BITTER WINTER

No Uyghur Is Beyond Reach: AI and Beijing’s New Machinery of Transnational Repression

by | Sep 18, 2026 | Testimonies China

From WhatsApp groups and diaspora media to Türkiye and Syria, the Anthropic report reveals how technology expands Beijing’s repression.

by Asiye Uyghur

Uyghurs across the diaspora use digital platforms to maintain family and community connections—but the same communications can be transformed into tools of surveillance, profiling, and transnational repression. AI-generated.
Uyghurs across the diaspora use digital platforms to maintain family and community connections—but the same communications can be transformed into tools of surveillance, profiling, and transnational repression. AI-generated.

For Uyghurs, leaving our homeland has never necessarily meant escaping Beijing’s reach. The borders crossed by refugees, journalists, activists, and ordinary families do not prevent surveillance, intimidation, or pressure through relatives who remain behind. Exile may provide physical distance, but it has not always brought genuine security.

Anthropic’s new threat-intelligence report, discussed this week in “Bitter Winter,” shows that this already extensive system of transnational repression is entering a new phase. Artificial intelligence does not merely provide Beijing-aligned actors with another propaganda tool. It can help them collect information from entire communities, connect identities across different platforms, identify personal vulnerabilities, locate individuals in the physical world, conduct deceptive conversations in languages they do not speak, and prepare campaigns to silence independent Uyghur voices.

The report should therefore not be read only as a story about the misuse of Claude, Anthropic’s AI model. Nor is it simply a story about several journalists or one armed group in Syria. It reveals the emerging infrastructure of a system capable of treating the worldwide Uyghur population as one continuously monitored target.

From Community Conversations to Intelligence Files

According to Anthropic’s report, Detecting and countering misuse of AI: September 2026, a China-based actor extracted conversations from more than one hundred monitored WhatsApp groups and dozens of Telegram channels. Claude was then used to convert this material into structured Chinese-language data.

These were not merely general summaries of political discussions. The operation created profiles of individuals regarded as potentially vulnerable because of financial hardship, separation from their families, or ideological disillusionment. It specifically identified people who still had relatives in the Uyghur homeland.

That detail is crucial. Information about a person’s financial difficulties may support manipulation. Knowledge of family separation may enable emotional pressure. But identifying relatives who remain under Beijing’s rule introduces another form of leverage—one that, as Anthropic itself observed, can only be effectively exploited through coordination with the PRC’s domestic security system.

For Uyghurs, this is a familiar method. Relatives in the homeland have long been turned into instruments through which those abroad can be intimidated, silenced, or pressured to provide information. What AI changes is the scale and efficiency of the process. Information once gathered and examined manually can now be extracted, translated, categorized, cross-referenced, and turned into targeting profiles by a small number of operators.

As a Uyghur journalist who has lived in Europe for many years, I have heard directly how this coercion enters the private lives of Uyghurs abroad. One Uyghur I knew told me that, during a video call with their parents in the homeland, a police officer was standing beside them. According to this person, the officer demanded that they collect information inside the Uyghur community abroad. The officer also warned that, before becoming involved in activities the authorities considered inappropriate, they should think about the safety of their parents and other relatives in the homeland. Unsure how to respond, the person asked me for advice. I urged them to reject the demand, because cooperating even once could draw them into an escalating cycle of coercion that would become increasingly difficult to escape. After that conversation, however, all contact between us abruptly stopped. I still do not know what happened to this person, and I cannot infer what choice they ultimately made.

On another occasion, an acquaintance whom I had known for many years but had not spoken to for a long time called me late at night. When I answered, they were crying so intensely that they could not speak for some time. They eventually told me that their mother had been detained in a camp without any legitimate reason and had later developed cancer. Her illness had reached its final stage. According to my acquaintance, the police were using her continued medical treatment as leverage, demanding information about Uyghurs abroad and warning that, if the acquaintance refused to cooperate, the mother might die sooner. I tried to comfort them and advised them to disclose the case publicly, in the hope that international pressure could prevent the authorities from continuing to use their mother’s life as an instrument of coercion. After that call, this person also fell silent. I do not know what happened to the mother or what the acquaintance ultimately endured.

In both cases, contact stopped. Their silence does not prove that either person accepted the authorities’ demands. It does reveal one of the cruelest features of transnational repression: victims are often left alone with a choice in which no option feels safe. Refusing may expose relatives in the homeland to retaliation; complying may harm their own community and pull them deeper into a system they cannot easily leave. The danger revealed by Anthropic’s report is that AI can help those applying this pressure identify, much faster, who still has relatives in the homeland, who is under financial or psychological strain, and who may be most vulnerable to such coercion.

Private conversations thus become raw intelligence. Family relationships become fields in a database. Human suffering becomes a measurable “vulnerability.”

Uyghurs in the Syrian Army. From X.
Uyghurs in the Syrian Army. From X.

Syria as a Testing Ground

The most operationally advanced part of the case concerned Uyghurs in Syria. Anthropic assessed that the actor used Claude to track, profile, and attempt to recruit people believed to have access to Uyghur armed formations that had recently joined the newly formed Syrian Army. Some were offered money in return for information.

The actor did not speak Arabic. Claude nevertheless enabled the operation to communicate in a Syrian Arabic dialect, translate responses in real time, evaluate military terminology, and assess the psychology of the targets. It was even directed to act as an Arabic-speaking ‘expert’ who could check the credibility of the deception.

The reported targeting, however, extended beyond armed formations. The actor also sought to identify Uyghur civilians, businesses, locations, and other points of interest in Syria. Anthropic’s summary of the target set included armed formations, Uyghur civilian communities in Idlib Province, and Uyghur media and activists elsewhere in the world.

These categories must not be conflated. A civilian family, a business owner, a journalist, and a member of an armed formation are not interchangeable security targets. Yet the surveillance architecture described in the report placed all of them within the same broad field of collection.

This is precisely the danger. Beijing has long portrayed Uyghur identity, religious life, cultural activity, political expression, and overseas connections through the language of terrorism and security. AI-assisted surveillance makes it easier to extend this logic to an entire community, including civilians whose only “suspicious” characteristic may be their nationality, social connections, or presence in a particular location.

Syria may appear geographically distant from the Uyghur homeland, but the report shows that distance is increasingly irrelevant. A Chinese-speaking operator without Arabic skills could use AI to conduct localized outreach, construct credible cover stories, follow conversations in real time, locate people through maps and satellite imagery, and prepare the results for transfer further up an intelligence chain.

AI did not create the political objective. It removed many of the linguistic, technical, and staffing barriers that might previously have limited its execution.

Silencing the Rebuilt Uyghur Media

At the same time, the actor planned a separate campaign against Uyghur diaspora journalists, particularly those associated with “Uyghur Post.” The proposed methods included coordinated mass reporting, delegitimization through foreign fronts, and amplification by bot networks.

The choice of target is significant. “Uyghur Post” emerged after the closure of Radio Free Asia’s Uyghur Service, which had for decades played an indispensable role in reporting information that Beijing attempted to conceal.

As a former journalist with Radio Free Asia’s Uyghur Service, I understand the importance of independent Uyghur-language journalism. When a major institution disappears, the need for reliable reporting does not disappear with it. Journalists attempt to rebuild through smaller and more vulnerable platforms, often with fewer financial resources and weaker institutional protection.

The operation described by Anthropic appears to have recognized this vulnerability. Its objective was not simply to challenge individual articles. A coordinated reporting and bot-amplification campaign can attempt to have accounts suspended, overwhelm small media organizations, manufacture the appearance of public opposition, and destroy trust between journalists and their community.

This is not ordinary criticism. It is an attempt to manipulate the information environment surrounding a persecuted people.

The same data used to identify a journalist’s personal vulnerabilities can also be used to tailor attacks against that person’s reputation. A false allegation repeated by hundreds of coordinated accounts may acquire an artificial appearance of credibility. The victim must then spend time and energy defending against a controversy that never arose organically.

AI makes it possible to produce many versions of the same accusation, adapt them to different audiences and languages, and distribute them through apparently unrelated accounts. It can manufacture the illusion of a public consensus where none exists.

Uyghur protest in Washington DC. Credits.
Uyghur protest in Washington DC. Credits.

A Global System, Not an Isolated Operation

Other cases documented in Anthropic’s report reinforce the wider implications. China-based public- and state-security actors used Claude in ‘stability maintenance’ and transnational repression operations. They reportedly sought advance information about the locations and routes of overseas events, including Uyghur cultural activities in Türkiye, demonstrations in Vancouver, and screenings connected to the Oslo Freedom Forum.

Uyghur advocacy organizations were categorized within a security framework that associated their work with terrorism. Social-media and media content were processed into daily intelligence-style reports. In some cases, Claude helped produce government-formatted documents and recommendations for actions that only state authorities could carry out.

Taken together, these findings form a clear pattern:

  • community communications are harvested;
  • identities are connected across platforms;
  • personal and family vulnerabilities are mapped;
  • individuals and physical locations are identified;
  • deceptive approaches are adapted to local languages;
  • journalists and organizations are marked for delegitimization;
  • the results are prepared for security, propaganda, or commercial clients.

This is more than surveillance. It is a production chain linking collection, analysis, targeting, manipulation, and possible enforcement.

Anthropic assessed with low confidence that the actor targeting Uyghurs in Syria was a contractor working for PRC state security rather than a state-security organ acting directly. This attribution limitation should be respected. The available evidence does not allow every operator to be identified or every command relationship to be reconstructed.

Nevertheless, the operational priorities closely matched those of PRC state security. The actor identified relatives remaining in the Uyghur homeland, produced materials for bureau-level government clients, and used methods whose most coercive possibilities depended upon access to Beijing’s domestic security apparatus. Whether performed directly by an agency or outsourced to a contractor, the system served the same repressive objectives.

Outsourcing should not be confused with independence.

AI Is Industrializing an Existing Repression

The most important lesson is that artificial intelligence is not creating a new policy toward Uyghurs. It is industrializing an existing one.

The mechanisms are already familiar: surveillance, family pressure, infiltration, political labeling, manufactured allegations, and the systematic destruction of independent Uyghur voices. AI allows these practices to be conducted faster, across more platforms and languages, and with fewer people.

One operator can perform work that once required translators, researchers, data analysts, propaganda writers, and regional specialists. A vast volume of scattered personal information can be converted into a searchable map of a community. The target is no longer only the prominent activist whose name appears in international media. It may be anyone whose private messages, economic problems, family relationships, or community connections make them useful to an intelligence operation.

Anthropic states that it banned the accounts involved and is tracking their digital signatures. This intervention is important, but disabling several accounts cannot eliminate the wider threat. The methods can migrate to other commercial or open-source AI systems.

Technology companies should therefore establish mechanisms for notifying individuals and organizations that have been specifically targeted, while protecting sensitive investigative information. They should share relevant indicators with affected communities, human-rights organizations, digital-security specialists, and appropriate authorities. Platforms used for coordinated mass reporting and bot amplification must also recognize that their own complaint systems can be weaponized against vulnerable media.

Governments hosting Uyghur communities should treat AI-assisted surveillance, covert recruitment, intimidation through family members, and organized media suppression as forms of transnational repression—not as ordinary online disputes.

Most importantly, Uyghurs should not be left to discover these operations only after a technology company decides to publish a general report.

For years, Beijing has attempted to make geography meaningless for Uyghurs: a relative in the homeland can be used to silence a person in Europe; a cultural event in Türkiye can be entered into a security briefing; conversations in WhatsApp groups can be transformed into intelligence profiles; a journalist rebuilding Uyghur media in exile can be attacked by an artificial crowd; and a civilian or armed actor in Syria can be approached by someone who does not even speak the local language.

AI has not erased borders. It has enabled repression to cross them more efficiently.

The warning contained in Anthropic’s report is therefore not merely that Claude was misused. It is that the machinery targeting Uyghurs is becoming global, automated, and scalable. Unless democratic governments, technology companies, and civil society respond accordingly, no Uyghur—whether a journalist, activist, business owner, refugee, or ordinary member of a diaspora community—can safely assume that distance places them beyond Beijing’s reach.


NEWSLETTER

SUPPORT BITTER WINTER

READ MORE