A small team of Russia-based freelance developers used Anthropic's Claude AI to build software for an autonomous combat drone swarm capable of selecting targets and detonating without human oversight, according to a September 2026 threat report from the company. The system, called DronDoc or Serafim, involved swarm coordination, computer vision, terminal guidance and target selection including people. The developers trained their computer vision system on Ukrainian combat footage and used locations in Ukraine for simulated missions.
How the Drone Swarm Was Built
The freelance developers used Claude Code to write the entire software stack for the autonomous drone swarm. Claude helped create swarm coordination, computer vision, terminal guidance and other software that enabled drones to select targets and issue detonation commands without a human in the loop. The developers then loaded the software onto real development boards for hardware-in-the-loop testing. It remains unclear whether they field tested the system.
Anthropic identified the activity as suspected weapons development and banned the accounts associated with the group. The company incorporated what it learned into additional safeguards. However, the safeguards did not stop the project immediately, and based on the disclosure, Claude Code clearly helped advance the autonomous drone swarm program. Anthropic gathered enough information to assess that the group was not a Russian state entity but did not publicly name the organization.
Beyond Drones: Espionage and Influence
In addition to the drone swarm project, Anthropic discovered a Russian state-linked cyberespionage operation that used Claude to automate infrastructure setup, phishing, malware development and data exfiltration. The campaign targeted more than 20 organizations, including Ukrainian and European government, military, intelligence and defense entities.
Russia-linked actors also used Claude for propaganda operations. A Russian state-directed campaign in the Central African Republic produced pro-Russian and pro-Wagner content for radio, local media and Telegram. The report shows AI is now doing work that previously required teams of software engineers, intelligence analysts and security specialists. While Anthropic's safeguards block many malicious requests, the company admits they cannot block all of them.
Older models such as Claude Opus 4 and Sonnet 4.5 were demonstrably below the threshold for meaningfully assisting sophisticated biological research. Anthropic, however, can no longer make the same assurance about today's models. Furthermore, the company deliberately withholds details about the five biological misuse case studies, so the report does not attribute them to specific countries or organizations.
Why This Matters
The report marks a shift in how AI contributes to weapons development. The barrier for creating sophisticated military software has dropped sharply. Small teams with limited resources can now build autonomous systems that previously required large national labs or defense contractors. This trend poses direct risks to battlefield dynamics and civilian safety. Governments and international bodies face increasing pressure to regulate the use of AI in weapons systems. The inability to block all malicious uses of frontier models means that companies like Anthropic must continuously adapt their safeguards while transparency around misuse remains limited.
The incident also raises questions about enforcement of geographic restrictions and the effectiveness of current safeguards. French-based freelancers circumvented blocks using commercial VPNs, highlighting the ease of bypassing measures.



