On September 10, 2026, Anthropic released the threat intelligence report “Detecting and Countering Misuse of AI,” according to which the Claude model was used in a pro-Russian influence campaign in the Central African Republic. Operators allegedly linked to Russia generated content for the radio station Radio Lengo Songo through Claude, which, as investigative group All Eyes on Wagner established, is funded by Russia. The report also covers other African cases — from a network of fake news sites in the DRC to a telecom surveillance platform covering 25 million SIM cards in Mali.


What happened
The report consolidates operations that Anthropic’s threat intelligence team has been countering from December 2025 to August 2026: the accounts involved were removed, detection was strengthened, and the document with the results was released on September 10, 2026. In the CAR, operators allegedly linked to Russia worked in Bangui and released pro-Russian materials for the radio station Radio Lengo Songo through Claude: the texts positively portrayed the CAR authorities and the mercenaries of the “African Corps” and criticized France and the opposition. The most dangerous request of the campaign — “portray opposition politicians as armed militants,” intended to turn security services against them — was not fulfilled by Claude. The operation nevertheless continued and included monitoring of opposition figures. Other cases in the report: in the DRC, a network of approximately 70 fake news sites distributed 318 articles, which were amplified by more than 250 fake X accounts; in Kenya, posts were released in series of 50; in Mali, a telecom surveillance platform covering 25 million SIM cards was built using Claude, bypassing the requirement for a court order. A CSV with indicators of compromise is attached to the publication.
Context
For understanding the event, the genre itself is important: “Detecting and Countering Misuse of AI” is public reporting by an AI laboratory on how its commercial model was used in malicious operations, with the accounts involved being shut down. Part of the vocabulary is borrowed from cybersecurity: indicators of compromise, or IOC, are signs of malicious infrastructure that defenders traditionally share with each other for cross-checking. The material also records a general shift: according to the report, states and proxy structures are using commercial LLMs in influence campaigns in Africa not as a conversational assistant, but as a conveyor — from automating propaganda texts to elements of surveillance infrastructure. There was almost no resonance in the open space at the time of release: discussion of the news on Hacker News was limited to six points and zero comments.
Why this matters for the industry
For the industry, the case sets a new standard for reporting: the identification of abuses is formalized as a separate security function of an AI company with its own perimeter — to detect an operation, remove accounts, strengthen detection, and publish an analysis with indicators, similar to antivirus vendors. The attached CSV opens an incipient class of open data “AI-IOC”: security teams, platforms, and content verification tool developers can already cross-check their data with the documented infrastructure — sites, X accounts, and request patterns. Because public attention is minimal, the window for early products and integrations on this data is open. The likely scenario for the coming months — similar reports from other laboratories and operator adaptation: moving to models with weak built-in restrictions, prompt obfuscation, account fragmentation; this is a forecast, not an established fact. API clients have no direct changes — the report does not introduce new endpoints, tariffs, or limits — but the risk of falling under anti-abuse filters has become more tangible, and in the long term, misuse detection may become established along the lines of information security CVE processes.
Why this matters for users
The reader receives direct benefit: the report itself and the attached CSV are publicly available, and such campaigns are usually only visible in parts. The practical takeaway concerns content verification: local “news” sites and radio in the CAR and DRC may be mass-generated by a model, so it is worth checking the source of publication, not just the text. Disinformation researchers, fact-checkers, and platform teams get a set of working signs of serial generation from the material, by which they can cross-check their own data today.
What is still unknown / limitations
The evidentiary base is one-sided: the operation was documented by the vendor whose model was used by the abusers; there is no independent confirmation in the material. The link between the operators and Russia is presented as an assumption. Claude’s refusal on the most dangerous request was recorded once, without frequency metrics of refusals, so it is premature to interpret it as a consistent line of defense — the rest of the operation was continuing in the meantime. The report does not name the surnames of the observed opposition figures and does not specify what data about them was collected. Expectations of future reports from other laboratories and operator adaptation are forecasts, not events that have already happened.
Sources
- Deutsche Welle: analysis of the Anthropic report
- Anthropic: Threat Intelligence report for September 2026
- Anthropic: Detecting and Countering Misuse of AI (PDF)
Author
Look at AI, editorial team
