Anthropic said it has disrupted attempts by Iran, China, and other countries from using its artificial intelligence (AI) models to disseminate state propaganda and spy on ethnic minorities and dissidents.
That is according to the AI company’s latest threat intelligence report issued on September 11, which covers incidents from December 2025 to August.
The report also said criminals, state institutions, and scientists, including in Russia and China, were using AI models like Claude and Gemini to design missiles and bombs as well as create deadly pathogens.
'Cognitive Warfare'
Anthropic named several Iranian state institutions it said were using its AI models to shape public opinion inside and outside the country.
The entities include the Islamic Culture and Communications Organization, which operates under the Ministry of Culture and Islamic Guidance and oversees Iran's official cultural diplomacy and international relations abroad; the Islamic Propaganda Office, a religious organization; and the Islamic Propaganda Organization, a religious and cultural group.
Anthropic accused the institutions of running “cognitive warfare” campaigns and promoting narratives created by the powerful Islamic Revolutionary Guards Corps, the elite branch of Iran’s armed forces that plays a prominent role in politics and the economy.
“In each case, the operation relied on Claude to build campaign plans, doctrine manuals, persona systems, target databases, and ministerial planning documentation,” said Anthropic’s report.
“Using the model in this manner allowed them to generate complex organizational frameworks and assets that would otherwise have required a fully staffed program office to produce.”
In one case, the Islamic Culture and Communications Organization used Claude to “complete organizational plans” for the state funeral of slain Supreme Leader Ayatollah Ali Khamenei that took place from July 3-9, Anthropic said.
Recruitment Tool
Anthropic also said it disrupted an “influence operation” by the Mujahedin-e Khalq (MEK), an exiled opposition group that seeks to overthrow the Islamic republic and that Tehran regards as a terrorist organization.
The operation, the AI company said, “used a shared AI agent to impersonate real people and recruit inside Iran.”
“The operation successfully scraped over 500 social media channels to build detailed profiles of individuals inside Iran,” the report said.
“They then grouped these targets by city, age, occupation, political alignment, and arrest history likely to help them tailor their messages to the specific audiences.”
Surveillance Operations
Anthropic said it also disrupted operations by state actors, including Iran, that used Claude to “build, run, and otherwise facilitate surveillance operations.”
In one case, Iran-based actors used Claude to build and deploy a malicious Firefox extension that harvested users’ identities from social media networks, the AI company said.
In another case, an Iranian actor used Claude to analyze hundreds of thousands of social media posts and chose 39 opposition accounts to monitor.
“The operators were state-aligned organizations that targeted the same diaspora and dissident communities these regimes have historically targeted,” Anthropic said.