Houthis used Anthropic AI in an attempt to build ballistic missiles
The Financial Times reports that Houthi-linked users in northern Yemen used Anthropic’s Claude models while attempting to develop guided rockets and ballistic missiles. The reporting follows Anthropic’s September 2026 threat-intelligence report, which says the company identified and disrupted a Yemen-based cell running three weapons programmes. Anthropic says the group used Claude and Claude Code as part of its engineering work, then blocked the accounts.
The company describes one guided rocket using a commodity phone-class flight computer and final-phase homing guidance. It also describes a multi-stage ballistic missile with a stated range goal above 2,000 kilometres, plus a related set of missile concepts that included a hypersonic-glide-vehicle variant. Anthropic’s report says the actors conducted a live field test of the guided-rocket programme. These are details reported by Anthropic about its investigation; they do not establish that every design reached operational deployment or that the stated performance goals were achieved.
The case is part of a wider report covering six weapons-related investigations, including activity connected to China and Russia. Anthropic says the actors used its systems for software, engineering iteration, procurement research and intelligence work. It also says it added classifiers intended to detect and block requests associated with high-yield explosives and weapons development, while banning accounts that violate its policies.
The significance is less that a chatbot independently designed a missile than that general-purpose AI can become one layer in a larger weapons-development workflow. Code generation, documentation, translation and rapid troubleshooting can lower the cost of specialised technical work, even when physical manufacturing, testing and military expertise remain necessary. The report therefore adds pressure on model providers to detect harmful use without relying only on users to follow terms of service.
For AI users, makers and policymakers, the episode is a concrete governance test. Providers need clear boundaries, monitoring and escalation paths; governments and researchers need ways to assess whether safeguards work in practice; and organisations using capable models need auditable permissions and human accountability. Anthropic’s account is a company investigation, so independent confirmation of the cell’s identity, the designs and the field test remains important. The broader lesson is well supported: safety controls must address not only final answers, but also the cumulative assistance an AI system can provide across a long technical project.