
A weapons-development cell in northern Yemen used Anthropic's Claude Code in place of human software engineers to develop guidance software across three missile and rocket programs, a recent threat report from the AI company revealed.
Anthropic said the cell worked on a guided rocket, a multistage ballistic missile with a stated range goal above 2,000 kilometres, and a multi-variant missile system known as the R2000 set that included a hypersonic glide vehicle variant.
The company revealed the actors ran multiple Claude instances simultaneously, assigning different instances to coding, research and code review. Anthropic ultimately banned the associated accounts after identifying the activity and said it shared information with public- and private-sector partners.
The cell's location and weapons work have led outside reports to describe it as Houthi-linked or operating in Houthi-controlled territory. Anthropic's report itself does not identify the group as a Houthi unit or formally attribute the operation to the Houthi movement.
Claude Code Was Used in Place of Human Software Engineers
The actors did not use Claude merely as a research assistant. Anthropic said they used Claude Code to develop guidance, navigation and control software, or GNC, which governs how a flying vehicle is steered and stabilised.
The company said Claude was used to integrate an open-source autopilot with a phone-class flight computer, develop control and position-estimation software, tune settings, run a firmware build process and conduct flight simulation.
The operators also managed several Claude instances at once. One instance was assigned coding, another research, and another review of the code produced by the first. Anthropic compared the arrangement to a small engineering team in which a lead delegates different tasks.
The AI was incorporated into an existing engineering workflow, with human operators using multiple instances to divide up software-development tasks.
Three Weapons Programs Were Under Development
Anthropic identified three separate programs. The first involved a guided rocket using a commercially available, phone-class flight computer and final-phase homing guidance.
The second was a multistage ballistic missile with a stated range goal above 2,000 kilometres.
The third was a multi-variant missile system referred to by Anthropic as the R2000 set, which included a hypersonic-glide-vehicle variant. Anthropic cautioned that its visibility into the broader weapons programs was limited.
Anthropic said it found no evidence that the actors succeeded in fielding an operational device. It did, however, identify evidence of a live guided-rocket test.
The Rocket Test Failed. The Cell Then Returned to Claude
Anthropic said the weapons cell test-fired a guided rocket in Yemen and that the test appeared to fail. Within hours, the actors returned to Claude to work out why the test had failed, according to the company's investigation.
That sequence provides the clearest link between the AI-assisted software work and physical weapons testing. It also illustrates how the model was being used as part of an iterative engineering process rather than as a one-off source of information.
Anthropic said its assessment mapped the cell's activity across parts of a broader development process, including requirements work, software development, integration and testing. But the company stressed that its visibility into the complete program was limited.
The evidence therefore does not show that Claude independently designed or built a missile. It shows human operators using an AI coding system to perform portions of software engineering work while they already had access to weapons-related hardware and technical infrastructure.
The Cell Had Already Built an Offline Simulation Toolkit
One of the most consequential findings came after Anthropic shut down the accounts. The company said the actors had already built an offline simulation toolkit that did not depend on Claude or engineering environments such as MATLAB.
That means banning the accounts did not necessarily eliminate everything the group had created during the operation.
Anthropic said the Yemen-based actors deliberately split their work across multiple sessions and otherwise attempted to conceal the nature of their weapons program. The company's broader investigation found that sophisticated users were testing its safeguards and attempting to prevent individual interactions from revealing their overall objectives.
Anthropic said it banned every account it could link to the Yemen operation and shared threat information with relevant public- and private-sector partners.
No Evidence of an Operational AI-Enabled Missile
There is no evidence in the company's report that the Yemen-based cell successfully fielded an operational missile or other weapon. Anthropic said the guided-rocket test appeared to fail. It also said its visibility into the overall weapons-development program was limited.
Nor does Anthropic's report establish that the cell was formally part of the Houthi movement.
It is, however, clear that a weapons-development cell operating in northern Yemen used Claude Code to develop guidance software across three weapons program. The cell conducted a guided-rocket test that appeared to fail, attempted to circumvent Anthropic's safeguards and had already built an offline simulation toolkit before its accounts were banned.




