Thursday, September 24th, 2026

China’s AI surveillance machine: Beijing-linked actors turn Claude against dissidents, religious groups



Artificial intelligence (AI) is increasingly becoming part of the machinery of intelligence gathering, but a new investigation by US technology company Anthropic shows how quickly that shift can move from theory to operational reality.

According to Anthropic’s September 10 threat intelligence report, China-based actors linked to the country’s security apparatus used its Claude AI assistant to monitor religious communities, dissidents and overseas Chinese groups.

The targets included Falun Gong practitioners, Tibetan organisations, senior Catholic figures in Asia and the Presbyterian Church in Taiwan, as well as NTD, a media organisation affiliated with The Epoch Times.

What makes the findings particularly significant is not simply the identity of those being monitored, but the scale and speed at which information was processed.

Anthropic said one operator used Claude as a substitute for a much larger team of human analysts, generating thousands of intelligence products in a month.

The company said it banned the accounts involved and strengthened its safeguards after identifying the activity. It also cautioned that the cases demonstrate how advanced AI can be repurposed to industrialise surveillance and intelligence work.

One operator, thousands of intelligence reports

Anthropic identified what it described as a China-based, Chinese government-aligned intelligence operation targeting religious leaders and Chinese diaspora figures.

In one operation, an individual ran what Anthropic characterised as a “religious affairs intelligence collection desk”.

The operator divided the work into four simultaneous streams, directing Claude to collect and translate material from different languages before turning it into Chinese-language dossiers, intelligence reports and daily situational digests.

Anthropic said the system produced 2,475 finished dossiers and reports in 30 days.

The significance lies in the transformation of the workflow. Intelligence collection traditionally requires researchers to locate information, translate it, organise it, assess it and prepare reports for decision-makers.

In this case, Claude was directed to perform much of that process through an automated and repeatable system.

Anthropic said the operators collected information from Chinese platforms including WeChat, Xiaohongshu, Douyin and Weibo, while also drawing from LinkedIn, Instagram, Threads, X and Facebook.

The information reportedly included birth dates, birthplaces, immigration dates and social-media accounts. The operation also conducted reconnaissance of religious venues, including the collection of floor plans, facade photographs and structural diagrams.

Falun Gong remains a major target

Among the groups identified in the operation was Falun Gong, a spiritual practice that Beijing banned in 1999 and has subjected to a prolonged campaign of repression.

Human Rights Watch documented the crackdown beginning in July 1999, while US government religious-freedom reports have continued to document arrests, detention and harassment of Falun Gong practitioners in subsequent years.

Human Rights Watch’s 2026 China report says the government continues to classify Falun Gong as an “evil cult” and reports ongoing harassment, arbitrary imprisonment and torture of practitioners.

The Anthropic investigation suggests that the monitoring now extends into the digital and overseas environment.

The company said its identified actors compiled information on Falun Gong practitioners and associated organisations in the diaspora. The targeting also included Shen Yun Performing Arts and NTD, organisations associated with the wider Falun Gong diaspora.

Anthropic said the operators instructed Claude to use terminology reflecting the Chinese government’s perspective, including descriptions of Falun Gong as an “evil cult”. They also directed the model to adopt what they called “China’s standpoint”.

That is important because the AI was not merely being used as a neutral search engine.

According to Anthropic, operators were attempting to make the system reproduce the language and analytical framework of the security apparatus itself.

Religious intelligence becomes automated

The targets extended well beyond Falun Gong.

Anthropic said senior Catholic cardinals across Asia were individually profiled, while leaders of the Presbyterian Church in Taiwan became subjects of multiple dossiers and venue reconnaissance.

Tibetan Buddhist organisations and the Central Tibetan Administration were also targeted.

The operation additionally examined Christian missionary networks connecting Singapore, Hong Kong and mainland China.

The report said the requested intelligence included a target’s China-related activities, alleged scandals and potential “grab handles” — a term Anthropic linked to the United Front Work Department’s vocabulary for exploitable leverage.

This marks a shift from simply observing public activity to organising information around potential pressure points.

The reported collection also crossed national boundaries. A target could be living in North America or Europe, using Western social-media platforms and participating in a religious or political organisation outside China, while still becoming part of an intelligence file generated in Chinese.

Dissidents enter the same system

Anthropic separately identified three accounts linked to Chinese municipal public security and state security organisations that used Claude to monitor overseas dissidents and human rights groups.

The activities reportedly included tracking pro-democracy figures, rights defenders, ethnic minority organisations and overseas civil-society groups.

In one case, a state security bureau sought what Anthropic called “pre-operational venue intelligence” on overseas events.

The requested information included the location, route and endpoint of a pro-democracy march in Vancouver, venues for Uyghur cultural events in Turkey and screenings connected to the Oslo Freedom Forum.

Anthropic said the operation also involved daily intelligence briefings concerning overseas dissidents and civil-society organisations.

The company assessed with different levels of confidence that some actors were directly associated with Chinese state organs while others were contractors working for government-linked clients.

That distinction is important because the evidence does not establish that every activity described in the report was carried out directly by a Chinese government agency.

AI compresses the intelligence cycle

The most striking feature of the investigation is the compression of time and manpower.

Anthropic said the religious affairs operation effectively reduced work that would previously have required teams of analysts to a workflow controlled by a single operator using an AI assistant.

The model could translate material, extract personal details, classify information, produce standardised reports and maintain recurring reporting cycles. That allowed information gathered from multiple countries and platforms to be converted into a common intelligence format.

Anthropic’s broader investigation found similar patterns in other Chinese operations.

One China-based actor used Claude to process large quantities of social-media material and identify people potentially vulnerable to pressure because of factors including financial difficulties, family separation or ideological disillusionment.

Another operation involved monitoring overseas Uyghur targets and using Claude to draft and translate messages during an attempted recruitment campaign.

The technology did not necessarily create a new surveillance objective. Instead, it appears to have made existing intelligence priorities faster, cheaper and more scalable.

Beijing’s wider surveillance architecture

The Anthropic findings come against a broader background of extensive digital monitoring inside and outside China.

The US State Department’s religious-freedom reporting has previously documented what it described as high-technology surveillance of religious sites and reports of Chinese authorities conducting physical and digital surveillance of Falun Gong practitioners, Uyghurs, Tibetan Buddhists and other groups overseas.

Human Rights Watch’s 2026 assessment also reports continued restrictions on religious activity and online religious content in China, including restrictions affecting religious professionals and communities outside the official state-controlled framework.

The Anthropic case adds an artificial-intelligence layer to that established environment.

Instead of surveillance being limited to collecting information, AI can organise enormous volumes of information into profiles that are easier for officials or intelligence personnel to use.

That difference matters. The value of an AI system in such an environment is not necessarily its ability to discover information that nobody knew existed. Its value can lie in connecting thousands of fragments that were previously scattered across languages, websites, databases and social networks.

Anthropic’s findings arrive amid wider AI misuse

The investigation is part of a broader series of cases Anthropic has disclosed in September 2026 involving the misuse of Claude.

The company said its threat-intelligence team had identified and disrupted operations involving cyber activity, surveillance, influence operations, weapons-related research, biological misuse and fraud.

It also said malicious actors were increasingly using AI not simply to answer questions but to perform sustained, multi-stage tasks.

Reuters reported on September 11 that Anthropic had identified several serious cases in which Claude was misused for surveillance and other high-risk activities, including monitoring minority groups and political figures.

The findings arrive as governments and technology companies are confronting a rapidly changing AI security environment.

Reuters reported on September 14 that China itself is developing a regulatory framework for AI-agent safety, including security assessments and testing, while continuing to push rapid deployment of AI technologies.

The contradiction is increasingly visible: AI is being treated simultaneously as a strategic technology to accelerate and as a capability that can create new security risks.

The old targets, with a new instrument

The Anthropic investigation does not establish that AI created China’s surveillance priorities.

The targets identified in the report — Falun Gong practitioners, Tibetan organisations, dissidents, human-rights groups and overseas Chinese communities — have appeared in documentation about Chinese security and political controls for years.

What has changed is the instrument.

A system capable of processing thousands of documents, translating information across languages, identifying patterns and producing standardised intelligence reports can substantially alter the scale at which surveillance can operate.

For communities already accustomed to monitoring, pressure and restrictions, the emergence of AI-assisted intelligence collection adds another layer to an established security environment.

Anthropic’s report ultimately points to a broader development in the technology itself: AI is no longer being used only to retrieve or summarise information.

In the cases the company identified, it was being integrated into workflows designed to identify people, map organisations, assess vulnerabilities and prepare intelligence for operational use.

Publish Date : 24 September 2026 16:01 PM

House of Representatives approves proposal to consider Free Legal Aid Bill

KATHMANDU: The House of Representatives on Thursday unanimously approved a

Securities Board releases concept paper on implementing intraday trading

KATHMANDU: The Securities Board of Nepal (SEBON) has made public

UML Central Committee meeting concludes, Bidhya Devi Bhandari named senior leader

LALITPUR: The third Central Committee meeting of the CPN-UML has

Supreme Court orders immediate release of Bharat Dahal

KATHMANDU: The Supreme Court has ordered the immediate release of

UML nominates 29 Central Committee members, Yogesh Bhattarai records dissent

KATHMANDU: The CPN-UML has nominated 29 new members to its