Anthropic’s new Threat Intelligence Report is a useful reminder that the most consequential AI-security stories are not always about a model’s benchmark score. The company says it identified and disrupted attempts to use Claude for malicious activity between December 2025 and August 2026. The cases span seven harm areas: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional-weapons development and model distillation.
That scope makes the report more than a technical incident roundup. It offers a company’s view of where generative AI is being worked into harmful workflows—and where defenders may need to look next. It also deserves to be read with a clear limitation in mind: the report is Anthropic’s account of activity it says it found and disrupted, not an independent measure of how common these behaviors are across the AI industry.
From assistance to operational scale
The report’s most important distinction is not that people are trying to misuse AI; that has been evident for years. It is that some actors are attempting to make a model part of an operational system rather than using it only as a drafting or coding assistant. In the cyber section, Anthropic says it disrupted activity involving suspected state-sponsored groups, financially motivated criminals and politically motivated individuals. The company frames the change as an expansion in the speed, scale and depth that an attacker can pursue.
Anthropic’s own account is more measured than an automated-doomsday narrative. It says people retained decisions that mattered most in the cases it describes, including target selection, monetisation and review of results. That distinction matters. Greater autonomy can reduce the cost and labour needed to run a campaign without independently determining the campaign’s ultimate severity. But lower operating costs can make more targets economically attractive, which is why the report is relevant to organisations that may never consider themselves a headline cyber target.
The Anthropic threat intelligence report’s seven harm areas
Across the report, the recurring problem is the conversion of a general-purpose capability into a repeatable workflow. Anthropic describes influence operations that used AI to help create deceptive social accounts, news sites and material aimed at public discourse. It also describes surveillance-related activity involving state-aligned actors, contractors and commercial spyware vendors, alongside fraud schemes such as fake dating applications. The biological and weapons sections are a reminder that risk management cannot be limited to software-security teams.
For readers, it is important not to treat each case as proof of a new normal. Anthropic says the examples are selected because they were among the most notable and novel activity it identified, rather than typical use. The report does, however, give defenders concrete categories to consider: abuse of access credentials, synthetic identities, malicious extensions, deceptive content at scale, and models used to shorten the path from a plan to an executable operation.
What Anthropic says it changed
Anthropic says that, in the cases covered, it disrupted the activity, strengthened safeguards and shared intelligence with authorities and industry partners where appropriate. In its surveillance section, the company says it banned associated accounts, improved detection for observed tactics, techniques and procedures, and shared identifiers when impacts went beyond its platform. Those claims describe the company’s response, not a public audit of its effectiveness. The report does not establish how many attempts were missed, how its controls compare with competitors’, or whether its mitigations will hold as models and attackers change.
That gap is precisely why transparency is part of the story. Unhyd’s recent coverage of Anthropic’s call for pacing and independent review focused on a separate proposal about how frontier AI development should be governed. This report supplies a different, more operational piece of context: the types of misuse a provider says it is seeing now. It does not validate the broader claims in that proposal, but it does make the question of credible outside scrutiny more concrete.
A practical implication for organisations
For companies deploying AI, the immediate lesson is not to assume that a policy document closes the risk. Teams need to know which systems can access sensitive data, what actions an agent can take, how anomalies are detected and how quickly access can be withdrawn. That is consistent with the UK National Cyber Security Centre’s recent warning on shadow AI in the workplace: unapproved tools and poorly governed access can create security blind spots even when employees are trying to work more efficiently.
The report is also a reason to separate two questions that are often collapsed. One is whether an AI system can be misused by a determined person. The other is whether a particular provider’s safeguards are working as claimed. Anthropic’s report is evidence about the first question and a self-reported account of its response to the second. Both are valuable, but neither substitutes for independent evaluation, incident reporting standards and ordinary security controls.
For now, the strongest takeaway is practical rather than sensational. AI can compress parts of harmful work, while people still supply goals, judgment and access. That makes permissions, monitoring, review and rapid revocation central to the safe deployment of capable systems—and makes transparent reporting from providers worth scrutinising rather than simply applauding.
Sources
Anthropic, “Detecting and countering misuse of AI: September 2026”.