Russian Developers Used AI to Build Autonomous Drone Software, Anthropic Reports
Anthropic says a small Russia-based freelance team used Claude to develop software for an autonomous FPV drone swarm, highlighting the growing security risks of AI-assisted weapons development.
Xcademia Team
Xcademia Research Team

Russian Developers Used Claude to Develop Autonomous Drone Swarm Software
Anthropic has reported that a small group of Russia-based developers used its Claude AI system to develop software for an autonomous swarm of first-person-view (FPV) attack drones.
The disclosure appears in Anthropic's September 2026 Threat Intelligence Report, which examines how threat actors have used AI across cyber operations, surveillance, propaganda and conventional weapons development.
According to Anthropic, the group, which it assesses was made up of freelance developers rather than a Russian state entity, used Claude Code to write and test software for what the operators called "DronDoc" or "Serafim."
The project went beyond using AI as a simple coding assistant. Anthropic says Claude was used across several parts of the software development process, including coordination, onboard decision-making, guidance and other drone-control functions.
The company also says the system was designed for autonomous lethal engagement, including the ability to select targets and issue detonation commands without a human making the final decision.
What Anthropic Found
Anthropic identified the activity as part of its investigation into misuse of Claude for conventional weapons development.
The company says the developers used Claude Code to create and test their software and combined it with a software-in-the-loop simulation environment and rented computing resources.
The investigation found that the project involved real hardware-in-the-loop testing. According to Anthropic, the developers loaded low-level firmware onto development boards, provisioned small computers and connected their simulation environment through a mesh network.
Anthropic says the group also developed several software components intended to support the autonomous drone system.
These included swarm coordination and shared-memory functions, an onboard language model for managing operational behaviours, terminal guidance, a module intended to locate opposing drone operators, passive acoustic detection and low-level software for programmable chips.
For safety reasons, Anthropic did not provide a step-by-step technical procedure for building or deploying the weapon system, and this article does not reproduce such instructions.
The AI System Was Designed for Autonomous Decisions
One of the most significant aspects of the report is the degree of autonomy described by Anthropic.
The company says the onboard model could select targets, including a "person" target category, and issue detonation commands without a human remaining in the loop for the final decision.
The developers also trained a computer-vision classifier using Ukrainian combat footage. Anthropic says the system divided targets into "enemy" and "friendly" categories and repeatedly used a fixed location in Donetsk Oblast as a demonstration strike point.
This distinction is important because it illustrates how AI can potentially move from assisting human engineers to becoming part of an operational decision-making system.

The Group Circumvented Geographic Restrictions
Anthropic says the developers created their accounts between late 2025 and early 2026 and began the operation in mid-May 2026.
The company identified nine accounts associated with the group. Eight of those accounts were used only for ordinary freelance work rather than weapons-related software development.
Anthropic says the group bypassed its geographic access controls by routing traffic through commercial virtual private servers.
The company assessed that the developers were a small, specialised freelance team involved in both civilian and military-related work. Anthropic did not conclude that they were a Russian state entity.
The group reportedly claimed to have received funding from Russia's Advanced Research Foundation, National Technology Initiative and Ministry of Defence. However, Anthropic explicitly says it could not verify those claims.
That distinction is important. The report identifies the developers as Russia-based and describes their activities, but it does not establish that the Russian government directly operated the Claude accounts involved in the drone software project.
The Project Was Not Reported as a Fully Operational Weapon
Anthropic categorised the drone-related systems at Technology Readiness Levels 3 to 4.
The report says the systems were validated in simulation or reached similar early-stage development levels. Anthropic identified several systems and concepts in the recovered material, including an FPV kamikaze drone, an interceptor UAV, a standoff strike UAV and an autonomous heterogeneous swarm.
The report does not establish that the complete autonomous drone swarm became an operational battlefield system.
This is an important limitation when interpreting the findings.
The evidence demonstrates that AI was used during development and testing, including work involving real hardware, but the report does not establish successful battlefield deployment of the complete system.

Anthropic Reports a Wider Pattern of AI-Assisted Weapons Development
The drone case was not an isolated finding in Anthropic's report.
The company says that over the previous year its threat intelligence teams investigated and disrupted multiple operations in which Claude was used for conventional weapons development or for intelligence and procurement activities connected to weapons programs.
Anthropic describes six cases in total across China, Russia and Yemen.
These cases included attempts to use Claude for software supporting guided rockets, anti-torpedo systems, autonomous drones and electronic-warfare or air-defence targeting systems.
Anthropic says the actors often already had relevant expertise and access to hardware. In other words, the AI systems were not necessarily replacing the complete engineering capability required to create these systems.
Instead, the report indicates that AI was being incorporated into existing workflows to help produce, refine, analyse or test technical work.
Anthropic has therefore framed the issue as one of AI capability being integrated into real-world technical operations rather than AI independently inventing complete weapons systems from scratch.
AI Is Also Being Used Across Cyberattack Operations
The same Anthropic report highlights another major development: AI-assisted cyber operations are becoming increasingly automated.
In one case, Anthropic identified a Russia-linked operation that it says targeted Ukrainian and European governments, military intelligence organisations, diplomatic organisations and individuals connected to US foreign policy.
Anthropic refers to this activity as GTG-20006 and says its attribution is consistent with public reporting linking the actor to Midnight Blizzard.
The company observed AI-assisted workflows across multiple stages of the operation, including reconnaissance, phishing infrastructure, persistence, command and control and data exfiltration.
Anthropic says the actor also used AI to monitor whether malware was being detected by security products and then modify and rebuild detected components.
The report says more than 20 organisations were identified in the actor's operational planning, reconnaissance and live operations.
Ukraine and military drone technology providers were among the recurring areas of interest.
The actor reportedly targeted Ukrainian government, military and diplomatic personnel and also sought information connected to drone manufacturers and suppliers.
Anthropic says the group obtained proprietary material related to a drone vision system and investigated its architecture, hardware components and supplier dependencies.
AI Is Moving From Assistance Toward Orchestration
Anthropic describes this wider trend as a movement from AI acting as an assistant toward AI acting as an orchestrator.
In traditional software development, an engineer might use an AI system to explain code, generate a function or troubleshoot an error.
In the operations described by Anthropic, AI was used across connected stages of a larger workflow.
The report says a majority of the cyber operations it describes involved AI through direct execution or orchestration rather than simple question-and-answer interactions.
Humans still remained involved, particularly in setting targets and reviewing results, but more of the intermediate work could be delegated to AI-driven workflows.
This creates a different security challenge because defenders may no longer be dealing with a single automated tool. They may be dealing with systems capable of chaining multiple tasks together.

Why This Matters for Cybersecurity
The Anthropic findings point to a broader challenge for defenders.
Security teams have traditionally relied heavily on detection systems, signatures, behavioural monitoring and human investigation. When attackers modify their tools, defenders can update detections and begin another cycle of defence.
Anthropic argues that AI can potentially shorten this cycle by helping attackers repeatedly adapt their tools.
In the GTG-20006 case, the company observed AI-assisted processes that could identify detected malware and modify it to avoid existing security controls.
For defenders, this means monitoring only known malware signatures may become less effective against adversaries capable of rapidly changing their tooling.
The broader lesson is that security teams may need to pay more attention to behaviour, identity, infrastructure, access patterns and attack workflows rather than relying exclusively on static indicators.
Anthropic Says It Has Strengthened Its Safeguards
Anthropic says it banned accounts associated with the identified weapons-development operations.
The company also says it incorporated findings from its investigations into its safeguards and launched additional classifiers designed to detect and block activity associated with high-yield explosives and weapons development.
For the Russia-based drone operation specifically, Anthropic says it banned the accounts connected to the group and used the investigation to improve safeguards against future misuse.
The company also says that when actors worked across other platforms, it shared relevant findings with industry counterparts where appropriate.
What the Report Does Not Prove
The findings should not be interpreted as evidence that AI systems independently developed and deployed an autonomous weapon.
Anthropic's report describes human actors directing the work, using AI within a broader engineering process.
It also does not establish that the Russian state directly operated the drone-development accounts.
Most importantly, Anthropic's assessment of the drone systems indicates development and simulation maturity rather than confirmed operational deployment.
These distinctions matter because the security implications are serious without requiring claims beyond the evidence.
The Bigger AI Security Question
The report highlights a broader industry shift toward AI being embedded deeper into complex technical workflows.
The same capabilities that help legitimate developers write software, analyse information and automate repetitive tasks can potentially be misused by actors working on cyber operations, surveillance or weapons-related projects.
For cybersecurity professionals, the challenge is therefore not simply identifying malicious AI-generated content.
It is understanding how AI is being connected to tools, data, infrastructure and automated decision-making.
As AI systems become more capable of carrying out multi-step tasks, the security boundary increasingly extends beyond the model itself to the entire workflow surrounding it.
For enterprises, this could mean stronger controls around AI access, monitoring of automated agents, identity verification, tool permissions and audit trails.
The development also reflects growing demand for safeguards that consider not only what an AI model can answer, but how its capabilities can be connected to external systems and real-world operations.
Source: Anthropic
About the Author