Connect with us

Hi, what are you looking for?

Tech

Anthropic: Claude Was Used for Mass Surveillance and Political Influence Campaigns in Africa

Anthropic Claude Was Used for Mass Surveillance and Political Influence Campaigns in Africa
Anthropic Claude Was Used for Mass Surveillance and Political Influence Campaigns in Africa

Artificial intelligence is increasingly becoming part of the machinery behind political influence and state surveillance—and a new report from Anthropic shows just how far that shift may have already gone.

In its latest threat intelligence report, Anthropic documented multiple cases in which its Claude AI models were allegedly used to support surveillance operations, political influence campaigns, propaganda production and coordinated inauthentic behavior across Africa.

The cases included a surveillance platform reportedly designed for Mali’s intelligence service, a Russian aligned information operation in the Central African Republic, a network of fabricated news outlets targeting the Democratic Republic of Congo, an AI assisted political campaign in Kenya, and an influence operation connected to the war in Sudan.

Anthropic said the activities it documented took place between December 2025 and August 2026. The company said it disrupted the operations by banning accounts, improving detection systems and sharing relevant intelligence with authorities and other technology companies.

But the report reveals something more significant than a list of banned accounts.

Claude was not always being used simply to write propaganda. In several cases, it was being used as part of the technical infrastructure that made the operation possible.

Mali: When AI Becomes the Engineering Workforce

One of the most striking cases involved Mali.

Anthropic said a single Claude subscriber, whom it assessed was likely an independent consultant working with Mali’s national intelligence service, used Claude as the primary engineering resource behind a surveillance platform called Lakana 360.

According to Anthropic, the system was designed to operate across all three of Mali’s national mobile operators and could potentially monitor roughly 25 million SIM cards.

The reported platform was not simply an analytical dashboard.

Anthropic said it incorporated telecommunications data, including call records, text messages and voice traffic, and could generate intelligence dossiers associated with targeted phone numbers. The system was also designed to circumvent legal requirements requiring court authorization for certain surveillance records.

That detail changes the nature of the story.

Claude was not merely helping an intelligence analyst summarize information.

It was reportedly being used to engineer the underlying software infrastructure that enabled large scale intelligence collection.

Anthropic described this as a broader trend: AI can increasingly substitute for parts of an engineering workforce, allowing a relatively small number of people to build systems that previously would have required larger teams of specialized developers.

That may be one of the most important implications of the report.

The AI Surveillance Problem Is Bigger Than One Model

The Mali case also exposes a limitation of platform level AI safety.

Anthropic said that banning the relevant Claude account disrupted the development work, but it did not necessarily eliminate the locally deployed system itself.

In other words:

Stopping access to an AI model is not the same as deleting everything that the model helped create.

Once software has been generated, modified, deployed and integrated into a local environment, the original AI provider may have little or no direct control over what happens next.

This creates a difficult security problem.

An AI company can monitor prompts.

It can block accounts.

It can improve safety classifiers.

But it cannot automatically reach into every computer, server or locally deployed system where AI assisted software eventually ends up.

That distinction is becoming increasingly important as AI coding systems become more capable.

Central African Republic: AI Generated Propaganda at Industrial Speed

Another case involved the Central African Republic.

Anthropic said it removed an account operated by a Russian speaking actor in Bangui who served as a production component of a Russian state aligned influence operation.

The operation used Radio Lengo Songo, along with Russian state media organizations including RT, Sputnik Afrique and TASS, according to Anthropic’s investigation.

Claude was instructed to generate stories containing pro Russia and pro government narratives while attacking France and the local opposition.

But there was another objective:

The content had to look human.

The operator specifically instructed Claude to remove characteristics that might make the material appear AI generated.

This is significant because the strategic value of generative AI in propaganda is not necessarily that it creates convincing arguments from nothing.

Its real value may be that it allows an existing political operation to produce far more material, far more quickly, and in a form designed to look locally authentic.

Anthropic classified the operation as Category Four on the Brookings Breakout Scale because the content was broadcast daily and amplified through Telegram and local media.

The company also said the operation produced thousands of articles in multiple languages, although much of the content generated little observable engagement from genuine audiences.

That last point is important.

A campaign can produce enormous quantities of content without actually persuading anyone.

The DRC: 70 Fake News Sites and 318 Articles

The Democratic Republic of Congo provides another example of how AI can industrialize a disinformation operation.

Anthropic identified a network of approximately 70 fabricated news websites and associated X accounts that appeared independent but were connected through shared infrastructure.

Claude was used to create new articles and rewrite legitimate reporting into politically slanted versions.

The network also used fabricated journalist identities.

Anthropic identified 318 articles specifically focused on the Democratic Republic of Congo, many dealing with the country’s position on mineral agreements and tensions with Rwanda. The company found signals suggesting that the activity may have reflected the interests of customers with stakes in the DRC Rwanda conflict, but said it could not independently establish who commissioned the content and found no evidence that a government directed the operation.

One detail illustrates the level of coordination.

On September 11, 2025, several websites published nearly identical stories about the DRC Rwanda conflict within approximately three minutes of each other.

That is not what a normal collection of independent news organizations looks like.

It is closer to a content distribution system.

The Real Advantage Was Not Intelligence—It Was Scale

There is a common assumption that generative AI makes propaganda more dangerous because machines are becoming better at persuasion.

That may be only part of the story.

In many of the cases Anthropic documented, humans already decided what the political message should be.

They selected the targets.

They determined the talking points.

They chose the hashtags.

They established the political objectives.

Claude then handled much of the repetitive work.

That distinction matters.

AI did not necessarily invent the propaganda strategy. It made the strategy cheaper and easier to execute at scale.

The same pattern appeared in Kenya.

Kenya: 50 Political Posts at a Time

Anthropic identified a Kenyan operation that used Claude to generate batches of exactly 50 political posts designed to look like spontaneous grassroots opinions.

The campaign promoted Energy Cabinet Secretary Opiyo Wandayi while also attacking political opponents and promoting narratives about divisions within Kenya’s opposition ahead of the 2027 general election.

Anthropic said it found no evidence of government involvement and assessed the activity as a domestic Kenyan operation.

The campaign was classified as Category One on the Breakout Scale because it remained largely confined to the network of fake accounts and did not demonstrate evidence of reaching or influencing real people.

Again, the AI’s role was revealing.

The operator supplied the political topics, messages and hashtags.

Claude transformed them into large batches of posts designed to appear organic.

The technology therefore functioned less like an autonomous political strategist and more like an industrial scale communications assistant.

That distinction is critical when assessing the actual threat.

Sudan: AI Enters the Information Battle

Anthropic also documented an operation connected to the conflict in Sudan.

The company said an actor linked with high confidence to officials in a Gulf state operated a network of roughly 300 fake influencer accounts and impersonated a genuine Sudanese human rights organization.

Claude was reportedly used to create intelligence style briefs, targeting materials and testimony intended for international institutions.

In one particularly sensitive case, the model was used to ghostwrite testimony attributed to two individuals so that material supporting one side of the conflict could appear to originate from independent Sudanese witnesses rather than from a state linked actor.

Anthropic said it could not confirm that the testimony or targeting materials actually reached their intended recipients.

That caveat matters.

There is a significant difference between producing deceptive material and successfully influencing its intended audience.

The report repeatedly demonstrates why those two things should not be treated as equivalent.

The Most Important Finding: AI Does Not Need to Be Autonomous

Much of the public discussion around advanced AI focuses on autonomous agents that independently make decisions.

Anthropic’s report points toward a different and arguably more immediate problem.

Humans do not need to surrender control to AI for AI to become strategically powerful.

They can simply use AI as a force multiplier.

One person can generate hundreds of political messages.

A small team can operate dozens of fake media properties.

A developer can use AI assistance to build complicated software.

An influence operator can automatically rewrite content for different audiences.

A propaganda organization can produce material in multiple languages.

The human remains in control of the objective.

The machine provides the scale.

This is a very different risk model from the classic “AI takes over” scenario.

And it may be much closer to the present reality.

The Human in the Loop Is Not Always a Safety Feature

AI safety discussions often assume that keeping a human involved reduces risk.

Sometimes it does.

But a human using AI to pursue a harmful objective can also be the problem.

If the human decides who should be monitored, who should be targeted or what political narrative should be promoted, an AI system can dramatically reduce the time and resources required to execute that plan.

The technology does not need to make independent political decisions.

It only needs to become sufficiently capable at following instructions.

This creates an uncomfortable paradox:

More human control does not automatically mean less harm.

It depends on what the human is trying to accomplish.

Why Banning Accounts Is Becoming Harder

Anthropic said it banned accounts associated with the operations described in its report and strengthened its detection systems.

That is an important defense.

But the Mali case demonstrates why account level enforcement has limits.

If an AI assisted system has already been deployed locally, banning the original account may only prevent further development through that particular service.

The same is true of influence operations.

An operator can potentially use multiple AI providers, open source models or locally deployed systems.

Anthropic itself noted that some threat actors attempted to circumvent its restrictions through proxy infrastructure and other providers.

That means AI safety is gradually becoming less like traditional platform moderation and more like cybersecurity.

The question is no longer simply:

“Can Anthropic stop this user?”

It is:

“Can the wider ecosystem detect and contain what this user is building?”

The AI Disinformation Problem Is Also an Authenticity Problem

There is another consequence that may prove even more difficult to solve.

Generative AI makes it increasingly cheap to manufacture content that looks authentic.

But the danger is not only that people believe false information.

The opposite can happen.

People may eventually stop trusting genuine information because they know convincing fakes are possible.

A real photograph can be dismissed as AI generated.

A genuine recording can be called fabricated.

A legitimate news report can be accused of being synthetic.

A real witness can be portrayed as a manufactured persona.

That creates what researchers often describe as the “liar’s dividend”: once convincing deception becomes common, people who are caught in genuine wrongdoing can exploit the existence of deepfakes to cast doubt on authentic evidence.

The result is not simply more misinformation.

It is a weaker information environment in which proving what actually happened becomes harder.

Africa Is Becoming an Important Test Case

The geographic concentration of several cases in Anthropic’s report deserves attention.

The operations documented in Mali, the Central African Republic, the Democratic Republic of Congo, Kenya and Sudan are not identical.

Some were state linked.

Some appeared commercially motivated.

Some were domestic political campaigns.

Some showed no proven connection to governments.

But they share one important characteristic:

AI lowered the operational cost of activities that previously required more people, time and technical expertise.

That matters particularly in environments where political institutions, media systems and digital infrastructure may already be under pressure.

The technology does not create those vulnerabilities.

It can, however, exploit them faster.

This Is Bigger Than Claude

It would be a mistake to interpret Anthropic’s report as evidence that Claude itself is uniquely dangerous.

The company is publishing cases involving misuse of its own models because it can observe activity on its platform.

Other AI providers face essentially the same structural problem.

OpenAI, Google, Meta and developers of open weight models all have to contend with the possibility that increasingly capable systems will be used by people whose objectives conflict with their safety policies.

And as more powerful open models become available, the ability of one company to control misuse becomes even more limited.

This is why the future of AI safety cannot depend entirely on the policies of individual companies.

The Next AI Safety Battle May Be About Infrastructure

The most revealing lesson from Anthropic’s report is that AI misuse is moving beyond the chatbot interface.

AI is becoming embedded in:

  • software development,
  • surveillance systems,
  • media production,
  • political communications,
  • intelligence analysis,
  • social media operations,
  • and automated workflows.

That means safety measures need to move in the same direction.

Blocking harmful prompts remains useful.

But it is not enough.

The industry increasingly needs better detection of coordinated behavior, stronger identity and abuse monitoring, safeguards around high risk deployments, collaboration between AI companies, and mechanisms for sharing threat intelligence without creating new privacy or censorship problems.

The Dangerous Part Is Not That AI Replaced Humans

It is tempting to describe these cases as examples of AI replacing human operators.

The evidence suggests something more nuanced.

In most of the documented campaigns, humans remained firmly in charge.

They chose the objectives.

They defined the narratives.

They selected the targets.

They used AI to accelerate execution.

That may actually be the more immediate concern.

AI does not have to become autonomous to become powerful.

It only has to make a determined human significantly more capable.

The Bottom Line

Anthropic’s September 2026 report provides a glimpse of an AI threat landscape that is very different from the futuristic scenarios dominating the AGI debate.

The cases in Africa show AI being used for surveillance, propaganda, political manipulation and information operations—not by machines acting independently, but by people using increasingly capable models as force multipliers.

Some of these campaigns barely reached real audiences.

Others were much more sophisticated.

And that distinction is essential.

The existence of thousands of AI generated posts does not prove that thousands of people were persuaded. A fake news network does not automatically become influential simply because it produces hundreds of articles.

But the underlying capability is changing.

A task that once required a large communications team can increasingly be attempted by a small group with an AI model.

A technical project that once required several developers can potentially be accelerated by AI coding assistance.

A surveillance operation can incorporate AI into parts of its engineering and analysis pipeline.

That is the real shift.

The immediate AI risk may not be machines taking control from humans. It may be humans gaining capabilities that previously required institutions, money and large teams—and using those capabilities for surveillance, manipulation or political power.

And unlike a hypothetical future superintelligence, that transformation is already being documented.

You May Also Like

Tech

On Monday, September 28, 2026, OpenAI confirmed that it would not release GPT-6.1 Astra, a next-generation prototype that was nearing launch. The company had...

Blog

NVIDIA's Southeast Asia strategy goes far beyond chip sales: 1GW AI factories, language models it doesn't charge for, a robot testbed, and a supply-chain...

Blog

OpenAI has spent nine months failing to hire a communications chief. The rejections, the crisis backlog, the Altman problem, and what it means before...

Blog

The old MBC 1 Nilesat frequency 11938 V no longer works. What replaced it on Nilesat 201, where MBC 1 actually broadcasts in 2026...