Anthropic's latest threat-intelligence report describes a northern Yemen group working on three separate weapons programs while using Claude Code to perform software-engineering tasks.

Those projects included a guided rocket with terminal homing, a multi-stage ballistic missile with a stated range goal above 2,000 kilometers, and a multi-variant missile family referred to as R2000 that included a hypersonic glide vehicle variant.

Claude became part of the engineering process

According to Anthropic, the actors used Claude to develop guidance, navigation and control software. The model helped integrate an open-source autopilot onto a phone-class flight computer, write flight-control and position-estimation code, tune control settings, run firmware builds and perform simulations.

The workflow is more notable than any single prompt. Anthropic says the users operated several Claude instances at once, giving one coding work, another research tasks and a third responsibility for reviewing code generated by the first.

That makes the misuse problem harder to reduce to a question of whether a model can independently design a complete weapon. A sufficiently capable model can instead remove dozens of smaller engineering bottlenecks and accelerate an existing team's work.

Safeguards stopped many requests, not all of them

Anthropic says its defenses blocked many of the actors' requests. The group allegedly responded by concealing the purpose of individual tasks and distributing the work across different sessions, preventing any one conversation from revealing the full project.

This is an awkward limitation for safeguards that rely heavily on visible context. A request for one technical component may look ambiguous in isolation even when it belongs to a clearly prohibited system at the project level.

Anthropic says it has since deployed additional classifiers designed to detect and block traffic associated with high-yield explosives and weapons development.

The project reached a live field test

There is an important limit to the company's finding. Anthropic says it has no evidence that the actors succeeded in fielding an operational weapon.

They did, however, test-fire a guided rocket. Anthropic believes the test failed because the users returned to Claude within hours and used it to diagnose the failure from telemetry.

That distinction matters. The report does not demonstrate that Claude enabled the construction of a functioning advanced missile. It does describe AI-assisted engineering work that moved beyond simulation and reached physical testing.

Banning the accounts did not erase the output

Anthropic says it banned every account it could associate with the operation and shared threat information with public- and private-sector partners.

By then, however, the actors had already produced an offline simulation toolkit that no longer depended on Claude or engineering environments such as MATLAB. The company's report also describes digital modeling work intended to reduce reliance on repeated physical tests.

That creates a persistent asymmetry. Access to a centralized AI service can be revoked; exported code, simulations and accumulated engineering work cannot simply be pulled back.

Anthropic stops short of naming the Houthis

The attribution also needs precision. Anthropic identifies the actors as a cell based in northern Yemen but does not formally name the Houthis as the operators. Northern Yemen is controlled by the Iran-backed Houthi movement, which is why the report has drawn obvious scrutiny around the group.

Associated Press reported that a member of the Houthis' political bureau rejected the suggestion that the movement would rely on open-source tools to develop its military capabilities. A weapons analyst quoted by AP also cautioned that the Houthis remain far from possessing the industrial and technical capacity required to independently manufacture some of the most advanced systems described.

The broader finding is less cinematic and more consequential: frontier AI can already act as a force multiplier for teams that possess hardware, domain knowledge and military objectives of their own.