Anthropic Says It Removed Claude Accounts Tied to Nine Influence Operations

The company says it can spot some campaigns while they are still being built, but its visibility narrows once deceptive content leaves Claude for radio, news outlets, and social platforms.

By 3 min read
Anthropic Says It Removed Claude Accounts Tied to Nine Influence Operations
Anthropic Says It Removed Claude Accounts Tied to Nine Influence Operations

Listen to this story

The audio brief

About 1:42
0:001:42
Read transcript
Anthropic says it removed accounts tied to nine influence operations that used Claude not just to write deceptive political posts, but to build the machinery around them. The campaigns spanned six continents and involved actors linked to Russia, Iran, Turkey, the Gulf, South Asia, Africa, and Europe, including governments, state-aligned media, private influence firms, political operators, and an exiled opposition movement. The activity included fake social-media identities, entire news sites, forged government documents, staffing systems, and repeatable workflows built from standing instructions and approved sources. Some operations were timed around elections, including fabricated claims about Moldova’s president before its September 2025 vote and fake grassroots posts prepared ahead of Kenya’s 2027 election. Anthropic’s most detailed case involved a Russian state-aligned operation in Bangui, in the Central African Republic. Content was distributed daily through Radio Lengo Songo, amplified on Telegram, and carried by local outlets. Anthropic classified that campaign as Breakout Scale Category Four. Yet most of the content it identified attracted little authentic engagement. The broadest reach came through state-media distribution. Claude also refused a request to name real people as militants, so the operator switched to anonymous-source framing. That points to Anthropic’s advantage—and its limit. Model-use patterns may reveal a campaign while it is still being built, allowing account removals and better safeguards. But once the material moves into broadcasters, newsrooms, and social platforms, the provider’s visibility narrows. The central constraint is stopping deceptive content after it leaves the model.

Story brief

3 key points

Anthropic’s September 2026 threat report details nine Claude-linked influence operations spanning six continents, with actors using the model for far more than drafting posts: fake identities, news sites, forged documents, staffing systems, and repeatable distribution workflows. The company removed associated accounts and says model-use signals can expose campaigns before publication. But the intervention is...

  1. 01

    The operations involved actors linked to Russia, Iran, Turkey, the Gulf, South Asia, Africa, and Europe.

  2. 02

    A Central African Republic campaign reportedly used Radio Lengo Songo, Telegram, and local outlets to distribute content daily.

  3. 03

    Most identified content generated little authentic engagement; state-media distribution produced the broadest reach.

Anthropic says it removed accounts tied to nine influence operations that used Claude to create deceptive political material and the systems needed to distribute it. The cases stretched across six continents, showing how an AI assistant can support both fake content and the organizational work behind it.

In its September threat report, Anthropic said the operations originated in Russia, Iran, Turkey, the Gulf, South Asia, Africa, and Europe. It attributed the activity to a mix of governments, state-aligned propaganda institutions and media, private influence firms, domestic political operators, and an exiled opposition movement. Several campaigns were timed around elections, including fabricated claims about Moldova’s president before its September 2025 vote and fake grassroots posts prepared ahead of Kenya’s 2027 election.

From posts to an operating system

The reported activity went beyond prompting a model for a single post. Anthropic said actors built networks of fake social-media profiles and entire news sites, then used deceptive personas and impersonations of real people and institutions to hide who was behind the material. The company also found actors using persistent files, shared source lists, evasion rules, custom software, and batch calls rather than relying only on isolated prompts.

The reported uses of Claude included

  • Creating contracts, job descriptions, staff-scoring rubrics, scripts, graphics, posts, and political talking points for a Central African Republic operation.
  • Producing forged government documents and building personas, fake news sites, and deceptive political content.
  • Turning standing instructions and approved sources into repeatable content workflows.

One campaign reached beyond the platform

Anthropic described its most detailed case as a Russian state-aligned operation in the Central African Republic. It said a Russian-speaking actor in Bangui supplied content for an operation distributed through Radio Lengo Songo and other outlets. Anthropic assessed the campaign as Breakout Scale Category Four, saying its material was broadcast daily, amplified on Telegram, and carried by local news outlets.

That case illustrates the difference between producing content and giving it reach. Anthropic said most content it found drew little or no authentic engagement, and that state-media distribution created the widest authentic reach among the reported operations. In the Central African Republic case, the company said Claude refused a request to name real people as militants in an effort to prompt security action. The actor instead shifted to anonymous-source framing.

Detection before publication, with a boundary

Anthropic’s proposed advantage is timing. The company said planning and content-generation activity can leave detectable signals, allowing it to identify some operations before content reaches social-media platforms. Once it identifies an operation, Anthropic says it removes involved accounts, attributes the activity to the organization behind it, and feeds the tactics it found into automated detection systems.

But the report also sets out a practical constraint: a model provider’s direct view is at the production stage, not across every channel where a campaign may later travel. That makes account removals and behavioral detection useful interventions, while leaving the harder question of how to stop material that has already entered a broader media network.

Editorial analysis

Our Read

Anthropic’s report makes an important operational claim: AI providers may see a campaign’s planning machinery before platforms see its posts. The Central African Republic example also shows the limit of that advantage. Anthropic says it removed the account, yet the reported operation had a distribution route through radio, Telegram, and local outlets. The strategic question is whether upstream detection can reliably interrupt a campaign before those channels give it public reach. The next evidence worth watching is whether providers disclose how often detections occur early enough to prevent distribution, rather than only documenting operations after they have been mapped.

Sources

  1. anthropic.comCountering misuse of AI: September 2026 / Anthropic

Loading discussion...