Anthropic says likely freelance developers based in Russia used Claude Code to build software for an autonomous kamikaze drone swarm designed to select targets and issue detonation commands without a human in the loop.
The project, called “DronDoc” or “Serafim,” went considerably beyond using artificial intelligence to assist with conventional software development.
According to Anthropic’s September threat-intelligence report, the developers used Claude to build core components including shared swarm memory, fault-tolerant coordination logic and an onboard AI model governing attack, observation and return-to-base behaviour.
They also developed terminal-guidance software capable of steering drones using onboard cameras and issuing a command to detonate, along with technology intended to geolocate opposing drone operators.
The most consequential element concerns who makes the final targeting decision.
Anthropic says the platform was designed for autonomous lethal engagement.
The onboard model could select targets, including a “person” target class, and issue detonation commands without a human in the loop.
The developers also trained a computer-vision classifier using Ukrainian combat footage and divided potential targets into “enemy” and “friendly” categories while allow-listing Russian systems.
Anthropic says a fixed coordinate in Donetsk Oblast was repeatedly used as a demonstration strike point.
There are important limits to what the evidence establishes.
Anthropic does not say the Russian government operated the accounts.
It assesses the developers were a small specialised freelance team conducting a mixture of civilian and military work rather than a Russian state entity.
The developers claimed funding links to Russian state organisations, including the Ministry of Defence, but Anthropic says it could not verify those claims.
Nor does Anthropic say the autonomous swarm was successfully deployed in combat.
The systems were assessed at approximately Technology Readiness Level 3–4, with the FPV kamikaze drone and autonomous swarm validated primarily through simulation.
However, the activity extended beyond purely conceptual work. Anthropic observed firmware being flashed onto real development boards and hardware-in-the-loop testing.
Anthropic says it banned the accounts involved and incorporated findings from the investigation into safeguards intended to prevent similar misuse.
The larger significance is the direction in which military artificial intelligence is moving.
AI has already become capable of helping humans design weapons, analyse battlefield information and develop military software.
An autonomous system capable of identifying a human as a target and issuing its own detonation command crosses a different conceptual boundary.
The question is no longer simply whether artificial intelligence assists a person making a lethal decision.
It is whether software itself can increasingly become the entity making that decision.
Once the final decision over who or what to attack moves from a human being to software, the argument over meaningful human control stops being theoretical.
More to follow.
Source: Anthropic, September 2026 Threat Intelligence Report
Join the Dissenting Citizen Newsletter
Independent news and commentary delivered directly to your inbox.