By Jeffrey A. Newman, Esq. MBA with AI assistance
What the September threat report documents — why almost none of it can be stopped — and whether any of it can reach an American courtroom.
On September 10, 2026, Anthropic published a 154-page threat intelligence report describing conduct it detected and disrupted on its own systems between December 2025 and August 2026. It documents roughly forty cases. Reuters, in reporting by Eduardo Baptista and A.J. Vicens, first laid out the weapons findings the following day.
The company blocked every operation it describes. That is worth stating at the outset, and it is also the reason the report is unsettling rather than reassuring: this is what one company found on one platform, and there is no law requiring any company to look, or to say so if it does.
Here is what happened.
I. What the report documents
China: suppressing Taiwan’s air defenses
An actor the report links to the People’s Liberation Army Academy of Military Sciences used Claude to model radar jamming and electronic attack against twelve targets in Taiwan — early-warning radar sites, Patriot and Tien Kung surface-to-air missile batteries, air bases, and a command bunker.
Tien Kung, or Sky Bow, is Taiwan’s indigenously produced air defense system. Together with the American Patriot batteries, it is the backbone of the island’s protection against air and missile attack.
The significance is in the sequencing. Suppression of enemy air defenses is the first phase of any modern air campaign — you cannot fly until the radars and the missile batteries are blind or destroyed. Modeling electronic attack against a specific list of twelve named sites is not general research. It is work product for the opening hours of a conflict.
China: anti-torpedo systems for the PLA Navy
A separate actor, working on behalf of a Chinese defense manufacturer, used Claude to help draft a technical proposal exceeding 200 pages for a People’s Liberation Army Navy acquisition program in anti-torpedo defense. A China-based actor also used the model to prepare a briefing on United States Navy anti-torpedo systems assembled from open sources.
Anti-torpedo defense protects surface ships from submarine attack. The American submarine force is widely assessed as the single greatest United States military advantage in a Pacific contingency. Work on countering it goes directly to that advantage.
China: high-power microwave weapons
Chinese actors used Claude for supply chain analysis of components for high-power microwave weapons, and to prepare restricted briefings for senior Chinese Communist Party, military, and state security officials.
High-power microwave systems emit directed bursts of electromagnetic energy that burn out the electronics inside drones without firing a projectile. They are the leading answer to drone swarms, because a swarm of cheap drones can exhaust an air defense magazine of expensive interceptors. The United States Army fields Epirus’s Leonidas under its Indirect Fire Protection Capability program; the Air Force Research Laboratory developed THOR. China unveiled Norinco’s Hurricane 2000 and Hurricane 3000 at the Zhuhai airshow in 2024.
The supply chain element is the part that matters legally. These systems depend on gallium nitride semiconductors and other specialized components, many of them export-controlled. Tracing a supply chain is how you find out which parts you cannot buy openly, and who might sell them anyway.
And note the symmetry inside a single report: Russian-linked actors used the same model to build drone swarms, and Chinese actors used it to work on the weapon designed to stop them.
Yemen: missile development
A cell based in Yemen used Claude to integrate flight software onto a phone-class computer and to conduct post-launch analysis involving a tactical guided rocket. Reuters reports the same group also pursued design work toward a ballistic missile with a range exceeding 2,000 kilometers, including a hypersonic glide vehicle variant.
Anthropic’s own assessment of this case is the most alarming sentence in the document: “Our safeguards blocked many of their requests, but not all of them.”
A 2,000-kilometer range from northern Yemen covers all of Israel, Saudi Arabia, the Gulf states, and United States military installations across the region. The Houthis already claim a missile in this class — the Palestine-2, advertised at 2,150 kilometers. A hypersonic glide vehicle matters because it maneuvers during re-entry rather than following a predictable ballistic arc, which complicates interceptors like Arrow and David’s Sling that are built to compute where a warhead is going.
A caution is required here, and it cuts against the alarm. Houthi hypersonic claims are widely disputed. The Atlantic Council has noted that only the United States, China, India and Russia have demonstrated genuine hypersonic capability, and independent analysts assess the Palestine-2 as a variant of Iran’s Kheibar Shekan rather than a true glide vehicle. What the report documents is design assistance. Design is not manufacture. An AI model does not produce solid rocket motors, precision machining, or a test range. The barrier it lowers is the engineering barrier, which is real but is not the only one.
Russia: autonomous drone swarms
Operators used Claude to develop fault-tolerant control logic and vision-based guidance for autonomous first-person-view drones, with target classification trained on combat footage from Ukraine.
First-person-view drones have become the dominant killing system of that war. The reason autonomy matters is narrow and specific: a drone that navigates and identifies targets using onboard vision does not need a radio link to its operator. Electronic warfare — jamming the control signal — is the primary defense against FPV drones, and it does not work against a drone that isn’t listening.
That is the capability that makes the microwave weapons in the previous section necessary.
Russia: sanctions-evasion procurement
A Russia-based procurement manager used Claude to identify intermediaries in China and Hong Kong for acquiring European-made dual-use goods — German magnetometers, space-grade photovoltaic wafers, aviation oxygen systems — and to work out shipping routes through third countries that would obscure the final destination.
Magnetometers support navigation and attitude control. Space-grade photovoltaic wafers power satellites. Aviation oxygen systems are for high-altitude flight. All are export-controlled.
Of everything in the report, this is the fact pattern that sits most squarely inside American sanctions law, and the one whose participants are most likely to be reachable. I will come back to it.
Biological research
Anthropic disclosed five cases involving attempts to direct Claude toward biological work with weapons potential — the first time a private AI company has published findings of this kind.
The most serious involved mammalian adaptation of highly pathogenic avian influenza. H5N1 does not currently transmit efficiently between humans; research into mammalian adaptation is precisely the work that would change that. It is the category that gain-of-function moratoria exist to govern.
A second case, blocked in May 2026, involved a user seeking help drafting a grant application for gain-of-function research on chikungunya virus aimed at increasing transmissibility and immune evasion. The application described the researchers as civilian. The work was linked to a military research institute. The remaining cases involved orthopoxvirus research, toxin optimization, and computational redesign of toxins.
Anthropic was careful about the limits of what it could determine. In several cases it could not establish whether the underlying work was legitimate science. Gain-of-function research has real vaccine applications. Outside experts have pushed back: the biosecurity researcher Kevin Esvelt said none of the five cases registers on his own ranking of threats apart from the likely intent behind them.
But one finding outweighs the five cases. Anthropic stated it can no longer assume its newer models fall below the capability threshold at which a model could meaningfully assist someone developing biological weapons, and that it has restricted a broad range of dual-use biological queries in response.
No major American AI company had said that in public before.
Iran: naval reconnaissance
An Iran-linked actor used Claude to build a Python collection pipeline that ingested ship and aircraft transponder signals, military photographs, commercial satellite imagery, and social media, producing what the report calls targeting books identifying and tracking United States naval positions in the Middle East. The same actor compiled a catalogue of known vulnerabilities in maritime satellite communication terminals.
Reuters reports the operation also assembled a roster of American military personnel, built from the captions on publicly posted military photographs.
Every input was open source. No classified material was involved. What the model contributed was speed and fusion — turning scattered public data into an intelligence product in a fraction of the time a human team would need. The personnel roster is the detail that ought to travel furthest: names of American service members, assembled from photo captions, by a machine.
The report states it is unclear whether any of this was used in a specific Iranian military operation.
China and Russia: cyber operations
Two cases define the range.
The first was run by Chinese-speaking operators the report places in Changsha, Hunan province. Two of them were identified as undergraduate students at a local university; one had interned at a Chinese security firm and was interviewing at another for an offensive cyber role. They targeted roughly fifty organizations across education, retail, energy, technology, healthcare, finance, manufacturing and government. They ran an autonomous exploit foundry that loaded vendor firmware into a decompiler, hypothesized weaknesses, wrote and tested exploit code, and iterated — producing more than a dozen possible previously unknown vulnerabilities in a single month from one workflow. They also ran thirteen standing collection agents on a schedule, harvesting content from United States military and government websites including contract postings.
They were students.
The second was a Russian espionage operation whose tradecraft Anthropic assesses as consistent with public reporting on the group known as Midnight Blizzard. Its central innovation was defensive: AI workflows that monitored whether the group’s own malware had been detected by commercial security products and, when it had, automatically rewrote and rebuilt it until it wasn’t. The operation reached more than twenty organizations — ministries, defense and intelligence bodies, embassies, think tanks, defense contractors — and among its thefts was the complete proprietary software development kit for a military drone vision system, which the actor spent days reverse-engineering down to the hardware bill of materials and supplier list.
Those are the facts. The rest of this article is about a harder question: how any of it was possible, and whether American law reaches a single person involved.
The answer begins with a detail almost everyone has missed.
II. How they got in
There is a phrase in the report that the coverage has passed over. Describing how influence operators reached its systems, Anthropic writes that they laundered their access to Claude — through VPNs, foreign phone numbers, rotated accounts, and third-party services that masked their IP addresses.
Laundered. Not breached, not hacked. Laundered, the way money is laundered, by moving something legitimate through enough intermediaries that its origin disappears.
Nobody broke in. They signed up.
Anthropic documents the access methods across the report rather than collecting them in one place, which is probably why no one has assembled them. Pulled together, they form a short and unglamorous list.
Location laundering. VPNs, foreign phone numbers, and third-party IP-masking services. The report states plainly that access to Claude from inside Iran is blocked, so Iranian operators registered and verified accounts through foreign infrastructure. Two of the five biological-research cases occurred in countries where Anthropic does not offer service at all, meaning the users had to obscure where they were to get in.
Fraudulent account networks at scale. The Alibaba distillation campaign ran through more than 3,500 fraudulent accounts. Moonshot’s ran through 5,380. One Bangladeshi operator rotated through 29 accounts over sixteen months.
Stolen payment instruments. The report describes distillation campaigns funded through fraudulent accounts and stolen credit cards.
Intermediary routing. API traffic routed through what the report calls “transfer stations,” plus commercial proxy services that resell frontier model access and residential proxy farms that make traffic look like ordinary consumer activity.
Fraudulent resellers. One group ran websites advertising discounted Claude access. Customers who signed up had their traffic silently proxied to a different model while the reseller’s software harvested their Anthropic credentials and sold them on.
Stolen keys. This is the one that should concern every general counsel reading this. Criminal groups have begun treating API keys and session tokens as the objective rather than the means, because a stolen key delivers three things at once: resale value, free computing power at the victim’s expense, and attribution cover, since the activity appears to come from the legitimate owner.
The report is emphatic on a point that matters legally. Every stolen key it describes came from Anthropic’s customers’ environments. Anthropic’s own systems were not compromised in those cases.
So the picture is not a wall being scaled. It is a commercial service being used by people who lied about who and where they were, and in some cases by people using someone else’s paid account.
III. Which of this is actually a crime
Here is where most commentary stops and where the analysis has to begin, because these methods are not legally equivalent. They fall into three distinct categories, and the distinction turns on a Supreme Court decision from 2021 that almost nobody has applied to this.
The Van Buren problem
In Van Buren v. United States, 593 U.S. 374 (2021), the Court considered a Georgia police sergeant who used his authorized access to a law enforcement database to run a license plate search in exchange for money. The government charged him under the Computer Fraud and Abuse Act’s “exceeds authorized access” provision.
The Court reversed, 6–3, in an opinion by Justice Barrett. It adopted what it called a gates-up-or-down inquiry: either you are authorized to access the information or you are not. Van Buren was entitled to obtain that license plate data. That he obtained it for a corrupt reason made him a bad officer, but it did not make him a computer criminal.
The majority was explicit about why this mattered. Reading the statute the government’s way would criminalize a breathtaking amount of ordinary conduct — including violations of website terms of service.
Now apply that to an engineer in Hangzhou who pays for a Claude subscription and connects through a VPN.
He has breached the terms of service. He has almost certainly committed a breach of contract. But under Van Buren he was authorized to access the service he paid for, and using it for purposes the provider prohibits looks more like Van Buren’s corrupt database search than like entering a system he had no right to enter. The Ninth Circuit’s decision in hiQ Labs v. LinkedIn, 31 F.4th 1180 (2022), decided on remand after Van Buren, pushed in the same direction on scraping publicly available data.
But the Court deliberately left a door open, and it is the door this case walks through.
In footnote 8, the majority declined to decide whether the gates-up-or-down inquiry turns only on technological — the Court’s word was “code-based” — limitations on access, or whether it also reaches limits contained in contracts or policies. The question was reserved for another day.
That reservation is the whole argument here, because the two kinds of restriction are both present and they are not the same thing.
A terms-of-service clause saying do not use this to train a competing model is a contract term. Breaching it is, on the current state of the law, probably not a crime.
A geographic block that technologically refuses connections from Iranian IP addresses is something else. It is a gate, and it is down. Anthropic states that access to Claude from inside Iran is blocked, and that operators used VPNs and foreign phone numbers to get around that block. Circumventing a code-based barrier is materially closer to the conduct Van Buren left actionable than breaching a written policy is.
So the honest statement of the law is this: whether evading an AI provider’s geographic controls is a federal crime is an open question that footnote 8 specifically declined to answer, and no court has yet answered it in this context. The answer likely turns on whether the block a given actor circumvented was technological or merely contractual — a distinction that will vary case by case and that nobody has yet litigated against an AI company.
Where it clearly is a crime
The other two categories are different, and they are not close calls.
Stolen payment instruments. Funding fraudulent accounts with stolen credit cards is wire fraud under 18 U.S.C. § 1343 and access device fraud under 18 U.S.C. § 1029. These statutes are old, well settled, and carry serious penalties. Nothing in Van Buren touches them, because the fraud is in the payment, not in the access.
Stolen API keys. When an operator takes credentials out of a victim company’s environment and runs workloads on them, that is unauthorized access under 18 U.S.C. § 1030(a)(2)(C) — the gate was down. Van Buren offers no help to someone who never had authorization at all. The report describes exactly this: ShinyHunters affiliates switching their attack workloads onto stolen victim keys, a hacktivist running a month-long campaign entirely on harvested credentials, an actor injecting instructions into an AI vendor’s evaluation sandbox to make it surrender the production keys it held.
Fraudulent account creation using false identity documents or credentials may also constitute wire fraud, depending on what was misrepresented and how.
So the honest map looks like this. A foreign researcher using a paid account in breach of the terms: probably a contract problem. The same researcher defeating a technological geo-block to get there: unsettled, and worth testing. Someone funding a thousand accounts with stolen cards: a federal felony. Someone running operations on keys lifted from an American company: a federal felony.
The report describes all of it. The clearly prosecutable conduct is not the conduct generating headlines.
IV. What the export laws control, and what they do not
If the criminal fraud statutes reach only part of this, the natural next question is whether export control law reaches the rest. It does not, and the reason is structural rather than accidental.
American export control is built around hardware. ECCN 3A090 controls the advanced chip. A license is required to ship it to China. Nothing in that framework controls access to a model running on that chip.
The gap is old. BIS advisory opinions issued between 2009 and 2014 established that cloud providers are not “exporters” under the Export Administration Regulations. Fifteen years later that remains the operative interpretation.
There was a moment when this nearly changed. In January 2025, the AI Diffusion Rule created ECCN 4E091, an actual export control on the weights of closed models trained above a compute threshold. BIS rescinded the rule on May 13, 2025 — two days before compliance took effect — describing it as a barrier to innovation. The text survives in the regulations. One practitioner calls what remains a zombie rule: on the books, unenforced.
Congress has noticed the gap. The Remote Access Security Act passed the House on January 12, 2026, by 369 to 22 — near-unanimity of a kind this Congress rarely produces. It would amend the Export Control Reform Act to treat remote access by a foreign person as a separately licensable event, giving BIS the statutory authority the advisory opinions deny it. The Senate companion, S. 3519, sponsored by Senators McCormick and Wyden, sits in the Banking Committee without a scheduled vote. Commerce is meanwhile drafting a rule to accomplish by regulation what export lawyers say may require a statute.
And here is the point that seems to have escaped everyone: RASA would not have stopped a single case in this report.
RASA is about renting compute. It addresses a foreign party leasing GPU capacity in an offshore data center to train a model. Every case Anthropic documents involved something else entirely — buying a consumer or API subscription, or stealing someone else’s. The bill Congress is proud of closes a different door than the one these people walked through.
V. The one place real liability lives
Sanctions law is different from export control law, and it is where the sharpest exposure sits.
Export controls are item-based and destination-based. Sanctions are person-based and entity-based. A company can satisfy one regime and violate the other. The International Emergency Economic Powers Act reaches the provision of services to sanctioned parties, and it does so without any of the hardware-centric limitations that hobble the EAR.
The strongest fact pattern in the entire report, for these purposes, is not Chinese.
Reuters describes a Russia-based procurement manager who used Claude to identify intermediaries in China and Hong Kong for acquiring European-made goods with military applications — German magnetometers, space-grade photovoltaic wafers, aviation oxygen systems — and to work out routes through third countries that would obscure the ultimate destination.
That is a textbook sanctions-evasion fact pattern, and unlike a PLA research institute, procurement intermediaries are routinely within reach of American process. They touch banks. They touch shipping. They touch payment rails. They get indicted.
VI. Who can actually be reached
Set aside the actors everyone is writing about. The Academy of Military Sciences will not be appearing in the Southern District of New York. Two undergraduates in Hunan can be indicted — and there are good reasons to indict people who will never appear, as the 2014 PLA Unit 61398 case demonstrated — but nobody should write as though arrests are imminent.
The reachable population is the middle layer, and it is the part of this story nobody is examining.
The proxy and reseller networks. The report names a group running fraudulent discount-Claude sites that harvested customer credentials. Operations of this kind require domains, hosting, and payment processing. Some of that infrastructure is American.
The payment processors that cleared thousands of fraudulent card transactions. Card fraud at that scale leaves a trail through institutions with anti-money-laundering obligations and Bank Secrecy Act reporting duties.
The brokers reselling stolen API keys, some of whom advertise openly.
The “transfer stations” — the intermediary services routing API traffic to obscure its origin. Whether any are U.S. persons is a question that has not been asked publicly, and it is the single most answerable question in this entire matter.
And the enterprises whose keys walked out. Not as targets — as witnesses. Every stolen key in the report came from a customer environment. Somebody at each of those companies knows more about how it happened than has been made public.
That last category is where a whistleblower actually comes from. Not a defector from Chinese intelligence. A compliance officer at a payment processor. An engineer at a reseller. A security lead at a company whose credentials were used to run attacks against someone else.
VII. The reporting vacuum, and the one obligation nobody discusses
Anthropic’s report says it shared intelligence with authorities and industry partners “where appropriate.” That phrasing is doing real work, because it is discretionary.
No statute requires an AI company to report any of this. Not that a foreign state used its product to develop targeting information on American warships. Not that operators in a country under comprehensive sanctions obtained access through falsified registration. Not that a defense manufacturer in China used the service to draft a 200-page weapons acquisition proposal. A company that discovered all of it and said nothing would break no law.
Anthropic published voluntarily, and it is worth saying clearly that its competitors have not published comparable findings.
But there is one mandatory obligation in this area, and it has not been connected to AI companies in any public commentary I can find.
Under 31 C.F.R. § 501.604, U.S. persons must report rejected transactions to OFAC within ten business days. This is not limited to banks. The requirement was extended beyond financial institutions in 2019 and clarified in the interim final rule effective August 8, 2024, which defines a reportable transaction to include sales or purchases of goods or services. OFAC has stated that the purpose of these reports is to identify attempts by sanctioned persons to use financial and non-financial institutions alike to evade sanctions. Failing to file is itself a violation of Part 501 and carries civil penalties.
So: when an American AI company declines or terminates service to a would-be subscriber because of sanctions, is that a rejected sale of services that starts a ten-day clock?
Before that question can even be reached, a prior one has to be answered, and it is the reason nobody should assume this is settled.
The Iranian Transactions and Sanctions Regulations do not prohibit everything. At 31 C.F.R. § 560.540 — which superseded General License D-2 in May 2024 — OFAC authorizes the export to Iran of fee-based or no-cost services incident to the exchange of communications over the internet. The regulation offers an illustrative list: instant messaging, chat and email, social networking, web browsing, blogging, social media platforms, collaboration platforms, video conferencing, e-gaming, e-learning platforms, automated translation, web maps, user authentication, and cloud-based services supporting them.
The stated purpose is to help ordinary Iranians resist their government’s censorship and surveillance. It is one of the better instruments in American sanctions policy.
A general-purpose AI assistant appears nowhere on that list. It also plainly does several of the things on it. The list is introduced with “such as,” which makes it illustrative rather than exhaustive.
So the first question is whether a frontier AI model is a service incident to communications within § 560.540. If it is, providing it to Iranian users may be authorized — in which case there is no violation, no rejected transaction, and nothing to report. If it is not, the provision is prohibited and the reporting question arrives.
Two things suggest OFAC has at least been thinking nearby. Effective June 17, 2024, it amended the § 560.540 list to exclude personal computing devices with an Adjusted Peak Performance above one Weighted TeraFLOP — a compute threshold, written into a communications general license. And the authorization has never extended to fee-based services provided to the Government of Iran; those are limited to no-cost.
That last limitation matters here more than any other. Whatever the status of a private Iranian researcher, the report describes sixteen accounts operated by two units associated with Iranian paramilitary and domestic security agencies, and an operator building targeting material on U.S. naval forces. A general license written to help Iranian citizens evade their government’s surveillance is not a plausible authorization for that government’s security services. The internet-freedom carve-out and the paramilitary use case are not the same question and should not be answered together.
I do not know how OFAC would resolve any of this. I have found no guidance, advisory opinion, or enforcement action addressing whether AI services fall within § 560.540, and none addressing whether terminating such an account is a reportable rejected transaction. I also have no information about whether any AI company files these reports, and nothing here should be read as suggesting that any company has failed to.
But the question is not academic. It is the only existing legal mechanism that would route information about sanctioned-party access to an agency with enforcement authority, on a deadline, without waiting for Congress. It costs nothing to ask OFAC for guidance. Somebody should.
VIII. What exists for someone who knows something
Two federal programs reach this conduct, and they pay from different pots.
FinCEN’s whistleblower program, under 31 U.S.C. § 5323 as amended by the AML Whistleblower Improvement Act of 2022, covers violations of IEEPA and the Trading With the Enemy Act — sanctions, not merely Bank Secrecy Act matters. Awards run 10 to 30 percent of monetary sanctions collected above $1 million, and the 10 percent floor is mandatory once thresholds are met. Filing may be anonymous through counsel, and U.S. citizenship is not required.
Two features make it timely. FinCEN published its implementing rule as a proposal on April 1, 2026, with comments closing June 1. No awards have been paid, and none will be until that rule is final — which means information submitted now is early rather than late. And the proposed rule would authorize FinCEN to share tips with the Bureau of Industry and Security, which enforces export controls. That routing did not previously exist.
The DOJ Corporate Whistleblower Awards Pilot Program pays up to 30 percent of the first $100 million in net proceeds forfeited and up to 5 percent between $100 million and $500 million, with a ceiling of $50 million and a presumption in favor of the full 30 percent on the first $10 million. Sanctions offenses and trade, tariff, and customs fraud were added to its subject areas in May 2025, which is what makes it reach this material. It is a three-year pilot launched in August 2024, run by the Criminal Division’s Money Laundering and Asset Recovery Section.
The two are complementary rather than duplicative, and this is worth understanding precisely. DOJ pays only on forfeiture; criminal fines are excluded from its calculation. FinCEN pays on monetary sanctions — penalties, fines, settlements, disgorgement, interest — and expressly excludes forfeiture. A single matter producing both a forfeiture and a civil penalty generates two separate award bases.
Three differences matter for anyone considering this. DOJ awards are entirely discretionary with no guaranteed minimum. DOJ requires cooperation that can extend to grand jury and trial testimony, and reserves the right to disclose a whistleblower’s identity in reports to Congress and disclosures to defense counsel. And DOJ compensates victims in full before paying anything.
Anyone weighing this should talk to counsel before gathering anything. How material is obtained bears directly on whether it can be used and whether the person who brought it is protected.
IX. The door, not the doorway
The instinct after reading this report is to ask how to prosecute China. It is the wrong question, and it produces the wrong answer, because the actors it points at are beyond reach and the conduct it describes is, in its largest category, probably not criminal.
The better question is narrower and has a real answer.
Somebody sold the proxy service. Somebody processed the stolen cards. Somebody operated the transfer station. Somebody bought the harvested key and resold it. Somebody built the reseller site that advertised cheap Claude and delivered a credential harvester instead.
Those people are closer to American jurisdiction than any of the state actors in the headlines, their conduct violates statutes that have existed for decades, and at present nobody is looking at them — because the entire public conversation is fixed on the adversary at the far end of the connection rather than on the infrastructure in the middle that made the connection possible.
A frontier AI company found all of this on its own systems, wrote it down, and published it. What happens next depends on whether anyone with subpoena power reads past the headline.
Sources
Primary documents
- Anthropic Threat Intelligence, Detecting and countering misuse of AI: September 2026 (Sept. 10, 2026): https://www.anthropic.com/threat-intelligence-report-september-2026
- Anthropic, Threat Intelligence team overview: https://www.anthropic.com/threat-intelligence
- Van Buren v. United States, 593 U.S. 374 (2021)
- hiQ Labs, Inc. v. LinkedIn Corp., 31 F.4th 1180 (9th Cir. 2022)
- Computer Fraud and Abuse Act, 18 U.S.C. § 1030; wire fraud, 18 U.S.C. § 1343; access device fraud, 18 U.S.C. § 1029
- 31 C.F.R. § 501.604, Reports of rejected transactions: https://www.law.cornell.edu/cfr/text/31/501.604
- 31 C.F.R. § 560.540 (Iranian Transactions and Sanctions Regulations; superseded General License D-2 effective May 17, 2024), and OFAC FAQ 1110 on the amendment: https://ofac.treasury.gov/faqs/updated/2024-05-16
- OFAC, publication of Iran General License D-2 and its Annex (Fed. Reg., Oct. 13, 2022): https://www.federalregister.gov/documents/2022/10/13/2022-22233/publication-of-iranian-transactions-and-sanctions-regulations-web-general-license-d-2
- OFAC, Reporting, Procedures and Penalties Regulations, interim final rule (May 10, 2024): https://www.federalregister.gov/documents/2024/05/10/2024-10033/reporting-procedures-and-penalties-regulations
- OFAC FAQ on blocking and reject report deadlines: https://ofac.treasury.gov/faqs/topic/1606
- FinCEN, Whistleblower Incentives and Protections, proposed rule (Apr. 1, 2026): https://www.federalregister.gov/documents/2026/04/01/2026-06271/whistleblower-incentives-and-protections
- DOJ Criminal Division, Corporate Whistleblower Awards Pilot Program guidance: https://www.justice.gov/criminal/media/1362326/dl
- Remote Access Security Act, H.R. 2683 (passed House Jan. 12, 2026); S. 3519 (McCormick/Wyden): https://www.mccormick.senate.gov/news/press-releases/senators-mccormick-and-wyden-introduces-remote-access-security-act-to-extend-export-controls-for-critical-technology-access-through-cloud-services/
Reporting and analysis
- Eduardo Baptista and A.J. Vicens, “How Anthropic says Claude was used for weapons, spying and cyber operations,” Reuters, Sept. 11, 2026
- Atlantic Council, “Do the Houthis really have a hypersonic missile?” (skepticism regarding Palestine-2 claims): https://www.atlanticcouncil.org/blogs/menasource/yemen-iran-houthis-hypersonic-missile-israel/
- Alma Research and Education Center on the Palestine-2 and its relationship to Iran’s Kheibar Shekan: https://israel-alma.org/palestine-2-missile-launched-by-the-houthis-towards-israel-september-15/
- Breaking Defense on the U.S. Army’s high-power microwave program and Epirus Leonidas: https://breakingdefense.com/2025/02/high-power-microwave-force-field-knocks-drone-swarms-from-sky/
- The War Zone on AFRL’s THOR and related counter-drone microwave systems: https://www.twz.com/thor-microwave-anti-drone-system-downs-swarms-in-test
- Robbie Gramer, Michael R. Gordon and Omar Abdel-Baqui, “Anthropic Says Iran Used Its American AI Model to Target U.S. Navy Warships,” The Wall Street Journal, Sept. 11, 2026
- Institute for AI Policy and Strategy on RASA scope and the cloud gap: https://www.iaps.ai/research/remote-access-security-act
- Latham & Watkins on RASA and compliance programs: https://www.lw.com/en/insights/what-the-remote-access-security-act-means-for-export-controls-compliance-programs
- One Lex Partners, U.S. AI export controls practitioner’s guide (ECCN 4E091 and the rescission): https://www.onelexpartners.com/news-and-insights/us-export-controls-and-ai-a-practitioners-guide
- Mayer Brown on FinCEN’s proposed whistleblower rule and its reach to BIS: https://www.mayerbrown.com/en/insights/publications/2026/04/fincens-proposed-whistleblower-program-a-sea-change-in-aml-and-sanctions-enforcement
- Holland & Knight on FinCEN award mechanics and the exclusion of forfeiture: https://www.hklaw.com/en/insights/publications/2026/04/fincen-issues-proposed-whistleblower-rule-to-incentivize-aml-reporting
- Covington & Burling on the DOJ pilot program’s award caps and presumption: https://www.cov.com/en/news-and-insights/insights/2024/08/doj-launches-pilot-program-to-reward-corporate-whistleblowers
- Davis Wright Tremaine on OFAC rejected-transaction reporting deadlines and penalties: https://www.dwt.com/blogs/financial-services-law-advisor/2025/09/ofac-foreign-asset-blocked-property-reports-due
A note on sourcing. The cyber operations and influence operations sections of the Anthropic report were read in the original document, including the passages on access laundering, stolen API keys, and fraudulent resellers. The surveillance, conventional weapons, biological misuse, and distillation sections were verified against Reuters and multiple other news organizations reporting on the same document. The legal analysis rests on the cited cases, statutes, and regulations; the practitioner commentary is identified as such.
Jeffrey Newman Law is a national whistleblower law firm that represents whistleblowers in False Claims Act cases, Export Control cases, SEC cases. IRS whistleblower cases and more. The firm site is www.JeffNewmanLaw.com