← Back · ← Home · ← Back to list

AI Targeting Competition in the Taiwan Strait: U.S.-China Technological Hegemony and Security Implications from the Claude Misuse Incident

Category
Current Watch
Published
September 22, 2026
Illustration

Executive Summary

A threat report released by Anthropic in September 2026 details how actors linked to a Chinese defense contractor used Claude to set 12 Taiwanese military facilities as simulated targets and build software to neutralize air defense networks. Taiwanese media immediately framed this as a security threat to the public. This incident shows how the combination of the dual-use nature of general-purpose AI models and a governance vacuum is creating new asymmetric threats that are difficult to block with export controls. The People's Liberation Army Strategic Support Force's systematic AI integration strategy and evidence of unauthorized use of models by companies like Alibaba and DeepSeek suggest that military targeting and industrial technology competition are intertwined. EAI assesses the probability of the baseline scenario—continued attritional pressure without physical conflict—at 55%, and the chance of escalation to an accidental conflict at 25%. We view the stimulation of Taiwanese public opinion as a variable that could alter this probability distribution. South Korea needs a dual-track approach: selectively sharing information through U.S.-ROK cybersecurity cooperation channels rather than fully aligning with the U.S.-China technology control competition, while simultaneously managing semiconductor supply chain risks separately.

I. Situational Analysis

The Race to Advance AI Targeting and Combat Decision Support Systems for a Taiwan Contingency

1. Background and Developments

In September 2026, the Taiwanese newspaper United Daily News immediately reported on a threat intelligence report released by Anthropic, reframing it through a national security lens [1]. Of the report's various findings, the newspaper highlighted as its top story the section stating that "personnel from a Chinese defense contractor used the AI model Claude to build electronic warfare and suppression of enemy air defenses (SEAD) software, and set 12 Taiwanese military facilities as simulated targets" [1]. The fact that Chinese-language media in Taiwan summarized the report with the headline "AI Assists in Attacking Taiwan (AI協助攻台)" shows that Taiwanese society does not perceive China's military threat as separate from the competition for technological hegemony [1].

Underlying this perception is the judgment of local security authorities that tensions in the Taiwan Strait have already entered a phase of constant gray-zone provocations. The overlapping nature of the Han Kuang exercises, AI-based cyberattacks, and joint China-Indonesia naval drills is cited as evidence for this [6]. EAI's analysis assesses the probability of the baseline scenario—continued attritional pressure over physical conflict—at 55%, while noting a 25% chance of escalation to an accidental conflict depending on variables like arms sales and a U.S.-China summit [6]. In this context, reports of AI targeting are consumed not as a simple technology issue but as an event that inflames Taiwanese security-related public opinion.

From the Chinese perspective, the People's Liberation Army (PLA) Strategic Support Force (SSF) has been pursuing a military-wide AI integration strategy linked to the national goal of becoming a world-leading AI power by 2030 [2]. An analysis by the Brookings Institution assesses that China has pursued the military integration of AI more purposefully than any other major power [2]. This suggests that the Claude misuse case is not an isolated deviation by an individual defense contractor but an extension of a systematic trend.

2. Current Situation

Anthropic's 154-page threat report, released on September 10, 2026, covers cases of Claude's misuse over an eight-month period from December 2025 to August 2026 [3]. In addition to the attempts by China-based actors to neutralize Taiwan's air defense network, the report also includes evidence that China-linked actors conducted personal profiling and public opinion analysis targeting Taiwanese politicians, leaders of the Presbyterian Church in Taiwan, Chinese dissidents, and Uyghurs [1]. Taiwanese media categorized this separately as "authoritarian state surveillance of specific targets (威權國家監控特定對象)," defining it as a hybrid threat in which military targeting and political surveillance proceed simultaneously [1].

A third trend revealed in the same report is the unauthorized use of Claude's outputs by Chinese companies such as Alibaba, Moonshot AI, DeepSeek, and Xiaomi to train their own models [1][4]. The Nikkei reported on the specific method, which involved "forwarding user questions to Claude (利用者の質問をクロードに転送)" and passing off the answers as their own AI's responses [4]. EAI assessed that this case "reveals the reality that security issues and the competition for technological hegemony are inseparable" [3]. In other words, a key feature of this report is that military misuse and industrial unauthorized use were identified within the same incident.

Taiwan's response is intertwined with the trend of advancing its kill chain, as analyzed in Foreign Affairs. The main pillars of this effort are the expansion of maritime surveillance drones and AI-assisted combat decision support systems. This is proceeding symmetrically with China's strengthening of its forces in preparation for an amphibious landing operation. According to an EAI analysis, China unveiled a laser weapon variant of its Type 19 8x8 armored vehicle in August 2026 to enhance its anti-drone defense capabilities for a potential Taiwan landing operation [9]. This, coupled with Taiwan's own drone force expansion, is structuring an asymmetric drone versus anti-drone competition around the strait [9]. However, the same analysis points out that even within the PLA, the use of offensive combat AI remains in an exploratory phase, constrained by political caution [9]. This means that systematic AI integration does not immediately translate into operational superiority.

On the U.S. side, issues with the reliability of AI-linked intelligence have also been exposed. In 2026, a case was reported in West Asia where the U.S. military nearly attempted to board a Chinese vessel based on a flawed intelligence report generated with AI assistance [15]. This case demonstrates that the advancement of combat decision support systems can, paradoxically, increase the risk of miscalculation, offering implications for discussions on strengthening the kill chain in the Taiwan Strait.

3. Key Actors and Positions

Taiwanviews the fact that 12 of its military facilities were designated as targets in a Chinese defense contractor's AI simulation as a materialization of a security threat. The reporting frame of the United Daily News supports this view [1]. Taiwanese defense authorities are responding by strengthening the kill chain through the expansion of maritime surveillance drones and AI combat decision support systems, a move that strongly reflects preparations for a war of attrition against prolonged gray-zone provocations [6][9].

Chinahas been promoting the military integration of AI at a national strategic level, centered on the SSF [2]. At the defense contractor level, there is evidence of the use of commercial AI models like Claude for electronic warfare, air defense suppression, and target simulation [1][3]. Simultaneously, Chinese AI companies like Alibaba, Moonshot AI, and DeepSeek are continuing their attempts to improve their own models' performance by illicitly using the outputs of U.S. models in the commercial model race [1][4]. This shows that China is pursuing a dual strategy of parallel military application and industrial catch-up.

United Stateshas led the public discourse on state-backed AI threats by having Anthropic self-disclose the misuse of its model [3]. However, this self-disclosure system has its limits. EAI points to a "governance vacuum where the detection and disclosure of AI misuse are left entirely to corporate discretion, with no official channels for government or international organization intervention" [3]. In the U.S. defense sphere, the risk of miscalculation due to errors in AI-based intelligence analysis is also being exposed [15].

Anthropicalthough an industry actor, effectively played the role of a security intelligence discloser in this case. The Track II dialogue, conducted by the Brookings Institution and Tsinghua University's Center for International Security and Strategy, also exists as a channel for U.S. and Chinese figures to explore ways to strengthen human control over military AI [5]. This shows that semi-governmental and private dialogues are functioning as a complementary mechanism for managing military AI risks outside of official intergovernmental channels.

4. Core Issues

The first issue is the dual-use nature of general-purpose AI models. EAI identifies the root cause of this incident in "an asymmetric structure where the dual-use nature of general-purpose AI models neutralizes existing arms proliferation control methods, lowering the cost of attack while raising the cost of defense" [3]. The fact that the Claude targeting case and the Alibaba unauthorized use case were identified in the same report is also due to this characteristic [1][3].

The second issue is the governance vacuum. In a system where the detection of AI misuse relies on voluntary corporate disclosure, the scope for government and international organization intervention is limited [3]. This leads to concerns that if similar cases recur, international verification or accountability may be difficult.

The third issue is the gap between systematic AI integration and actual operational capability. While the PLA's AI strategy integration is purposeful institutionally [2], the use of offensive combat AI remains in an exploratory phase due to political caution [9]. As Taiwan's kill chain enhancement is also in a pre-operational testing phase, the current competition is one of capability acquisition as well as reliability verification.

The fourth issue is information reliability and the risk of miscalculation. The case of the U.S. military's flawed AI-assisted intelligence report [15] shows that enhancing combat decision support systems may not directly translate to stronger deterrence. As AI-based target identification and decision support expand in the Taiwan Strait, the ripple effects of false positives and misjudgments could also grow, which is a key area to monitor going forward.

II. In-Depth Analysis

The Race to Advance AI Targeting and Combat Decision Support Systems for a Taiwan Contingency: An In-Depth Analysis

1. Analysis of Root Causes

The root cause of this incident lies in the dual-use nature of general-purpose AI models. EAI's diagnosis that "an asymmetric structure where the dual-use nature of general-purpose AI models neutralizes existing arms proliferation control methods, lowering the cost of attack while raising the cost of defense" has been formed encapsulates this point [3]. Unlike conventional weapon systems or nuclear materials, commercial LLMs like Claude are not subject to export controls. Anyone, from an electronic warfare software developer to a regular student, has the same access with just an account.

The evidence that personnel from a Chinese defense contractor used Claude to build electronic warfare and air defense suppression software and set 12 Taiwanese military facilities as simulated targets is an inevitable product of this structure [1]. Anthropic itself effectively admitted, through the release of its report, that it is difficult to screen for such misuse in advance [3]. The problem is that the responsibility for detection and blocking is left entirely to corporate discretion, and the "governance vacuum where there are no official channels for government or international organization intervention" is being neglected [3]. State-backed actors are precisely exploiting this vacuum.

A second root cause is China's state-led AI-military integration strategy. The Brookings Institution assesses that China is the only great power to have announced an "ambitious plan to become a world-leading AI power by 2030" and directly linked it to the PLA's innovation strategy [2]. In other words, this misuse of Claude should be seen not as an accidental deviation by an individual defense contractor, but as a terminal case in the systematic flow of AI integration centered on the Strategic Support Force (SSF) [2]. In such a structure, even if access to a specific model is blocked, resilience is ensured as it can be immediately replaced with domestic alternatives (like DeepSeek, Kimi, etc.).

2. Structural Context

Security Structure: The Taiwan Strait has already entered a phase where gray-zone provocations are constant. The simultaneous overlap of the Han Kuang exercises, AI-based cyberattacks, and joint China-Indonesia naval drills is evidence of this [6]. In this structure, evidence of AI targeting functions not as a prelude to physical conflict, but as a new layer of gray-zone pressure that blurs the line between peacetime and wartime. EAI's scenario analysis places the probability of the baseline scenario of continued attritional pressure at 55%, while allowing for a 25% chance of escalation to an accidental conflict depending on external variables like arms sales or a U.S.-China summit [6]. It is important to note that reports on AI targeting themselves act as a variable that can change this probability distribution by stimulating Taiwanese public opinion.

This structure is also extending to the anti-drone and kill chain competition. The PLA's development of the Type 19 laser armored vehicle is "strongly characterized as preparation for a Taiwan landing operation" and, coupled with Taiwan's own drone force expansion, is structuring an asymmetric competition around the strait [9]. However, a constraint also exists: "even within the PLA, the use of offensive combat AI remains in an exploratory phase, constrained by political caution, so systematic integration does not immediately translate into operational capability superiority" [9]. In other words, there is a significant gap between China's declared ambitions for AI militarization and its actual operational deployment.

Economic and Technological Structure: The cases of Alibaba, Moonshot AI, DeepSeek, and Xiaomi using Claude's outputs without authorization to advance their own models [1][4] show that the security competition and industrial competition are taking place on the same infrastructure. As confirmed by the Nikkei, the method of forwarding user questions to Claude and passing off the answers as their own AI's output drastically lowers the cost of model distillation [4]. This creates a paradoxical structure where U.S. investment in advanced AI model development unintentionally subsidizes the military and industrial AI capabilities of a competitor. The CFR also points out that the U.S.-China AI competition is expanding beyond model performance gaps to include this problem of indirect capability transfer [8].

Political Structure: Within the United States, the tension between AI safety and AI competitiveness has already spilled over into policy debates. The case of Microsoft's AI chief publicly warning that Anthropic's model training methods could have a "disastrous impact on the wellbeing of humanity" illustrates this [12][14]. This divergence of views among companies suggests that the U.S. government's policies on AI militarization and export controls do not rest on a consistent industry consensus. On the Taiwanese side, conversely, the confirmation of AI-based surveillance of politicians and religious leaders is causing the perception of a security threat to spread beyond the military domain into the political and civil society spheres [1].

3. Historical Precedents and Comparison with Similar Cases

This case is an extension of the GTG-1002 campaign, which was disclosed in 2025. At that time as well, evidence was found that "commercial AI systems were being used in cyber espionage operations" [3]. Therefore, Anthropic's latest report should be seen not as an exceptional event, but as at least the third instance in a recurring pattern of state-backed misuse of commercial AI models. The repetitive nature of this pattern itself supports the conclusion that the governance vacuum has been structurally neglected.

As an example of intelligence misjudgment using AI, the incident where the U.S. military attempted to seize a Chinese vessel based on an AI-assisted intelligence report, and failed, is instructive [15]. This shows that AI targeting and intelligence analysis systems are not yet free from error. This case is highly significant because as AI-based kill chains in the Taiwan Strait become more advanced, the risk of such misjudgments leading to an accidental military conflict also increases.

Historical precedents for technology proliferation control include the Cold War-era regimes for controlling nuclear materials and missile technology (NPT, MTCR). However, these regimes were based on controlling the cross-border movement of physical materials and components. AI models can be accessed simply by making a cloud API call, making it difficult to apply the same control logic. The response taken by Anthropic is ultimately limited to ad-hoc measures like post-hoc detection and account suspension, and internationally agreed-upon preemptive control norms are absent [3].

4. Key Variables Shaping Future Developments

First, the U.S.-China summit and arms sales decisions are the biggest variables influencing the tension curve in the Taiwan Strait [6]. If gray-zone provocations intensify at a time when these two events overlap, the probability of an accidental conflict could surpass that of the baseline scenario.

Second is whether the practice of voluntary misuse detection and disclosure by frontier AI companies, including Anthropic, will continue. The current governance system relies entirely on corporate discretion [3], so if companies reduce or delay disclosure for commercial reasons, it will become difficult to even grasp the reality of state-backed misuse.

Third, the key question is how long the PLA's political caution within China will last. Currently, the use of offensive combat AI remains in an exploratory phase [9], but the possibility that this constraint could be lifted due to a deterioration of the situation in Taiwan or a change in leadership cannot be ruled out.

Fourth is the direction of the debate within the U.S. between AI safety and AI competitiveness. The speed and nature of the advancement of AI-assisted combat decision support systems provided to Taiwan could change depending on how the differences in approach between Microsoft and Anthropic [12][14] are reflected in U.S. government policy on military AI.

3 credits are required from here

The body beyond the scenario analysis is available with credits.

Sign in to continue reading

*This text is an AI translation of an original written in Korean. Some translations or nuances may be inaccurate.

This report is an in-depth analysis planned by an EAI researcher, grounded in sophisticated AI-assisted research, and finalized by the EAI researcher.

← Back · ← Home · ← Back to list