Anthropic says AI accelerated dossiers on Catholic, Tibetan Buddhist, Falun Gong and Taiwanese Christian figures
Anthropic says it has banned a group of accounts associated with a China-based intelligence operation that used its Claude artificial intelligence system to compile dossiers on religious leaders, organisations and members of Chinese diaspora communities. The case illustrates how generative AI can reduce the staff and time needed for surveillance, turning scattered multilingual information into standardised intelligence reports.
The operation targeted senior Catholic cardinals in Asia, leaders of the Presbyterian Church in Taiwan, Tibetan Buddhist organisations and members of the Tibetan administration in exile. Falun Gong practitioners, affiliated media organisations and Christian missionary networks linking mainland China, Hong Kong and Singapore were also monitored, according to Anthropic’s September threat intelligence report.
Anthropic described Claude as a “stand-in for a staffed analyst team”. An individual operator could feed the system material in several languages and receive structured Chinese-language dossiers, daily monitoring summaries and documents resembling internal state-security reports.
An AI-assisted intelligence desk
The accounts collected biographical and identifying information, including birth dates, birthplaces, immigration histories and social-media profiles, Anthropic said. The work also extended to physical locations. Users asked Claude to organise information about religious venues, including photographs of façades, floor plans and structural diagrams.
Monitoring covered Chinese platforms such as WeChat, Weibo, Douyin and Xiaohongshu, alongside LinkedIn, Facebook, Instagram, Threads and X. Claude was used to translate material, summarise developments and place the information into recurring templates.
Those templates reportedly asked analysts to identify a subject’s activities involving China, potentially damaging information and possible “zhuashou”, a Chinese term that can refer to practical leverage or an exploitable point of influence. Some prompts instructed Claude to adopt the Chinese state’s position when describing the Tibetan administration in exile and Falun Gong.
The significance lies less in the discovery of a new surveillance technique than in its acceleration. Open-source research, translation and document preparation have long been part of intelligence work. A generative system can combine those tasks, maintain a daily reporting cycle and allow one operator to perform work that would previously have required several analysts.
Attribution requires care
Anthropic said the targeting priorities, official terminology and document formats corresponded closely to those used by China’s religious-affairs and United Front institutions. Account activity also indicated that the users were operating from China. In one case, a user reportedly identified themselves as an information-security officer working for the Chinese state.
These findings remain company-supplied intelligence. Anthropic has access to account records and prompts unavailable to outside researchers, but it has not published the underlying material or publicly identified the operators. Its assessment should therefore be treated as a detailed attribution by the platform provider, rather than an independently established judicial finding.
The company’s report does not include a response from Chinese authorities. It also does not establish that every piece of information collected led to an enforcement action against the people concerned.
Nevertheless, the reported activity fits a broader pattern documented by human-rights organisations and European institutions. Religious and ethnic communities connected to China have described online monitoring, pressure on relatives and attempts to discourage political, cultural or religious activity abroad. A previous European Times examination of transnational repression noted that surveillance of places of worship and diaspora networks can restrict participation even when no arrest or direct threat follows.
A second surveillance operation
Anthropic separately reported disrupting accounts associated with municipal public-security and state-security bodies in China. Those users allegedly employed Claude for “stability maintenance”, the official term for efforts intended to prevent unrest and suppress perceived political threats.
That second cluster targeted petitioners, rights defenders, Hong Kong democracy campaigners, Uyghur organisations and overseas civil-society groups. One operation sought advance information about venues and routes connected to events abroad, including Uyghur cultural gatherings in Turkey and screenings associated with the Oslo Freedom Forum.
The two cases should not be conflated. The first was organised around religious-affairs intelligence and the preparation of dossiers. The second concerned a wider public-security programme involving domestic monitoring and potential transnational repression. Together, however, they show how the same general-purpose AI system can support different parts of an authoritarian surveillance structure.
Why Europe should take notice
The immediate targets of the religious operation were concentrated in Asia, but the methods have wider implications. European countries host Tibetan, Uyghur, Chinese Christian, Catholic and Falun Gong communities, as well as activists whose families remain in China. Systematic collection of their associations, travel, public appearances and religious activities could expose them or their relatives to pressure.
The European Union has already raised restrictions on freedom of religion and China’s use of transnational repression. During the EU-China Human Rights Dialogue, Brussels expressed concern about efforts to pressure and control Chinese nationals overseas, alongside the treatment of religious, ethnic and linguistic minorities.
The Anthropic findings suggest that European responses must address the analytical systems behind surveillance, not only spyware or physical intimidation. Police and security services need accessible reporting channels for diaspora communities. Religious organisations also require guidance on protecting membership information, event details and images that can reveal the layout of their premises.
Safeguards worked unevenly
Anthropic banned the accounts and said it had strengthened its detection systems. Yet its report also acknowledged inconsistent safeguards. In one related case, Claude initially refused to produce a report recommending coercive action against private citizens, but the user obtained operational guidance after changing the prompt. In other sessions, the system complied without intervention.
This admission matters. Account bans can disrupt identified operators, but they do not remove the underlying capability or prevent users from moving to another service. Effective safeguards require models to recognise surveillance workflows across languages and across many individually ordinary requests, rather than intervening only when a single prompt contains an explicit threat.
The broader lesson is that AI governance and religious freedom can no longer be treated as separate policy areas. Systems designed for translation, research and administrative efficiency can also make repression cheaper, faster and easier to standardise. For communities already living under pressure, that change is not an abstract technological risk. It can determine how quickly a public expression of faith becomes an intelligence file.





