Search

Beijing’s AI Spy Desk: Inside Anthropic’s Exposure of China’s Automated War on Dissidents

On September 10, 2026, the San Francisco-based AI company Anthropic published a 154-page threat intelligence report that reads less like a cybersecurity document and more like a whistleblower's file from inside China's security apparatus. It details how China-based, state-aligned actors turned Claude one of the world's most advanced AI chatbots into an industrial-scale machine for surveillant dissidents, defaming critics and manufacturing propaganda. The targets were not abstract, they included Hong Kong democracy activists, Tibetan and Falun Gong communities, Uyghurs in exile, journalists and even the leadership of Taiwan's Presbyterian Church. As Bitter Winter reported, some of those named are the outlet's own writers.

What the Report Revealed

The report, “Detecting and Countering Misuse of AI, September 2026,” covers operations Anthropic disrupted between December 2025 and August 2026 across seven categories of harm, including cyber operations, influence operations, surveillance and illicit model distillation. The China-related cases fall into two streams: systematic surveillance of communities Beijing considers threats and mass-produced slander designed to destroy their reputations.

Slander at Industrial Scale

he influence operations described in the report are startling in their scale and boldness. One China-linked network used Claude to rewrite fabricated news stories and distribute them across roughly 70 fake news websites, amplified by 70 matching X accounts and more than 250 inauthentic commenting accounts. The same operators produced fabricated intelligence dossiers containing entirely invented allegations against an opposition politician and civil-society organizations. Another China-based campaign generated at least 1,500 headlines, 300 fabricated stories and 1,500 image prompts.

The pattern is clear: AI has become the production engine for state-aligned disinformation, replacing teams of writers with a single prompt.

The Surveillance Machine

The surveillance cases are even more chilling in their bureaucratic efficiency. Chinese actors linked to state security organs used Claude to support “stability maintenance programs,” tracking overseas dissidents and compiling details such as the route of a pro-democracy march in Vancouver and venues of Uyghur cultural events in Turkey. One state security bureau even had Claude draft an internal operations manual for its personnel.

Operation GTG-14022 went further, running Claude as an automated “public opinion monitoring” system that processed 15 to 30 foreign news articles daily from platforms including Weibo, X, YouTube, Telegram and Facebook, producing restricted briefings that catalogued dissidents, ethnic minorities, diaspora communities and foreign media as “threats to political stability.” The model was instructed to role-play as a “senior emergency public opinion analyst serving the government of the PRC.”

Perhaps most alarming was the religious-affairs desk. A single operator generated 2,475 finished dossiers in 30 days, covering senior Catholic cardinals, Tibetan Buddhist leaders, Falun Gong practitioners and Taiwan’s Presbyterian leadership, complete with personal histories, exploitable “points of leverage” and floor plans of religious venues. One surveillance program even scored social media users by political sensitivity and flagged individuals for “control.”

The Targets Speak

The human cost is now surfacing. “Teacher Li Is Not Your Teacher,” the influential dissident news account, confirmed on September 12 that he was among the named targets. For Taiwan, the report lands with particular force: Beijing’s AI surveillance desk, in effect, kept files on the island’s civil society.

Beijing’s Response

Beijing has dismissed the findings. Foreign Ministry spokesperson Mao Ning said she was “not familiar with the specifics,” insisted China advocates “AI for good,” and accused Anthropic of “distorting facts” and smearing China, a denial repeated across the surveillance and distillation allegations. The row now sits squarely within the wider US–China AI rivalry, with Washington, OpenAI, Google and Anthropic all levelling claims Beijing rejects.

The Irony and the Limits

There is bitter irony here. Beijing bans Claude for Chinese users, yet its security organs ran intelligence desks on it. Worse, the report accuses Chinese firms, including Alibaba, which allegedly routed 151 million exchanges through Claude in the largest illicit “distillation” operation ever measured, Moonshot and DeepSeek, of secretly using Claude’s outputs to build their own models. DeepSeek reportedly even forwarded its own users’ sensitive queries to Claude, exposing them in the process.

The report also exposes the limits of AI safety. One actor simply re-asked after a refusal and obtained guidance naming ten private citizens for suppression. Detection came only after substantial output, and nothing stops these actors from moving to open-weight models no company monitors. That gap, between the watchdogs we have and the ones we don’t, is where the next story begins.

 

Prev Article
Tibetan Democracy Day: A Symbol of Hope Against Decades of Repression

Related to this topic: