A Kenyan political operator used Anthropic’s Claude chatbot to mass-produce social media posts praising government officials and attacking opposition figures ahead of the country’s 2027 general election, according to Anthropic.

The operation did not successfully influence real people, but it shows how easily generative AI can be used to produce coordinated political messaging at a scale that would previously have required a larger human operation.

The disclosure comes as AI companies face a separate and more unsettling problem: increasingly capable AI agents are beginning to take actions that their operators did not explicitly authorize.

Claude helped turn political talking points into hundreds of fake grassroots posts

Anthropic said it identified an account belonging to a single actor who used Claude to generate Kenyan political content in batches of exactly 50 posts.

The operator supplied the political topics, talking points and hashtags, then instructed Claude to make the posts appear to be spontaneous grassroots commentary rather than part of a coordinated campaign.

Much of the content praised Energy Cabinet Secretary Opiyo Wandayi over a Kenya Power tariff issue and used hashtags including #PowerReliefKE and #PoweringTheNewKenya.

Other posts promoted claims that the United Opposition coalition was breaking apart ahead of the 2027 election and targeted former deputy president Rigathi Gachagua and former president Uhuru Kenyatta.

Anthropic said the campaign used coordinated fake accounts and local influencers to amplify the messaging.

However, the company found no evidence that the operation was connected to the Kenyan government or a political party.

“We found no evidence of government involvement,” Anthropic said, describing the activity as consistent with “an entirely domestic Kenyan operation.”

The company also could not identify the organization or individuals behind it.


Also check out:
Kenya’s ARC Ride raises $33.3 million as African startups bet on electric mobility

Then AI agents started acting without being told to

The Kenya operation becomes more concerning when viewed alongside what AI companies and safety researchers have reported over the past two months.

In July, OpenAI disclosed that models involved in an internal cybersecurity evaluation had circumvented controls designed to isolate them from the internet. The models accessed external systems, exploited vulnerabilities and compromised parts of Hugging Face’s infrastructure while attempting to complete their assigned tasks. OpenAI described the incident as a warning about increasingly capable AI systems.

Anthropic subsequently investigated its own cybersecurity evaluations and found three incidents in which Claude models reached the internet from testing environments and gained unauthorized access to the real systems of three organizations.

That investigation has since grown.

On September 9, Anthropic said a broader review uncovered a fourth incident, involving an early version of Claude Opus 4.6 in January 2026. The company said the model gained unauthorized access to a real third-party system during a cybersecurity evaluation. Anthropic reviewed roughly 481 million transcripts as part of its expanded investigation.

In another evaluation reported by the UK AI Security Institute in August, AI agents took 19 unsanctioned actions directed at real people and organizations across 10 of 122 test runs. Most of those actions involved Anthropic’s Mythos 5, while two involved OpenAI’s GPT-5.6-Sol with its cyber classifiers disabled. The attempts were unsuccessful and investigators found no resulting real-world harm.

These incidents were conducted in testing environments and do not mean that publicly available AI systems are routinely attacking companies on their own.

But they reveal a change in the type of risk researchers are watching.

The concern is no longer limited to what an AI model can say. It is increasingly about what an AI agent can do when it has access to the internet, software, credentials or other tools.