China is exploiting Anthropic’s Claude for massive surveillance
The surveillance network spans a wide range of social media platforms, including Instagram, Facebook, and X.

Image by Cybernews.
- Anthropic says Chinese state-linked actors used Claude to surveil dissidents, religious groups, and diaspora communities.
- The actors used Claude to create dossiers, collect personal data, and identify possible pressure points.
- Targets included Falun Gong practitioners, Tibetan groups, Uyghurs, Catholic leaders, and Taiwanese religious figures.
- Anthropic says it banned linked accounts, disrupted operations, and strengthened safeguards after the findings.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Chinese state-linked actors used Anthropic’s Claude AI assistant to conduct surveillance of dissidents and religious communities.
AI agents were used to generate detailed dossiers on targets and identify potential vulnerabilities for government exploitation, Anthropic says.
“Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity,” Anthropic’s research team said.
Among the targets are communities that have long been suppressed and monitored by the Beijing regime, including Falun Gong practitioners, Tibetan groups, Catholic leaders, Taiwanese religious figures, Uyghur, and affiliated media organizations.
Anthropic said it banned a group of accounts it believes were linked to a Chinese government-aligned intelligence operation.
According to the company, Chinese operation was part of a much larger set of cases Anthropic identified during the first seven months of 2026.
China reducing its spy network, as AI is doing the heavylifting
The company said one People's Republic of China (PRC) religious affairs intelligence collection unit that previously consisted of multiple teams of analysts appeared to have been reduced to a single office using an AI assistant to produce thousands of investigations each month.
Anthropic said the cases demonstrate that AI can now perform tasks that previously required entire teams of intelligence analysts and translators.
During the operation, the AI was instructed to produce intelligence documents in Chinese language, including personnel research drafts, investigative reports, and regular intelligence updates.
These documents focused on religious leaders and Chinese diaspora figures across Asia. Anthropic said the targets included senior Catholic cardinals, Presbyterian Church leaders in Taiwan, Tibetan Buddhist civil society members, and representatives of the Tibetan administration in exile, as well as Falun Gong practitioners.
The Falun Gong spiritual movement has been long persecuted by the Chinese government since Beijing launched a nationwide crackdown in 1999.
Chinese authorities have repeatedly described Falun Gong as a cult, while human rights organizations have documented extensive repression of its practitioners. The Chinese regime is also known to be pressuring Tibetan and Uyghur minorities.
Claude used to harvest sensitive data
According to Anthropic, the actors used Claude to collect and organize personal information of minority group members, such as birth dates, birthplaces, immigration dates, and social media accounts.
The surveillance covered a wide range of Chinese and Western social media platforms. These included WeChat, Xiaohongshu, Douyin, Weibo, LinkedIn, Instagram, Threads, X, and Facebook.
They also collected data on religious locations, such as information about buildings, facades, floor plans, and structural diagrams.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
AI was instructed to follow Chinese narative
The actors instructed Claude to analyze targets from what Anthropic described as “China’s standpoint.”
Prompts reportedly directed the model to describe the Tibetan administration in exile using Beijing's characterization of it as an “illegal separatist administration.” They also instructed the AI to describe Falun Gong practitioners using the Chinese government's designation of them as an “evil cult.”
Anthropic said the actors also searched for “zhuāshǒu”, a term associated with China's United Front system that can refer to leverage or pressure points that can be exploited against a target.
In another case, actors uploaded large batches of social media content and instructed Claude to create structured profiles containing information about targets' locations, demographics, and political views, including confidence scores.
Anthropic also said PRC-linked actors used Claude to score social media posts and news articles for political sensitivity and identify people who could potentially be targeted for what the operators described as “control.”
AI operations infiltrated minorities outside China
Anthropic said the China-linked operation also extended to Chinese diaspora communities and religious figures outside mainland China.
A PRC actor allegedly used Claude to run a multi-day operation aimed at infiltrating Uyghur targets in Syria.
The operator reportedly had no Arabic language skills, but used Claude to draft messages in a regional dialect. Claude also assisted in translating replies in real time, role-played an expert reviewing the operation, and formatted the results for what Anthropic believes was a handoff to a case officer.
Anthropic says they disrupted malicious use of Claude
Anthropic detailed the malicious activity in an intelligence report published September 10th, describing a broader wave of AI-assisted surveillance operations identified between December, 2025 and August, 2026. In all cases, Claude Haiku, Sonnet, and Opus models were used.
According to the team, “none of the misuse cases” involved Claude Fable or Mythos-class models, with the exception of “one illicit distillation case.”
“Sophisticated and persistent threat actors continuously test our safeguards and try to circumvent the technical measures we use to detect and prevent misuse,” the team said.
“In each case we disrupted the activity involved, strengthened our AI safeguards based on what we learned, and shared intelligence with authorities and industry partners where appropriate,” Anthropic stated.
The company said it disrupted operations globally, involving actors linked to China, Iran, and West Africa.