When AI Becomes a Weapons Engineer
Twenty-five years ago on Friday, Americans awakened to an enemy most of us had seriously underestimated.
On September 11, 2001, al-Qaeda terrorists turned four commercial airliners into weapons, striking the World Trade Center and the Pentagon while passengers and crew aboard Flight 93 fought back before it crashed in Pennsylvania. The attacks killed 2,977 innocent people, and America’s understanding of terrorism changed for good.
Within weeks, America was at war in Afghanistan against al-Qaeda and the Taliban regime that had sheltered it. Operation Enduring Freedom began October 7, 2001. The Iraq War followed in that same shockwave, though the bipartisan 9/11 Commission found no evidence that Iraq cooperated with al-Qaeda in developing or carrying out attacks against the United States. Even so, 9/11 permanently changed how America weighs terrorism, hostile regimes, and the danger of waiting for threats to mature.
A quarter-century later, the terrorist threat has not disappeared. But the technology available to terrorists is changing fast.
That is why Anthropic’s own threat intelligence report, published this week and covered from the New York Times to Reuters, deserves close attention. Among its cases: a weapons-development cell in northern Yemen using AI to help engineer guided weapons, something that would have sounded like science fiction only a few years ago.
Anthropic did not name the organization, but The New York Times reported it involved the Iran-backed Houthi militia, known formally as Ansarallah, which the State Department designated a Foreign Terrorist Organization in March 2025.
The details are sobering: Anthropic says the cell pursued three weapons programs at once — a guided rocket, a multistage ballistic missile with a range goal beyond 2,000 kilometers, and a missile family that included a hypersonic-glide variant.
More striking than the weapons themselves was how the cell built them. Anthropic reports the actors used Claude Code “in place of human software engineers” for guidance, navigation, and control software, assigning different AI instances to coding, research, and review, much as a team lead divides work.
Then came the real test: the cell test-fired a guided rocket in Yemen, and it apparently failed. Within hours, the actors returned to Claude to help diagnose why — the detail Washington should not overlook. The rocket failed. The warning did not.
From Propaganda to Weapons
Until recently, most of the concern about terrorist use of AI centered on propaganda, recruitment, translation, and disinformation. A U.N. Counter-Terrorism Committee trends report released this week found terrorist groups exploiting AI to sharpen recruitment and expand multilingual outreach. Those activities are dangerous, but mostly concern how terrorists communicate. The Yemen case points to something different: AI-assisted propaganda, AI-assisted operational research, and now AI-assisted weapons engineering.
That progression echoes one of September 11’s central lessons: terrorists repeatedly adapt technologies built for other purposes and turn them toward destruction. On 9/11, the weapon was the commercial airliner. Twenty-five years later, one of the emerging tools may be artificial intelligence.
The Expertise Barrier
We should be precise about what Anthropic found. AI did not independently design a terrorist ballistic missile. The Yemen cell already had weapons knowledge, equipment, and access to testing, and Anthropic found no evidence it was ever fielded. But that does not shrink the larger danger.
For decades, technical expertise has separated a terrorist group’s ambitions from its capabilities. Sophisticated weapons demand engineers, institutional knowledge, money, time, and repeated trial and error, and artificial intelligence can strip away some of that. Anthropic’s own research, released alongside the threat report, found frontier AI models can now perform military and intelligence tasks that once required scarce human experts, capabilities the company warns are useful to actors pursuing weapons development.
A terrorist organization may still need engineers, but perhaps fewer of them. A small technical team paired with several AI agents can now accomplish work that once required more specialists, compressing timelines and pulling once-distant projects within reach. The danger is not a missile factory for every terrorist. It is that AI steadily lowers the price of expertise.
The Safeguards Are Already Being Tested
There is another warning in Anthropic’s report: its safeguards blocked many of the Yemen cell’s requests, but not all. The actors concealed their objectives and split the work across multiple sessions, so no single conversation revealed the full scope of the effort. Anthropic also found the cell had built an offline simulation toolkit that could run without Claude — a reminder that cutting off access does not erase capability AI has already helped build. Once identified, Anthropic banned the accounts, tightened its safeguards, and shared what it found with government and industry partners.
That is encouraging, but also a reminder that safeguards and adversaries are locked in a running contest. American AI companies should be treated as important national security partners; they may spot a weapons program’s digital fingerprints before intelligence agencies see its physical infrastructure. Washington needs standing channels for sharing credible indicators of weapons-related AI misuse among AI firms, intelligence agencies, law enforcement, the Pentagon, and allies, with constitutional protections built in from the outset.
And the answer cannot simply be restricting AI. Washington must also put AI to work on defense: hunting terrorist networks, flagging suspicious activity, and helping defenders move closer to the speed of AI-enabled attackers.
Twenty-Five Years Later
September 11 taught my generation a hard lesson about technology and evil. The men who attacked America that morning did not invent aviation or design the aircraft they hijacked. They took an advanced civilization’s achievements and turned them against the people who built them. We would be foolish to assume today’s terrorists will treat AI any differently.
Yet the fundamental problem was never the machine. Jesus located the source of evil elsewhere: “For out of the heart come evil thoughts, murder, adultery, sexual immorality, theft, false witness, slander” (Matthew 15:19, ESV).
Claude hated no one, embraced no ideology, and chose no target. Humans supplied the intention; AI supplied knowledge, speed, persistence, and technical competence. That is why the failed rocket test in Yemen matters. The frightening fact is not that AI built a terrorist missile; by Anthropic’s account, it did not. The frightening fact is that people trying to build one put AI on their engineering team, and when the weapon failed, went straight back to it for help.
Twenty-five years after September 11, we should remember the cost of underestimating what determined terrorists can do with tools built for other purposes.
AI does not have to become evil to make evil people more capable.
And this time, America should recognize the warning before the weapon succeeds.


