Anthropic findings show China-based threat actors instructing Claude AI to adopt the Chinese state’s political narrative on Tibet

A new Anthropic threat intelligence report titled ‘Detecting and countering misuse of AI: September 2026’ provides disturbing evidence of China-based, government-aligned actors targeting the Tibetan exile government or the Central Tibetan Administration (CTA), members of the Tibetan Buddhist civil society and advocacy organizations, including the International Campaign for Tibet (ICT) and Students for a Free Tibet (SFT).

The findings — which were based on malicious activity identified on Anthropic’s Claude using Claude Haiku, Sonnet, and Opus models between December 2025 and August 2026 — provide independent evidence of the artificial intelligence (AI)-enabled surveillance of Tibetans, Uyghurs, Taiwanese and other religious groups by threat actors aligned with China’s United Front Work Department, the Ministry of State Security, and the former State Administration for Religious Affairs.

ICT finds the report particularly disturbing because it also shows AI tools being used to advance the Chinese government’s political narrative on Tibet — potentially giving Beijing a powerful new mechanism to amplify and normalize that narrative at digital scale — and the deep integration of AI models into the daily work of the PRC municipal and state security bureau for “stability maintenance” and transnational repression.

“When Tibetan Buddhist civil society, the Tibetan government-in-exile and organizations peacefully advocating for Tibetan rights are subjected to AI-assisted surveillance, this cannot be treated simply as the misuse of a new technology. It is the modernization of transnational repression,” ICT President Tencho Gyatso said. “Governments and AI companies must ensure that technologies built to expand human knowledge do not become instruments for authoritarian governments to monitor people, intimidate communities and impose their version of history on the digital world,” she added.

Anthropic reports that the operation targeting members of Tibetan Buddhist civil society, the CTA and Tibetan advocacy groups, explicitly naming ICT and SFT, used Claude to transform multilingual information into Chinese-language intelligence dossiers, organizational datasets and daily “situational awareness” reports. They collected personal information, monitored Chinese and international social-media platforms and conducted physical reconnaissance of religious venues, including gathering floor plans and structural information.

Anthropic also found operators instructing Claude to adopt “China’s standpoint” and characterize the Tibetan administration in exile as an “illegal separatist administration.” Anthropic also uncovered a separate China-based operation in which AI was used to impose PRC-preferred terminology and reframe foreign reporting critical of China for government intelligence briefings.

“For decades, Beijing has tried to control Tibet by controlling our institutions, our religion, our language and the story the world hears about Tibet. What Beijing has sought to impose in Tibet’s physical spaces must not become the default version of Tibet in the world’s digital spaces,” Gyatso said. “Artificial intelligence should expand access to knowledge — not accelerate surveillance, intimidation and the erasure of a people’s history and identity.”

Chinese authorities have long sought to reshape Tibetan identity and historical understanding through restrictions on Tibetan-language education, political education, controls over Tibetan Buddhism and efforts to replace the internationally recognized name “Tibet” with Beijing-preferred terminology. Anthropic’s findings point toward a digital extension of that effort, where AI can reproduce Beijing’s political framing of Tibet at speed and scale.

The findings reinforce patterns documented separately by OpenAI, which has reported PRC-linked actors seeking assistance with large-scale social-media monitoring, profiling critics and identifying ethnic, religious and political content. OpenAI also reported a proposed “early warning” system combining transportation and police data to identify movements of people classified as “Uyghur-related” and “high-risk;” it was not able to establish whether the system was deployed.

ICT, therefore, calls on governments and AI companies to take two immediate steps:

  1. AI companies should prevent and report AI-enabled transnational repression. Providers should block political, religious and ethnic profiling; detect coordinated state-linked surveillance and narrative manipulation; terminate abusive accounts; share threat indicators; and notify targeted individuals and organizations wherever safely possible.
  2. International governments, including the U.S., should investigate and protect communities targeted by Chinese AI operations. In the U.S., H.R. 6909 — referred to as the China AI Threat Assessment Act and introduced in Congress on December 18, 2025 — would require an intelligence assessment of Chinese AI’s potential use for foreign influence, surveillance and information manipulation targeting the U.S. and its allies. ICT calls for that assessment to examine AI-enabled targeting of Tibetans, Uyghurs and other diaspora communities, religious institutions and human-rights organizations, and to recommend safeguards and mechanisms for sharing threat information with those at risk.