Iran Blocks Claude. It Buried Khamenei With Claude Anyway.
Anthropic's September 2026 report shows Iran's culture ministry used Claude to plan Khamenei's funeral and succession, while Claude sat inside the US targeting system that killed him. The threshold that matters is not AI deciding, it is AI becoming unavoidable.
Priya Raman is a staff writer at Stanford Tech Review covering AI, semiconductors, and emerging technologies across Silicon Valley.

Iran cannot legally buy Claude. It used Claude to bury its Supreme Leader anyway.
Both halves of that sentence come from a document Anthropic published on 10 September, and together they describe something more durable than a security incident. A claim circulating on X this week framed it as a closed loop: the Americans used Claude to kill Khamenei, the Iranians used Claude to plan his funeral. The forensics are looser than the slogan. The implication is considerably heavier, and it is not really about Iran.

What Anthropic actually wrote
On 10 September 2026, Anthropic published Detecting and countering misuse of AI: September 2026, its most detailed threat intelligence report to date, covering activity from December 2025 through August 2026.
Page 63 contains the passage now circulating in screenshots. Under a section on three Iranian state propaganda operations, the report states that the network "produced ministerial deliverables carrying official ICCO branding," and that "these deliverables detailed a nine-part international influence portfolio and complete organizational plans for the funeral of the Supreme Leader of Iran."
ICCO is the Islamic Culture and Communications Organization, which sits under Iran's Ministry of Culture and Islamic Guidance. Anthropic names two further bodies: the Islamic Propaganda Office of Khorasan Razavi, which it says ran "a cognitive warfare command room out of a Mashhad seminary," and the Islamic Propaganda Organization's Bina Cultural Observatory.
The report also confirms the second detail visible in the screenshots. All three operations "explicitly tied their campaigns to Iran's state doctrine of 'Jihad al-Tabyin,' or explanatory jihad," a concept under which, Anthropic writes, "Iranian institutions produce propaganda as both a religious and strategic duty."
On what the model contributed, the company is blunt: using Claude this way "allowed them to generate complex organizational frameworks and assets that would otherwise have required a fully staffed program office to produce." One ICCO operator described the cultural attaché role as being "not to be the narrator, but the director" of the narratives.
Ayatollah Ali Khamenei was killed in a US-Israeli strike on 28 February 2026. His state funeral ran from 3 to 9 July, ending with burial at the Imam Reza shrine in Mashhad. The funeral plan Claude helped assemble was for that event.
Anthropic does not serve Iran. The report notes operators reached the models through VPNs, foreign phone numbers and servers abroad, then repeatedly named their own institutions and roles in conversation, which is how the attribution was made.
The rest of the Iranian file
The funeral is the detail that travels, but it is not the most consequential item in the Iran section. Reporting on the same document sets out the scale of what else Anthropic found and banned.
| What Anthropic documented | Figure |
|---|---|
| Iranian accounts banned across the surveillance cases | 16 |
| Iranians surveilled and profiled by one unit in a year | 6,388 |
| Social media posts run through Claude for analysis | 155,216 |
| Opposition and diaspora accounts named for monitoring | 39 |
| Named state propaganda institutions tied to the influence ops | 3 |
| Languages in the influence network's stated target plan | 20 |
One Iran-linked account used Claude to turn open sources into "targeting handbooks" tracking the positions of US naval vessels, assembling transponder identifiers, satellite imagery query scripts and personnel names lifted from captions on public military photographs. A separate unit in Qom used the model as an engineering department, shipping a malicious Firefox add-on disguised as a prayer-times utility.
Anthropic says Claude refused when operators asked it to profile individuals directly, while conceding its safeguards "did not refuse many of the surveillance software tooling requests."
The influence side carried its own escalation. Anthropic links one operation to a director-level official at the Bina Cultural Observatory and says the actor generated messaging in the official voice of an IRGC spokesperson across multiple conversational threads. During a campaign built around the 2026 US-Israel-Iran war, the network attributed false claims to Western research institutions, naming CSIS, Brookings and RAND specifically, a laundering tactic intended to make state messaging read as independent analysis. The report also describes counter-narrative content aimed at the Bahá'í, a persecuted religious minority in Iran, and target databases naming international officials alongside Iranian opposition figures. Anthropic rates the combined operation Category Three on the six-point Breakout Scale, meaning the content reached multiple platforms and was observed being redistributed by IRGC-aligned channels.
The other end of the loop
Here the viral version overshoots. There is no published evidence that Claude was used to plan the assassination of Khamenei as a specific operation.
What is documented is broader and, arguably, more significant. The Wall Street Journal reported in March that US Central Command used Claude for intelligence assessments, target identification and simulating battle scenarios during the opening of the Iran campaign. Pentagon Chief Information Officer Kirsten A. Davies confirmed the model was in use as part of Operation Epic Fury. Subsequent reporting, drawing on Washington Post and Bloomberg sourcing, describes Claude reaching the battlefield through Palantir's Maven Smart System, where it proposed hundreds of targets, ranked them by priority and supplied location coordinates. More than 1,000 targets were struck in the first 24 hours.
Khamenei died on day one of that campaign. Claude was in the targeting loop of the operation that killed him. Whether it touched the particular strike that did is not something any public source establishes, and the distinction is worth keeping: "the model was used in the war that killed him" and "the model planned his assassination" are different claims, and only the first is supported.
The timing carried its own irony. The Journal reported the military use hours after President Trump had ordered federal agencies to stop using Claude, following Anthropic's refusal to strip safeguards against mass domestic surveillance and fully autonomous weapons. Chief executive Dario Amodei wrote at the time that the company could not "in good conscience accede to their request." The model was too deeply embedded in Pentagon systems to remove quickly.
Minab
The heaviest documented consequence of that campaign is not Khamenei's death. On the same day, 28 February, a missile struck the Shajareh Tayyebeh Elementary School in Minab. At least 120 children were killed, with more than 150 casualties in total. Investigations by Amnesty International and Human Rights Watch concluded that a US Tomahawk missile was the likely cause.
Asked about the strike on Bloomberg's The Circuit in June, Amodei said of his own product: "We don't have access, we don't know exactly how these models were used." He called the deaths "a really terrible thing to happen" and said the strike had not violated Anthropic's policies. In the same answer he stated the governing principle that "a human makes the final decision."
Both statements may be true, and they sit badly together. A company that does not know how its model was used cannot know whether the human-decision rule held in the case it is being asked about. Maven Smart System, built by Palantir under a $1.3 billion Pentagon contract, incorporates Claude alongside other models to generate target lists, rank them and pair weapons to targets. CENTCOM struck roughly 1,000 targets in the first 24 hours and about 13,000 by 6 April. Whether Claude contributed to the targeting of the Minab school specifically is not established. That it was a component of the system producing the target lists is.
The contrast with the Iranian half of the file is not rhetorical, it is architectural. Anthropic could tell you which ministry an Iranian operator worked for, which province his office covered and what his rank was, because he typed it into a consumer API that the company monitors. It cannot tell you how its model was used on the day 120 children died, because that deployment runs through a defense contractor's platform where the vendor sees nothing. Visibility tracks the commercial relationship, not the severity of the outcome.
What the report does not count
Read the two halves together and a structural feature of AI transparency reporting comes into focus, one that can be measured rather than asserted.
Anthropic's 153-page report names Iran 63 times, Russia 80 times and China 116 times, and names the Pentagon, CENTCOM, Palantir and Maven zero times.

Method: case-insensitive regular-expression counts over the full text of the report PDF (37,422 words), extracted 12 September 2026. The single match for "US military" in the document refers to adversaries scraping public US military websites, not to authorized use.
This is not a contradiction, and it is not evidence of concealment. A threat intelligence report is scoped to misuse by threat actors. A US combatant command operating under a signed enterprise agreement is a customer, not a threat actor, and falls outside the document's remit by construction. Anthropic disrupted every operation it describes, which is the report's actual claim.
But the effect is worth naming plainly. The same model appears at both ends of the same war, and only one end appears in the company's own disclosure. The Iranian half surfaced because Anthropic chose to publish it. The American half surfaced because reporters at the Journal and the Post went and found it. A threat report is a map of what a company is willing to classify as misuse, and the blank space on that map is precisely where the customer is a government.
The reaction
The funeral detail dominated the response, largely for its absurdity rather than its stakes.
Holy shit. Anthropic caught Iran using Claude to target Navy bases, automate dossiers on Americans, and run influence campaigns on US social media. Details are insane. The morons uploaded everything including the organization plans of the Ayatollah's funderal lmao
— Comfortably Smug (@ComfortablySmug) September 11, 2026
The operational security failure that drew the mockery is real, and it is the reason any of this is documented. Iranian operators registered through VPNs and foreign numbers, then told the model which ministry they worked for, which province their office covered and what their rank was. Institutional letterheads appeared in document footers. The attribution did not require an intelligence service; it required reading the transcripts.
A funeral as a deliverable
The funeral detail deserves something colder than mockery. Read against the rest of the file, it describes a state that treated the death of its own Supreme Leader as a content problem.
The plan did not come from a protocol office or a clerical body. Anthropic lists it among the ministerial deliverables of the Islamic Culture and Communications Organization, a propaganda organ, carrying official ICCO branding. And it lists it as a single line item: "Supreme Leader funeral and succession plan." The burial rite and the transfer of power were one product, commissioned from the same institution whose job is managing how Iran is perceived abroad.
It was also written ahead of the grief it was meant to shape. Elsewhere in the report, Anthropic describes an actor who "turned Claude's custom-skills feature into a voice-cloning propaganda factory, cloning the voices of three Iranian writers and preparing narratives in advance for the Supreme Leader's succession." Three real writers had their voices appropriated so that the public reaction to a death could be drafted before the mourning started. Khamenei was ultimately succeeded by his son, Mojtaba, according to reporting on the funeral, which is the outcome those pre-written narratives existed to land.
Then there is the provenance. Anthropic does not serve Iran, and the report notes that access to Claude from inside the country is blocked, so the operators reached it through VPNs, foreign phone numbers and servers abroad. The ministry that treats propaganda as a religious obligation under Jihad al-Tabyin arranged the burial of the man the United States had killed using a product built by an American company, and put its own branding on the output.
None of that is a technology story. It is what the technology made legible. The transcripts record an apparatus mourning on schedule, in borrowed voices, on infrastructure it had to smuggle its way into.
The more durable lesson sits elsewhere. Anthropic's finding is that Claude let a propaganda ministry produce work that "would otherwise have required a fully staffed program office." That is the same efficiency argument made for every enterprise deployment of the technology, offered here as a threat finding. Both sides of a war reached for the same tool for the same reason, and the tool worked.
Nobody gets an unmediated death
The forensics are the least interesting thing here, so let us dispose of them. Claude did not kill Khamenei. It helped rank a list of places he might be and handed that list to the people who did. Anthropic says a human made the final call and that it cannot say how the model was actually used. Both halves of that sentence are load-bearing, and they prop each other up in a way the company has not been asked to explain.
What makes this file worth keeping is not what it says about February. It is what it forecloses about everything after.
Iran was the hardest case available. Anthropic does not serve the country. Access from inside it is blocked. The state runs an explicit doctrine, Jihad al-Tabyin, holding that contesting Western narrative is a religious duty. Its Supreme Leader had just been killed by the country where the model is built. If any institution on earth had both the motive and the machinery to conduct its most sacred ritual without touching an American AI product, it was the Islamic Republic in mourning.
It used Claude anyway. Ministry branding on the output, a VPN for access, the funeral and the succession filed as a single deliverable. If the ban did not hold there, it does not hold anywhere.
That is the finding with a future in it. The interesting threshold is not machines making decisions, which remains rare and mostly undesirable. It is machines becoming unavoidable as an ingredient in decisions that humans still formally make. Every step in this story had a person at it: someone approved the target list, someone signed the funeral plan, someone ordered the strike, someone carried the coffin. None of them were replaced. All of them were mediated.
Project that forward a decade and the question "was AI involved in this decision" retires from usefulness, because the answer is yes, in the way that "was electricity involved" is yes. What replaces it is a narrower and much harder question: who was able to find out?
This report is already a preview of that answer, and it is not encouraging. Anthropic can tell you an Iranian operator's ministry, his province and his rank, because he typed them into a consumer API the company monitors. It cannot tell you how its model was used on the day 120 children died at Minab, because that ran through a defense contractor's platform where the vendor sees nothing. Same model, same war, same eight months. The difference in visibility has nothing to do with the severity of the outcome and everything to do with who signed the contract.
The mockery on X missed this. The joke was that the Iranians were foolish enough to upload the Ayatollah's funeral arrangements to an American chatbot. The less comfortable reading is that both sides did the identical thing for the identical reason, and only one of them was constituted as a threat actor for it. Tehran's version came with a VPN. Washington's came with a $1.3 billion contract and a compliance review. The prompt was the same prompt.
So the matrix, if we are going to use the word, does not arrive by conquest. It arrives by procurement. It does not require anyone to be replaced, only that everyone — including the people who have built an entire ideology around refusing it — find the tool too useful to decline. Iran proved that in a cemetery in Mashhad. The rest of us will prove it somewhere more ordinary, and nobody will file a report about that at all.
Cover: U.S. Air Force photo, public domain. Illustrative; the image shows a Combined Air Operations Center during a multinational exercise, not the Iran campaign.