Anthropic exposes UAE-linked AI campaign targeting the Muslim Brotherhood
Anthropic has uncovered the use of its AI model, Claude, in covert political influence operations and digital surveillance, including an orchestrated campaign that the firm attributed with “high confidence” to United Arab Emirates government officials.
In a report released last Thursday titled “Detecting and countering misuse of AI: September 2026,” the San Francisco-based firm disclosed that a single operator directed the main operation.
The operative weaponized Claude to synthesize political and human rights materials, build intelligence dossiers on targeted public figures, and orchestrate a clandestine network of approximately 300 synthetic social media accounts across multiple commercial platforms, according to the report.
The campaign operated against the backdrop of intensifying international condemnation over Abu Dhabi’s involvement in the devastating war in Sudan, particularly its documented backing of the paramilitary Rapid Support Forces (RSF).
On April 27, a panel of UN experts formally demanded explanations from the UAE regarding allegations of illicit weapons transfers and the recruitment of foreign mercenaries to reinforce the RSF.
That inquiry specifically highlighted the Abu Dhabi-based private security contractor Global Security Services Group (GSSG), presenting the findings as grave allegations requiring formal rebuttal while noting that investigators had not made a premature determination on their validity.
In a diplomatic response circulated in July, the UAE denied supplying lethal military equipment to either warring party since the outbreak of hostilities. Abu Dhabi insisted that equipment cited by international monitors fell under a 2020 bilateral defense pact with the Sudanese government, while categorically denying any operational nexus between GSSG and mercenary networks.
Anthropic's findings show that the covert digital campaign directly mirrored these state interests. On 4 June, coordinated accounts on X launched a campaign under the hashtag “#SudanIslamists,” disseminating closely aligned graphics and uniform talking points designed to deflect scrutiny from the RSF by framing the Sudanese Muslim Brotherhood as the sole engine of regional destabilization.
Global mandates and ghost-writing
According to Anthropic, the operator engineered materials calibrated to obscure their state-aligned origins. The individual established a persistent configuration file across hundreds of conversational prompts, locking the AI model into a dedicated mission described internally as a “coordinated transatlantic and regional campaign to dismantle the Muslim Brotherhood globally.”
The operative systematically fed Claude designated subjects, specific targets, and predetermined political stances, directing the model to output texts styled as intelligence briefs, investigative dossiers, and third-party testimonies.
The operator also funded and maintained the network of roughly 300 automated social media accounts, configuring them to emulate disparate, unconnected private individuals to mask the coordinated nature of the information warfare.
Beyond social media amplification, the operative subverted established human rights channels. Anthropic revealed that the campaign fabricated a digital front masquerading as an existing, legitimate human rights organization to publish campaign-generated reports under stolen branding.
Anthropic's report leaves the target entity ambiguous, initially describing an organization of Swiss provenance before subsequently referencing a Sudanese human rights body without clarifying whether the descriptions denote one organization or two.
The operative further directed Claude to draft two formal testimonies submitted under the names of external proxies for delivery before the 62nd session of the United Nations Human Rights Council (held 15 June to 8 July 2026). Prompts specifically instructed the AI to excise any mention of the UAE, fabricating the appearance of independent, grassroots testimony.
Anthropic confirmed that a statement drafted by the model on behalf of third parties was delivered in person during a live session of the Human Rights Council.
However, the tech firm withheld both the verbatim speeches and the names of the individuals involved, leaving researchers unable to cross-reference official UN records.
The operation's surveillance wing systematically tracked figures scrutinizing Gulf foreign policy. Anthropic revealed that the network compiled dossiers on 18 Members of the European Parliament, prominent investigative journalists, and United Nations Special Rapporteurs who had publicly criticized the UAE’s conduct in Sudan.
The report noted that the operator prepared several of these surveillance dossiers for direct dispatch to high-ranking Emirati officials. Anthropic declined to name the targeted rapporteurs, leaving unresolved whether the monitored officials included the UN experts who signed the 27 April inquiry into UAE arms transfers.
While Anthropic asserted “high confidence” in linking the operation to UAE officials based on configuration files designating them as recipients, the company acknowledged critical evidentiary gaps. Anthropic withheld the identities of the named officials and left unclear whether these references constituted technical proof of attribution.
Crucially, the findings establish neither that Emirati authorities commissioned or had prior knowledge of the enterprise, nor that they ever received the completed dossiers or deployed state apparatuses against the targeted European lawmakers and UN rapporteurs.
AFP reported that it solicited formal comment from Emirati authorities regarding Anthropic’s allegations, but received no immediate response.
Mercenary intelligence
Anthropic’s investigation documented a second, distinct operation focused on bulk digital surveillance across Iran and the Persian Gulf region, carried out by or on behalf of “S2T Unlocking Cyberspace.” Open-source intelligence records identify S2T as a commercial intelligence and digital espionage entity operating across Israeli and Singaporean jurisdictions.
The venture deployed Claude to process raw user activity from social platforms, triangulating physical locations, demographic profiles, and political allegiances before converting the data into concise Arabic-language intelligence digests.
S2T’s algorithmic scoring categorized users as pro-government or anti-regime regarding the Iranian state, appending confidence scores to assessments of their identity and ideological disposition.
Anthropic uncovered more than 255 synthetic accounts linked to the S2T apparatus. Notably, the operators disguised several profiles as foreign migrant workers living in the UAE, assigning usernames crafted to emulate Pakistani and Bangladeshi laborers based in Dubai, Sharjah, and Ajman.
Anthropic emphasized that the presence of these migrant-worker sock-puppets provides no evidence of operational links to the UAE government, nor did the firm find evidence that the system was deployed against real civilian targets before Anthropic terminated the account in June while the software remained in its testing phase.
The limits of self-regulation
Anthropic classified the primary influence operation as “Tier 3” on its internal impact scale, a rating assigned because the network spanned multiple social media platforms, but fell short of the verified real-world disruption required for higher severity status. The company subsequently revoked access for the implicated accounts, deployed internal behavioral detection rules, and shared threat indicators with peer tech firms.
However, internal enforcement actions by Western AI developers highlight the structural shortcomings of corporate self-regulation. An API ban by Anthropic does not dismantle the synthetic accounts actively operating across third-party networks like X, nor does the vendor retain visibility into how state-linked actors distribute, repurpose, or weaponize synthetic texts once exported.
Both cases expose how advanced generative models are being integrated into state-aligned influence operations and privatized corporate espionage—spanning automated persona networks, international forum infiltration, and mass surveillance—while proprietary opacity keeps the full scope of digital interference hidden from public oversight.