Anthropic Says It Removed Claude Accounts Tied to Nine Influence Operations
The company says it can spot some campaigns while they are still being built, but its visibility narrows once deceptive content leaves Claude for radio, news outlets, and social platforms.
Listen to this story
The audio brief
Story brief
3 key pointsAnthropic’s September 2026 threat report details nine Claude-linked influence operations spanning six continents, with actors using the model for far more than drafting posts: fake identities, news sites, forged documents, staffing systems, and repeatable distribution workflows. The company removed associated accounts and says model-use signals can expose campaigns before publication. But the intervention is...
- 01
The operations involved actors linked to Russia, Iran, Turkey, the Gulf, South Asia, Africa, and Europe.
- 02
A Central African Republic campaign reportedly used Radio Lengo Songo, Telegram, and local outlets to distribute content daily.
- 03
Most identified content generated little authentic engagement; state-media distribution produced the broadest reach.
Anthropic says it removed accounts tied to nine influence operations that used Claude to create deceptive political material and the systems needed to distribute it. The cases stretched across six continents, showing how an AI assistant can support both fake content and the organizational work behind it.
In its September threat report, Anthropic said the operations originated in Russia, Iran, Turkey, the Gulf, South Asia, Africa, and Europe. It attributed the activity to a mix of governments, state-aligned propaganda institutions and media, private influence firms, domestic political operators, and an exiled opposition movement. Several campaigns were timed around elections, including fabricated claims about Moldova’s president before its September 2025 vote and fake grassroots posts prepared ahead of Kenya’s 2027 election.
From posts to an operating system
The reported activity went beyond prompting a model for a single post. Anthropic said actors built networks of fake social-media profiles and entire news sites, then used deceptive personas and impersonations of real people and institutions to hide who was behind the material. The company also found actors using persistent files, shared source lists, evasion rules, custom software, and batch calls rather than relying only on isolated prompts.
The reported uses of Claude included
- Creating contracts, job descriptions, staff-scoring rubrics, scripts, graphics, posts, and political talking points for a Central African Republic operation.
- Producing forged government documents and building personas, fake news sites, and deceptive political content.
- Turning standing instructions and approved sources into repeatable content workflows.
One campaign reached beyond the platform
Anthropic described its most detailed case as a Russian state-aligned operation in the Central African Republic. It said a Russian-speaking actor in Bangui supplied content for an operation distributed through Radio Lengo Songo and other outlets. Anthropic assessed the campaign as Breakout Scale Category Four, saying its material was broadcast daily, amplified on Telegram, and carried by local news outlets.
That case illustrates the difference between producing content and giving it reach. Anthropic said most content it found drew little or no authentic engagement, and that state-media distribution created the widest authentic reach among the reported operations. In the Central African Republic case, the company said Claude refused a request to name real people as militants in an effort to prompt security action. The actor instead shifted to anonymous-source framing.
Detection before publication, with a boundary
Anthropic’s proposed advantage is timing. The company said planning and content-generation activity can leave detectable signals, allowing it to identify some operations before content reaches social-media platforms. Once it identifies an operation, Anthropic says it removes involved accounts, attributes the activity to the organization behind it, and feeds the tactics it found into automated detection systems.
But the report also sets out a practical constraint: a model provider’s direct view is at the production stage, not across every channel where a campaign may later travel. That makes account removals and behavioral detection useful interventions, while leaving the harder question of how to stop material that has already entered a broader media network.
Editorial analysis
Our Read
Anthropic’s report makes an important operational claim: AI providers may see a campaign’s planning machinery before platforms see its posts. The Central African Republic example also shows the limit of that advantage. Anthropic says it removed the account, yet the reported operation had a distribution route through radio, Telegram, and local outlets. The strategic question is whether upstream detection can reliably interrupt a campaign before those channels give it public reach. The next evidence worth watching is whether providers disclose how often detections occur early enough to prevent distribution, rather than only documenting operations after they have been mapped.
Sources
- anthropic.comCountering misuse of AI: September 2026 / Anthropic
Loading discussion...
Reader comments
Newest comments first. Replies stay oldest first.