Anthropic's September threat-intelligence report offers one of the clearest recent looks at how capable AI systems are being used by real adversaries.
The company says its team identified and disrupted malicious activity between December 2025 and August 2026 across seven categories, including cyber operations, surveillance, influence operations, scams and fraud, biological misuse, conventional weapons activity and illicit model distillation.
The important cybersecurity point
The report argues that the most immediate risk is not limited to an AI model autonomously inventing a devastating exploit. Anthropic says the more visible effect today is acceleration across the entire cyber kill chain: reconnaissance, coding, debugging, phishing, analysis, automation and operational scale.
That distinction matters. A threat actor does not need a science-fiction breakthrough to become more dangerous. Reducing the number of people, time and specialized skills required for an operation can itself change the threat landscape.
Surveillance and influence operations
Anthropic also describes cases involving surveillance systems and influence networks. One section reports a network that produced thousands of politically slanted articles in multiple languages, while other cases involved systems designed to monitor activists, dissidents or communications.
These examples show why AI security cannot be treated as a narrow software-security issue. The same capabilities that make models useful for legitimate research, coding and automation can also lower the cost of surveillance, propaganda and fraud.
Why it matters
Threat reports from AI providers have an obvious limitation: the companies are describing activity they detect on their own platforms and deciding which cases to disclose. They are not a complete map of malicious AI use. But they provide valuable evidence about how abuse is actually evolving.
For defenders, the takeaway is practical: security programs should expect AI to increase adversary speed and breadth even when it does not create fundamentally new attack techniques.
This article summarizes Anthropic's own findings and labels our interpretation separately. See the editorial policy.