The Curious Case of the Houthis and AI-Enabled Conflict

Loading the Elevenlabs Text to Speech AudioNative Player...

The following piece originally appeared as “Clicks and Kalashnikovs: The Houthis, AI, and a New Security Debate” on ORF Middle East’s Expert Speaks on September 25, 2026.

By: Kabir Taneja and Siddharth Yadav

A report last month by the artificial intelligence (AI) company Anthropic revealed that the Houthis, a Shi’a paramilitary organization in Yemen also known as Ansarullah, used the Claude AI model to develop advanced weapon systems. These included a guided rocket, a ballistic missile with a range of over 2,000 kilometers, and a multi-variant missile that included a hypersonic glide vehicle variant. Anthropic maintains a list of countries where its services are available and Yemen is not on it. There have been other instances of such circumvention taking place through synthetic accounts, using intermediaries in approved regions and network routing.

Once the group gained access, they managed to avoid detection by not stating their goals in the prompts outright and dividing their work into separate Claude sessions — one for research, one for writing the code, and one for reviewing it. They managed to build an “offline simulation toolkit” that can be used without Claude. The group’s activities were eventually identified and their accounts terminated. Anthropic had no evidence that the Houthi inquiries led to the creation of any field operational weapon, but it stated that the group managed to test fire a rocket. These revelations add another dimension to the debate on AI safety and security by demonstrating that apart from creating new threats, AI is also reshaping old ones.

AI model capabilities have been growing at breakneck speed since 2023, and the case studies outlined in Anthropic’s report vividly illustrate how AI companies are now operating in a live intelligence and counterintelligence environment. Relying on AI models to identify and refuse to act on dangerous prompts — a measure that largely worked in the Houthis’ case — is not sufficient protection. AI labs now have to work against elaborate campaigns by resourceful and persistent groups that are actively bypassing safeguards.

This case highlights that adversarial AI campaigns have become an industry-wide issue. Groups can easily migrate to other AI platforms. The group did not need to rely on one or two critical answers from Anthropic’s frontier-class models; smaller, benign-looking prompts to sub-frontier models worked as well. Even if access to proprietary American AI models is denied, threat actors can access increasingly capable open-weight AI models that are now widely available. If weapons development happens with the aid of open-weight fine-tuned models on private servers and infrastructure, the visibility into such projects would be negligible.

The use of technology by bad actors, criminals, and terrorists is not new. This intersection has gained attention over the past decade due to the rapid rise in popularity of digital technologies, from messaging apps and streaming to 3D printing and drones. However, conceptually, technology has always been attractive to bad actors as a means of inflicting damage. Moreover, damage without publicity is counterproductive for such entities.

The Islamic State’s (ISIS or Daesh in Arabic) rise in the early 2010s was one of the most significant events in the post-9/11 era of extremism. The group not only took over vast swathes of territory at a rapid pace, but also utilized online platforms such as Facebook, Twitter (now X), Telegram and others to recruit members and distribute well-curated and produced propaganda to a global audience. Platform owners were often taken by surprise, as they did not have the expertise or the capacity to understand or address such use. Smaller outlets, especially those only in the business of encrypted messaging, such as Kik and SureSpot, had bigger crisis points, including a lack of human capital to deploy on security issues. This led to a challenge of how to control the use of online spaces. In response, tech companies, research groups, and civil society organizations collaborated to find solutions. Yet problems persisted. Arbitrary de-platforming of accounts came with a separate set of challenges. Allowing law enforcement greater oversight was seen as a problematic bridging of space between the state and business, one that often expanded into transnational diplomatic issues.

The gap between technology and policy was never plugged during the height of the social media security debate. The debate around guardrails for AI is of a similar nature, but multiplied by a factor of thousands. Ensuring the safe proliferation of AI, a technology that keeps evolving in a matter of weeks and months, requires the swift emergence of a global consensus on interoperable security protocols, transparency standards, institutional readiness, and willingness to share intelligence among cybersecurity entities across jurisdictions in real time. That is unlikely to happen soon.

However, AI companies can be persuaded to cooperate with each other to implement not just company-wide but ecosystem-wide guardrails. The creation of threat intelligence units in all major AI labs and mandating industry-wide sharing of threat assessments and intelligence amongst such units may be a viable step forward. Drawing upon the multitude of examples of what did nor did not work in the social media era can help address emerging risks.

Kabir Taneja is Executive Director at ORF Middle East and Siddharth Yadav is a Fellow for Technology at ORF Middle East.