Skip to content
Live Intelligence
Clash Report
World

Houthis Used Claude Code to Develop Missile Guidance Software: Anthropic

Anthropic says operators in northern Yemen ran parallel Claude Code instances to design guidance software, simulate trajectories, and analyze a failed rocket test, effectively compressing specialist missile-engineering work into an AI-assisted workflow.

Clash Report
Yemen's Houthi rebels launching a ballistic missile in Sanaa, March 27, 2018 - AFP
11 Sept 2026 · 12:40 GMT · 3 MIN READ
Google Search

Choose Clash Report as a preferred source and see our reporting first in Top Stories.

A cell in northern Yemen used Anthropic’s Claude Code to perform work that would ordinarily require a missile engineering team, developing software for guided rockets, a long-range ballistic missile and a hypersonic glide vehicle concept.

Anthropic’s September threat report describes operators running several Claude instances at the same time, dividing tasks between coding, research and technical review.

The company assessed the cell as highly likely to be linked to the Houthis, according to the material provided.

The operation marks one of the clearest examples in the report of generative AI being applied directly to conventional weapons development rather than used simply for research or information gathering.

Parallel AI Agents Replace Specialist Work

The Yemen-based operators used Claude Code across multiple engineering functions.

Their projects included guidance software for a tactical guided rocket, a ballistic missile with a range exceeding 2,000 km, and a hypersonic glide vehicle variant called “R2000.”

Rather than assigning the work sequentially to a single model instance, the group operated several sessions in parallel.

One could produce code while another conducted research and a third reviewed the output.

The workflow let a small group reproduce several functions normally distributed across specialist engineering teams.

From Flight Computers to Trajectory Simulation

The technical work extended into navigation, flight control and simulation.

The operators sought to integrate open-source autopilot software with a phone-class flight computer and used Claude to write navigation and control code.

They also developed six-degree-of-freedom trajectory simulations, a method for modeling an object’s movement and rotation through space.

They also used Claude for reinforcement learning work to tune flight-control algorithms.

The operators ultimately compiled the project into a standalone executable that could run offline. That meant development could continue without direct access to Claude.

Rocket Test Followed by AI Failure Analysis

The activity moved beyond software development.

The group test-fired a guided rocket in Yemen, according to the material documented by Anthropic. The test appears to have failed.

Within hours, however, the operators returned to Claude and began analyzing launch telemetry to investigate the failure.

That sequence, software development, physical testing and rapid post-test analysis, illustrates how the model was incorporated into an iterative weapons-engineering cycle rather than being used for isolated technical questions.

Anthropic said it found no evidence that the group succeeded in fielding an operational weapon.

But by the time the accounts were disrupted, the operators had already assembled an offline engineering toolkit that no longer depended on access to Claude.

Safeguards Met With Evasion

Anthropic’s safeguards blocked numerous requests during the project.

The operators adapted by obscuring the intended end use of individual tasks, dividing work across separate conversations, and using other methods to circumvent restrictions.

Anthropic subsequently banned accounts linked to the activity.

The case highlights a problem for AI safety systems: individual requests may appear disconnected from weapons development when a larger engineering project is deliberately fragmented across sessions.

Six Conventional-Weapons Cases

The Yemen operation was one of six conventional-weapons cases Anthropic documented.

Three were linked to China, two to Russia and one to Yemen. The cases covered attempts involving missiles, armed drones, firearms and bombs.

The wider report covers operations Anthropic said it disrupted between December 2025 and August 2026 across cyber operations, influence activity, surveillance, conventional weapons, biological misuse, scams and fraud, and illicit model distillation.

Anthropic also described biological research cases in which it could not establish whether scientists were conducting legitimate research or pursuing weapons-related objectives.

“You are not seeing someone in a comic book kind of way say, ‘Hey, I want to build a biological weapon to kill everybody,’” Jacob Klein, Anthropic’s head of threat intelligence, said. “It’s an incredibly nuanced situation.”

For the Yemen case, the immediate outcome was more concrete: Claude had been incorporated into a real development cycle spanning design, simulation, testing, and failure analysis.

The weapon itself was not shown to have become operational. The engineering capability assembled around it had already begun moving offline.

About the Author

Ahmet Koçak

Clash Report

Ahmet Koçak is a news editor at Clash Report based in Istanbul. He previously served as Deputy Managing Editor at Türkiye Today, helping launch the digital news platform in 2023, and spent three years as Senior Editor at Daily Sabah. His work focuses on breaking news, geopolitics, international affairs, and digital journalism.

Google Search

Choose Clash Report as a preferred source and see our reporting first in Top Stories.

0:00
0:00
Now playing · ClashPoint
EP 147

When the front line moves overnight

Guest: Daniel Reyes
0:00
0:00