A series of surveillance efforts aimed at Uighurs, Tibetans, Taiwanese politicians and activists are moving further from cameras, databases and artificial intelligence analytics to the era of generated artificial intelligence.Anthropic’s latest threat intelligence disclosure reveals that Chinese-related actors have tried to use Claude to automatically organize surveillance materials, generate intelligence reports and track concerned groups, so that political surveillance work, which previously required a large amount of manpower, could run at lower costs and on a larger scale.

The most alarming thing about the disclosure is not “somebody abuses a chat robot,” but generated AI is filling the last costly human link in the national monitoring system: machines not only collect people’s location, relationships and speech, but also start reading, classifying, summarizing and forming reports for monitorers that can be delivered directly to decision makers.

Anthropic said its investigation found that Claude was used for a variety of malicious activities, including cyber attacks, weapons-related work, fraud and surveillance operations, including cases related to Chinese interests involving the processing of information about Uighurs, Tibetans, Taiwanese politicians and activists.

原始来源 · anthropic.comDisrupting AI espionageAnthropic关于国家支持型行为者滥用Claude开展情报与监控活动的威胁情报披露。anthropic.com ↗

From “camera sees you” to “AI for police to read you”

Over the past decade, China’s digital surveillance system’s most concerned capabilities have focused on front-end capture: public cameras, facial recognition, mobile phone inspection, communication data, travel records and cross-database connectivity.

But the more they gather, the more the other question emerges: Who handles massive amounts of data?Traditional intelligence systems require staff to read reports, filter social media, organize relationships, translate texts, and determine what needs further attention.

Large language models can do a lot of work automatically, and it can:

新疆喀什居民区监控摄像头资料图。生成式AI的加入可能使既有大规模数据采集体系获得更强的自动分析能力|来源:National Geographic
新疆喀什居民区监控摄像头资料图。生成式AI的加入可能使既有大规模数据采集体系获得更强的自动分析能力|来源:National Geographic · 查看图片来源 ↗
  • Bulk summaries of characters and organizational materials;
  • extract names, locations, relationships and political positions from a large number of texts;
  • classify social media content;
  • generate monitoring reports based on established templates;
  • translate Uighur, Tibetan, Chinese and other language materials;
  • organize fragmented information into personality archives and action clues.

This means that the scale of monitoring is no longer strictly restricted by the number of monitoring personnel.A material pool that used to be processed by dozens of people can be preliminarily filtered by the model in a very short time.

Xinjiang has demonstrated the first phase of "data stability"

Public surveillance in Xinjiang has long been highly intensive. International human rights organizations have previously revealed that local law enforcement systems use big data platforms, cameras and multiple sources of personal information to identify and classify residents.

With the addition of generated AI, the change is not simply adding a camera, but giving the existing data a stronger analytical capability. The camera solves “what happened”, the database solves “who this person is”, and the generated AI tries to solve “what this information means and who should be focused next.”

The real danger is not that AI suddenly takes a political stance, but that it is a compulsive institution that can hand over its political labels, key people lists, and stability targets to AI, allowing machines to perform screening at an industrialized rate.

* Cross-border repression has thus obtained a cheaper intelligence tool

原始来源 · reuters.com多国情报机构警告针对台湾、西藏等群体的间谍软件威胁路透社此前报道多国安全机构针对中国相关恶意软件活动发布联合警告。reuters.com ↗

Uighurs, Tibet, Hong Kong and Taiwan have long faced cyberfishing, malware, account attacks and identity gathering. Western intelligence and cybersecurity agencies have previously warned that malware actions related to Chinese security agencies are targeting Taiwan, Tibet, Uighurs and other groups that criticize Beijing.

Overseas activists have been able to reduce some entity surveillance pressures by leaving China in the past, but the digital space blurred national borders. Public speeches, social media, organizational lists, conference photos, and contact networks can all be automatically captured and reassembled.

原始来源 · reuters.comAnthropic披露Claude被用于监控、武器和网络行动路透社梳理Anthropic最新威胁情报及涉及中国利益相关监控活动的案例。reuters.com ↗

The AI that brings here is not new monitoring objects, but new monitoring efficiency. A overseas organization of dozens of events, hundreds of participants and thousands of public posts, which used to require long-term manpower; now models can quickly compress these materials into structured summaries.

Commercial AI companies are being forced to take responsibility for “anti-stability tools”

Anthropic closed the relevant accounts, indicating that GM could no longer see itself as a software company providing only text tools.After the model has the ability to code, analyze, translate and integrate information, its customers could be both researchers and intelligence agencies, cyber attackers and political surveillance systems.

This puts at least three levels of responsibility on AI companies:

  1. Identify mass political surveillance and abnormal usage patterns targeting specific ethnic groups;
  2. Prevent models from being used to create automated records of political dissidents, ethnic minorities and exiles; and
  3. Disclose sufficient information when abuses are detected at national or par-national levels to enable the targeted groups to take protective measures.

Open-source models, local deployment models, and third-party agency services mean that such capabilities cannot rely on a permanent blocking by a U.S. company.

The problem ultimately still points to people and systems using AI

In recent years, China has steadily strengthened the combination of artificial intelligence, public security, big data and social governance. Technology itself can be used in healthcare, education, research and public services, and can also be a multiplier of political control. The difference is not in algorithms, but in who owns data, who defines “risk person” and who is labelled by machines.

When a system considers religious identity, ethnic background, political views, overseas connections or public expression as variables that need to be continuously recorded, AI does not automatically correct that institutional logic; on the contrary, it may execute existing biases faster.

From cameras sealed in the streets of Xinjiang to automatically generated monitoring reports, a new technology chain in Chinese-style digital stability is emerging: front-end collection everywhere, middle-end databases continue to cluster, and back-end AI begins to automatically understand and classify.

What this chain needs to be asked most is not how many reports Claude wrote, but how much it will cost an average person to escape from a digital observer who will never get tired, get out of work, or forget when political surveillance enters the era of automation.

MEMBER DISCUSSION

Article discussion

Verified members can discuss this report publicly and manage their own content.