Countering Misuse of AI — Threat Intelligence Report, September 2026

usefulAnthropicreport2026-09read ai llmssoftware engineeringsecurity

Synopsis

Anthropic’s fourth public threat report, covering December 2025 to August 2026. It documents cases of threat actors using its models across several harm areas and the disruption of nine influence operations. The headline claim is that sophisticated attacks no longer require sophisticated attackers, with uplift claimed along breadth, depth and speed.

Two findings underneath that are more interesting than the headline. Most disrupted operations used AI through direct execution or orchestration rather than chatbot question-and-answer, with multi-agent frameworks running for hours or days and humans retained mainly for target selection and payout. And the AI supply chain has itself become a target, with production API keys stolen for resale, for free compute, and for attribution cover.

Where I land

I did not have a position on this when I filed it, and working through it gave me one.

This is evidence for the guardrails argument from an unexpected direction. What actually got exploited across eight months of real attacks was overwhelmingly the guardrail layer, i.e. credentials, tools, sandboxes and supply chain. Almost none of it was model intent. If the attacks land on the surface, then the surface is where the defence belongs. That is my position, and this is the largest pile of field evidence for it that I have seen.

I still distrust the framing. Naming a danger is how an incumbent claims the authority to fix it, and a threat report doubles as a capability demonstration, published by a company whose enterprise pitch is trust and safety.

However, my own test cuts against dismissing it. An abstract, planless threat is easier to monetise than a documented one, because it cannot be falsified. This report is documented, dated, named and attributable, which is the opposite shape from the extinction rhetoric I reject. Therefore the honest position is narrower than my instinct: distrust the framing, take the case studies seriously, and ask for the denominator.

Connections

Related: The OWASP Top 10 for AI Agents (ASI Top 10), The Biggest AI Fraud Is the One Nobody Is Investigating