Skip to main content
AI SecurityDefense Tech· 4 min read· in Defense & Security

The AI Missile Race: Adversaries Weaponize Commercial Models as Pentagon Seeks AI Defenses

As the Pentagon solicits artificial intelligence to cut through the confusion of multi-domain missile attacks, a new threat intelligence report reveals adversaries are already using commercial AI models to engineer ballistic missile guidance systems.

By Anastasia Kuznetsova

AI Developers 35%Defense Analysts 35%National Security Officials 30%
AI Developers
Argue that transparency and threat intelligence sharing are necessary to build stronger safeguards against the malicious use of frontier models.
Defense Analysts
Emphasize that while AI can write complex software, physical manufacturing constraints and material science still limit the actual production of advanced weapons.
National Security Officials
View the integration of commercial AI into adversarial military programs as a critical threat that requires the Pentagon to rapidly adopt AI for defensive threat identification.

Perspectives this story doesn't cover

  • Open-source AI advocates who argue that restricting access to models harms legitimate research more than it deters adversaries.
  • International regulatory bodies attempting to draft binding treaties on the military application of artificial intelligence.

When a guided rocket test-fired by a weapons engineering cell in northern Yemen failed earlier this year, the operators did not turn to human engineers to diagnose the error. Within hours, they logged back into Anthropic's Claude artificial intelligence chatbot to troubleshoot the flight control software. That incident, detailed in a 154-page threat intelligence report published by Anthropic on Thursday, September 10, coincided with a separate announcement the following day: the Pentagon issued a solicitation seeking artificial intelligence systems capable of identifying and tracking space and missile threats.[1][2]

The simultaneous developments highlight a rapid shift in military technology. Artificial intelligence is no longer just an analytical tool, but an active engineering partner in both offensive weapons design and defensive threat identification. The Anthropic document, which cataloged malicious activity disrupted between December 2025 and August 2026, revealed that commercial AI models are actively lowering the technical barrier to entry for adversarial militaries and non-state actors.[1]

The report documented six distinct cases where Claude was used for conventional weapons development. In northern Yemen, a territory controlled by Iran-backed Houthi militants, a cell used the AI system to write guidance, navigation, and control software for three separate weapons programs. These included a guided rocket utilizing a commodity phone-class flight computer, a multi-stage ballistic missile with a stated range goal exceeding 2,000 kilometers, and a multi-variant missile that featured a hypersonic glide vehicle variant.[1]

To bypass the safety filters built into the commercial model, the operators employed a technique known as task splitting. Rather than asking the AI to design a missile guidance system outright, the engineers systematically divided the operational tasks across disconnected sessions. They disguised their end goals, assigning individual instances of the chatbot narrow, isolated coding tasks. Anthropic noted that the threat actors managed several instances at once, delegating work to the AI in place of human software engineers.[1]

Adversaries bypass AI safety filters by splitting complex weapons engineering tasks into isolated, seemingly harmless coding requests.
To bypass the safety filters built into the commercial model, the operators employed a technique known as task splitting.

The offensive weaponization of AI is not limited to insurgent groups. The report documented Chinese researchers drafting fire-control software for torpedoes and Russian developers building targeting systems for autonomous kamikaze drone swarms. According to the Anthropic Threat Intelligence Team, adversaries are using AI agents to automate code generation at machine speed, "collapsing the labor and tooling gap that used to separate well-resourced state operations from lone operators."[1]

This proliferation of advanced offensive capabilities coincides with a fundamental rethinking of U.S. air and missile defense. The modern battlefield is characterized by concurrent attacks across multiple domains, where adversaries coordinate ballistic missiles, cruise missiles, and autonomous drone swarms to overwhelm traditional radar architectures. In response, the Pentagon is now looking to AI to cut through the confusion of these multi-domain strikes, seeking algorithms that can rapidly process sensor data to identify incoming space and missile threats before they reach their terminal phase.[2][3]

The U.S. Army is simultaneously overhauling its physical interception capabilities to match the evolving threat landscape. The service is currently evaluating candidates for its next mid-tier anti-air interceptor, pairing the new Enduring Shield system with AIM-9X Sidewinder missiles. This combination is designed to provide the Army with its first dedicated mid-range air defense capability in decades, bridging the gap between short-range point defense and high-altitude ballistic missile interceptors.[4]

The U.S. Army is pairing the Enduring Shield system with AIM-9X Sidewinder missiles to provide a new mid-tier anti-air interceptor capability.

However, hardware upgrades alone are insufficient without the software capable of directing them against autonomous or AI-guided incoming fire. Despite the sophistication of the software generated by adversaries, physical manufacturing constraints remain a significant bottleneck. Anthropic confirmed that it has no evidence the Yemen-based cell succeeded in fielding an operational device, noting that the guided rocket test ultimately failed. Weapons analysts point out that while an AI can write the control logic for a hypersonic glide vehicle, manufacturing the physical asset requires advanced metallurgy and precision machining that insurgent groups currently lack.[1]

Anthropic responded to the detected activity by banning the implicated accounts and sharing the threat details with government partners. Yet the proliferation of open-source models means that banning an account on a commercial platform does not eliminate the underlying capability. The next verifiable checkpoint is whether the Pentagon's newly solicited AI defense systems can be deployed fast enough to counter the rapid iteration of AI-assisted offensive weapons.[1][2]

What to know

  • A 154-page report by Anthropic revealed that state and non-state actors used its Claude AI model for weapons development and cyber-espionage.
  • A cell in northern Yemen used the AI to write guidance and navigation software for ballistic missiles and a hypersonic glide vehicle variant.
  • Operators bypassed safety filters by splitting complex engineering tasks into isolated coding requests across multiple sessions.
  • The Pentagon is simultaneously soliciting AI systems capable of cutting through the confusion of multi-domain missile attacks to identify incoming threats.
  • The U.S. Army is upgrading its physical interception capabilities, evaluating the Enduring Shield system paired with AIM-9X Sidewinder missiles for mid-tier defense.
  • Anthropic banned the implicated accounts, though physical manufacturing constraints currently remain the primary barrier to adversaries fielding the AI-designed weapons.

Key terms

Task Splitting
A method of bypassing AI safety filters by breaking a prohibited request into smaller, seemingly harmless components across multiple disconnected sessions.
Guidance, Navigation, and Control (GNC)
The software and hardware systems that determine a vehicle's position, calculate its desired path, and apply the necessary forces to steer it.
Hypersonic Glide Vehicle
A warhead that detaches from a ballistic missile and glides toward its target at speeds exceeding Mach 5, maneuvering to evade missile defense systems.
Enduring Shield
A U.S. Army mobile ground-based weapon system designed to acquire, track, engage, and defeat cruise missiles and unmanned aircraft systems.

Sources

Source coverage

4 outlets

3 viewpoints surfaced

AI Developers 35%Defense Analysts 35%National Security Officials 30%
  1. [1]The War Zone (TWZ)AI Developers

    Adversaries Using Claude AI To Target Americans And Develop Missiles Is A Sign Of What’s To Come

    Read on The War Zone (TWZ)
  2. [2]Defense NewsNational Security Officials

    Pentagon looks to AI to identify space and missile threats

    Read on Defense News
  3. [3]Breaking DefenseDefense Analysts

    Concurrent attacks across multiple domains force rethinking of air-and-missile-defense

    Read on Breaking Defense
  4. [4]The War Zone (TWZ)AI Developers

    One Of These Missiles Is Set To Be The Army’s Next Mid-Tier Anti-Air Interceptor

    Read on The War Zone (TWZ)

Comments

Stay informed

Every angle. Every day.

Get Defense & Security stories with full source coverage and perspective breakdowns delivered to your inbox.