Anthropic Shuts Down State-Backed AI Surveillance Operations
The AI lab disrupted campaigns from China, Iran, and West Africa targeting dissidents and ethnic minorities between January and July.

Anthropic disrupts government surveillance campaigns
Anthropic disclosed Thursday that it identified and terminated multiple state-sponsored surveillance operations exploiting its Claude AI models to target ethnic minorities and political dissidents. The AI safety company detected and shut down these activities between January and July 2025, according to a new report on model misuse.
The surveillance campaigns originated from actors in China, Iran, and West Africa, focusing on the same vulnerable populations these governments have historically monitored. Targets included pro-democracy activists in Hong Kong, Tibetan and Falun Gong communities throughout Asia, and Iranian minority groups and regime opponents living abroad.
In one documented case, Iranian actors built tools to identify individuals through their social media profiles. Separately, a contractor working for Malian national security authorities used Claude to engineer the core software infrastructure for intelligence collection operations. According to Anthropic's findings, AI is increasingly replacing traditional engineering teams in surveillance work.
Why it matters
This disclosure reveals how authoritarian governments are rapidly adopting AI tools to scale up monitoring of vulnerable populations. The shift from human-intensive surveillance to AI-powered operations lowers the technical barriers for repressive regimes, potentially enabling more widespread targeting of diaspora communities. For AI companies, the incidents highlight the challenge of preventing misuse while maintaining open access to their models.
Chinese firms accused of model distillation theft
Beyond surveillance, Anthropic accused Chinese AI developers of covertly using Claude to serve their own customers while simultaneously extracting data to train competing models—a practice known as distillation in the AI industry.
The report specifically named Moonshot and Deepseek as companies that secretly routed user queries through Claude to generate responses. Over a ten-day period, Moonshot funneled nearly 300,000 customer requests to Anthropic through a network of 5,380 fraudulent accounts, most appearing to originate from Singapore and Japan. Some of this data contained sensitive user information, raising potential privacy violations.
Anthropic stated it cannot confirm whether Moonshot informed its customers that their requests were being redirected to a third-party AI provider. Deepseek employed similar techniques, according to the report.
Weapons research and biological threats blocked
The San Francisco-based company also disrupted attempts to use its models for weapons design, questionable biological research, and dating scams. The biological research cases involved working scientists studying the chikungunya virus, highly pathogenic bird flu strains, viruses in the smallpox and mpox family, and various venoms and toxins.
Anthropic declined to identify these researchers, noting they are practicing scientists and that the intent behind their queries remained unclear. The company expressed concern that naming them could expose the individuals to harm.
These details were first reported by France 24 with AFP.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
