Post

Countering Misuse of AI - September 2026

Countering Misuse of AI - September 2026

Countering Misuse of AI - September 2026

Source: Anthropic
Date Published: September 11, 2026

Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity. This report covers activity we disrupted between December 2025 and August 2026 across seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and distillation. Claude Haiku, Sonnet, and Opus models were used. The threat actors covered in this report include suspected state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions, and politically motivated individuals. The cases range from a network of fake dating apps designed to defraud users to surveillance systems built to identify and monitor dissidents. In each case, we disrupted the activity, used what we learned to strengthen our safeguards, and shared intelligence with authorities and industry partners, where appropriate.

Key Findings

Regarding AI-augmented cyber operations, Anthropic’s Threat Intelligence team identified and disrupted a series of operations in which threat actors used Claude over the past six months. These actors included suspected state-sponsored groups, financially motivated criminals, and politically motivated individuals. While many commentators focus on the risk of AI developing exploits at scale, the report notes this is a danger, but the risk from AI adoption is more pronounced across the cyber kill chain, where adversaries can operate faster, across a broader and deeper surface area, with fewer resources.

A key trend observed is that sophisticated attacks no longer require sophisticated attackers. The cybersecurity skills of AI models mean that AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators. Every layer of offensive operations has been uplifted by AI, from reconnaissance and tool development to data processing and exploitation. Furthermore, in November 2025, we documented an operating model used by a suspected state-sponsored campaign to carry out autonomous attacks. That operating model has now proliferated across every class of actors we investigated. Publicly available offensive agent frameworks, like PentAGI, reproduce much of the same scaffolding for anyone who downloads them, effectively automating each step of the cyber kill chain.

Additionally, AI’s role in cyber operations has become increasingly autonomous. A majority of the operations described in this report were enabled by AI via direct execution or orchestration. The use of AI went beyond simple questions and responses from a chatbot but rather involved the use of multi-agent frameworks executing reconnaissance, exploitation, and data exfiltration. Humans remained in the loop by setting the targets of attacks and reviewing exfiltration. An example of this trend is GTG-20006, an actor who developed an AI-assisted workflow that automatically rebuilt and re-deployed their toolkit if it was detected by security products.

For more details, you can read the complete article here: Read full article


This post is licensed under CC BY 4.0 by the author.