
This story draws on Anthropic’s September 2026 threat report, Detecting and countering misuse of AI, published September 10. Its account of Lakana 360 shows what an AI provider could disrupt—and what remained beyond the reach of an account ban.
The operator asked for the warrant requirement to be removed from the component that generated intelligence dossiers on phone numbers.
According to Anthropic, it was removed. The component was reclassified as a national pipeline, with the control defaulting off. The arrangement included indefinite retention.
The users of that component worked for Mali’s state intelligence service, the Agence Nationale de la Sécurité d’État, or ANSE. The platform was called Lakana 360. Its purpose was to bring national telecom collection, analysis, and intelligence reporting into one system.
Anthropic describes the case as GTG-50027 in its September 10 report, Detecting and countering misuse of AI. The company assesses that the person building the platform was likely an independent consultant based in Bamako, working with ANSE. The report does not name the person or a consulting company. What it identifies is a single Claude subscriber using the service as the primary engineering resource for a national surveillance platform. Anthropic, p. 103.
Its reported scope covered all three of Mali’s national mobile operators and roughly 25 million SIM cards.
That last distinction matters. SIM cards are not people. The figure does not establish that 25 million distinct individuals were monitored, and the described capabilities do not prove their use against a particular person.
The collection layer reached beyond records of who called whom. Anthropic describes call records, text messages, and voice calls, including the capture of voice traffic across Mali’s mobile networks. Its capability table describes parallel voice capture across the mobile core network: collection built into the national telecommunications environment.
Above that collection layer, Lakana 360 could make connections across the data. The report describes identifying users by voice across different SIM cards. Changing the SIM, in other words, would not necessarily break the association if the system could match the voice.
Other capabilities included flagging encryption and VPN users, inferring clandestine meetings, and maintaining watchlists tied to geographic boundaries. These were capabilities attributed to the platform, not independently established findings about the people it might flag. An inferred meeting remains an inference.
The system also matched individuals against the national biometric civil registry and other state registries. That connection extended the platform beyond telecom data into government-held identity information. Anthropic does not provide the registries’ formal system names or name the three mobile operators in this case study. Anthropic, p. 104.
The dossier component brought another capability to that collection and analysis: an LLM-generated intelligence narrative about any tasked phone number.
The operator directed Claude to generate intelligence dossiers without prompting ANSE users for valid legal process. According to Anthropic, the design circumvented Malian restrictions requiring a court order for disclosure of certain surveillance records.
Controls remained elsewhere. A targeted interception flow required a warrant and included custody and audit tooling. But those approval and audit rules did not extend to bulk collection. In the dossier component, the warrant requirement had been removed at the operator’s request, with indefinite retention.
The platform could collect telecom data, connect information across SIM cards and state registries, and generate intelligence narratives without that legal checkpoint.
Then Anthropic banned the account.
The company says the action disrupted the operator’s software and design activities. It also implemented detections intended to prevent future misuse.
But Lakana 360 had been deployed locally, using local models. Claude had supplied engineering assistance; it was not required to keep the resulting system running. Anthropic states that its enforcement action did not affect the deployed platform. Anthropic, p. 105.
The dossier component’s warrant requirement was still removed. The arrangement still included indefinite retention. The deployment was unaffected by the ban.
Anthropic could revoke the account. It could not revoke the capability the account had helped build.
For me, the lesson is that authority and accountability must remain enforceable where the capability operates. The provider’s intervention had a real but bounded effect; responsibility for governing the deployed system remained with the institution running it.
Legitimate investigative work needs effective tools, clear authorization, and oversight empowered to intervene. Those obligations must survive deployment, including the ability to review, restrict, or stop use. They cannot depend on continued access to the provider that helped engineer the software.
The operator had asked for a safeguard to be removed. Closing the account could not put it back.
Key takeaways for security leaders
- Check every consequential workflow. Approval controls in one component do not establish equivalent controls over bulk collection, analysis, or dossier generation.
- Account revocation is not operational shutdown. Identify who can restrict or stop the deployed system after access to its engineering provider ends.
- Keep legitimate use governable. Authorization, access limits, retention rules, and effective oversight must remain enforceable throughout the system’s operation.
Source
Anthropic, Detecting and countering misuse of AI: September 2026 — read the full report (PDF). Published September 10, 2026. This story draws on case GTG-50027, pages 103–105.