjiang Uyghur Autonomous Region. The company assessed that using this information as leverage would be possible only in coordination with Chinese domestic-security agencies.

The actor, who did not speak Arabic, used Claude to write messages in Syrian Arabic, translate incoming replies in real time and assess whether messages sent to targets were convincing in linguistic and psychological terms.

Claude was also instructed to assume the role of an Arabic-speaking “expert adviser” and evaluate operational messages for military terminology, dialect and the target's psychology.

Some targets were offered payment in exchange for information about Uyghur units.

Anthropic reported that the actor was also working on mass-reporting campaigns, bot networks and sham front organizations designed to discredit journalists in the Uyghur diaspora.

Sixteen accounts shut down in Iran

Anthropic also announced that it had closed 16 Claude accounts believed to belong to two separate units connected to Iran's paramilitary and domestic-security institutions.

The company found that, although the two units used different methods, both fed data into the same centralized surveillance infrastructure.

One of the units was a seven-department structure operating across different Iranian provinces. It allegedly maintained an identity-record database on Iranian citizens and monitored and profiled 6,388 Iranians in a single year.

Claude was reportedly used both as an analyst and as a software-development tool.

The system also carried out social-network analysis on 155,216 tweets and specifically flagged 39 Iranian opposition or diaspora accounts.

Malicious extension disguised as a prayer-times app

Another unit in the Iranian city of Qom used Claude as if it were a full software-engineering team.

The most striking tool developed by this unit was a malicious Firefox extension called “al-Najm al-thāqib.”

According to Anthropic, the extension had already been deployed and was used to collect user identities in bulk from major social-media platforms. It was reportedly disguised as a prayer-times application.

With Claude's help, the same unit also developed tools for identifying the real identities of users on messaging applications, systems for establishing identity from telephone numbers, phishing pages designed to collect national identification numbers and mass-reporting bots for Telegram.

Both Iranian units transferred the information they collected to a centralized case-management system called “Arman.”

The report said a person's file in this system contained a national identification number, beliefs, criminal record and social-media accounts, as well as a section labelled “action.”

The company also found indications that some operators received assignments from senior Iranian officials and that the systems were used to vet people for appointment to government positions.

Claude rejected some requests but produced some surveillance tools

One notable point in Anthropic's report is that, although Claude rejected some requests for political profiling or propaganda, it still helped develop certain surveillance software.

The company acknowledged that its existing safeguards were able to block explicit requests for political profiling but could not always detect when certain technical tools would be used for surveillance.

It said the methods identified in the Iran case had therefore been incorporated into new detection systems.

Israel-linked commercial surveillance company profiled users in Iran and the Gulf

Anthropic said it also closed an account in June 2026 that was developing a commercial surveillance platform to analyze and classify social-media users in Iran and the Persian Gulf.

The activity was assessed to have been conducted by, or on behalf of, the Israeli-Singaporean commercial intelligence company “S2T Unlocking Cyberspace.”

The system's main purpose was to map users' locations, sort people into different demographic groups and produce formal intelligence reports in Arabic.

Users were divided into six groups: “urban,” “religious official,” “military,” “young,” “diaspora” and “rural.”

Individuals were also classified according to whether they were pro-government or anti-government.

Batches of about 25 social-media posts were uploaded to Claude, which was then asked to estimate the demographic profile, location and political orientation of the people who had posted them.

Anthropic noted that the system was detected while it was still in the pilot stage and that it found no evidence that more advanced operations had been used against real people.

System covering 25 million SIM cards in Mali

One of the report's most extensive cases of state surveillance was uncovered in Mali.

Anthropic said a single Claude user had developed a nationwide surveillance system for Mali's state intelligence service. The actor was assessed to be an independent consultant living in Bamako.

The system, called “Lakana 360,” was designed to monitor approximately 25 million SIM cards used across all three of Mali's national mobile operators.

According to Anthropic, the system could collect call records, SMS messages and voice calls.

It was also developed to identify the same person by voice even when different SIM cards were used, flag people who used VPNs and encryption, infer the possible occurrence of clandestine meetings and automatically place people in particular areas on watchlists.

Matching individuals against Mali's national biometric population registry and other government databases was also among the system's capabilities.

The system keeps running even if Claude is shut down

Another critical aspect of the Mali case is that the surveillance infrastructure does not depend directly on Claude.

Claude was used to develop the system's software architecture and engineering, but the final surveillance platform was designed to run on in-house servers using local AI models.

Consequently, Anthropic's closure of the relevant account does not automatically stop the Lakana 360 system once it has already been installed.

Anthropic AI is being integrated into state security bureaucracies

Anthropic said these cases show that AI is no longer merely an auxiliary tool within states' security and intelligence mechanisms.

Models can now write code, classify millions of data points, select political or demographic targets, overcome foreign-language barriers and automatically prepare intelligence reports for use by state institutions.

The company said that, particularly in the Chinese and Iranian examples, AI was used to overcome technical and bureaucratic problems in existing state-security systems.

According to the report, the communities targeted also largely overlap with groups these states have monitored in the past.

They include pro-democracy activists in Hong Kong, Tibetans, Falun Gong practitioners, the Uyghur diaspora, Iranian dissidents and minority communities.

Anthropic said it had closed the accounts connected to all the operations it identified and added the technical methods used in these surveillance activities to its security systems so that future misuse can be detected earlier.

Sources: Turkistan Times article | Original Euronews Türkçe report