AI is scaling cyber work for attackers and defenders—and evidence quality matters
Anthropic describes disrupted misuse campaigns while Palo Alto Networks launches continuous AI-led testing. Both sides are automating more of the workflow, but provider case studies do not reveal the full threat rate.
Editorial responsibility: The Impact of AI Editorial Desk · Report a factual concern
Reads the full article in a natural voice. First play may take a moment to prepare.
At a glance
- 1AI is being used to organise repeatable campaigns, not only to write individual messages or code snippets.
- 2Defenders are responding with continuous AI-assisted testing, which can shorten discovery but also creates powerful system access.
- 3Provider reports show real cases, but they are selected samples and cannot establish how common AI-enabled attacks are overall.
Living evidence record
Impact record IAI-0ARFB1D
Evidence stage
Observed
Confidence
Supported
Reporting basis
Multi-source analysis
Independent support
Present
Record status
Updated
Last checked
27 September 2026
Source trail
2 direct sources across 2 source types.
People impact
Documented in this record.
Uncertainty
Limits and next checks are explicit.
Stages describe the evidence available—not whether a technology is good or bad. See the public method.
What the misuse report adds
Anthropic's September threat-intelligence report describes accounts and operations the company says it detected and disrupted across seven areas, including cyber activity, scams, surveillance, influence operations and attempts to copy model capabilities. The important change is not simply that a model can draft a phishing message. It is that an actor can use AI to organise research, content production, technical steps and repeated adaptation inside a broader campaign.
That can lower the amount of expertise or time needed for some operations and allow a small group to produce more variants. It does not make every attack sophisticated. Models can still produce incorrect code, miss context or trigger safeguards. The effect is best understood as uneven acceleration: parts of reconnaissance, translation, scripting and persuasion become faster, while access, operational security and exploitation may still require experienced people.[1]
Defenders are automating the same cycle
Reuters reports that Palo Alto Networks plans a service using cyber-focused models from Anthropic and OpenAI alongside open models to test web applications, APIs and cloud infrastructure continuously. The company says the system will identify weaknesses and attack paths as environments change, then suggest code fixes or virtual patches. Annual pricing will depend on the selected mix of models.
Continuous testing addresses a genuine gap: a yearly penetration test can become stale as soon as an application changes. AI may help defenders explore more paths and translate findings into remediation. Yet a testing agent needs extensive visibility and sometimes the ability to interact with sensitive systems. If compromised or poorly scoped, it becomes a new privileged asset. Customers should examine isolation, credentials, data retention, validation and how suggested fixes are reviewed before execution.[2]
How to interpret provider evidence
Threat reports from model providers offer visibility that outside researchers cannot easily obtain. Providers see prompts, account patterns and safeguard triggers across their own services. But published cases are curated. They may emphasise successful detection, omit activity on other platforms and use categories that are difficult to compare over time. They do not supply a denominator showing how many ordinary interactions occurred or how AI-assisted cases compare with non-AI crime.
Commercial security announcements have a different incentive: they explain a product's intended capability before customers have accumulated independent operating evidence. The right response is neither dismissal nor automatic acceptance. Organisations should use the reports to update threat models, then demand measurable tests, incident disclosures and independent assessment.[1][2]
What organisations can do now
Basic controls remain valuable. Staff accounts should have the minimum authority required, high-risk tool calls should require approval and agent actions should be logged in a form investigators can reconstruct. Organisations should inventory public-facing applications and APIs, patch exposed systems, protect secrets from model context and simulate prompt-injection or compromised-data scenarios. Security teams need a stop mechanism that works even when the agent's own interface is unavailable.
Defence also depends on people. Employees need an easy route to report suspicious communication without blame. Developers need secure defaults and time to repair findings. Leaders should distinguish a demonstrated compromise from a model-generated possibility so that continuous scanning does not overwhelm teams with noise. Faster discovery helps only when remediation capacity keeps pace.[1][2]
What this means for people
- Individuals may face more convincing, personalised scams across languages, making trusted verification channels more important.
- Security staff could find vulnerabilities faster but may also receive more alerts and pressure unless findings are prioritised well.
- Customers and employees need prompt notification and practical support when AI-enabled systems contribute to a breach.
Global context
AI-enabled fraud and cyber operations cross borders quickly, while reporting duties and law-enforcement capacity differ. Provider visibility is concentrated in a few US companies, so global understanding also requires local incident reporting, multilingual research and cooperation with regional responders.
What the evidence does not yet show
- Anthropic's cases are a provider-selected sample and cannot establish prevalence across the wider internet.
- The Palo Alto service description is a launch announcement; independent evidence of effectiveness in production is not yet presented here.
What to watch next
- Comparable incident statistics that separate AI-assisted activity from conventional cybercrime.
- Independent red-team results and customer evidence for continuous AI security testing.
- Standards for logging, disclosure and responsibility when defensive agents take or recommend consequential action.
Evidence trail
Sources used for this report
Links checked 27 September 2026
This report is labelled multi-source analysis. We summarise and analyse source material in our own words; company statements remain attributed claims until independently supported. Translated summaries preserve the meaning of the original source and link back to it. Read our editorial standards.
Continue the story
Related reporting
Security & Defence
Palo Alto Networks launches continuous AI-led exposure testing
The company says Unit 42 will combine frontier models with security expertise to find and validate weaknesses. Independent evidence of coverage, false positives and remediation outcomes is still needed.
5 min · 2 sources
Security & Defence
UK AI Security Institute maps how frontier capabilities are changing
The AI Security Institute's Frontier AI Trends Report consolidates evaluations of model capability and safeguards to show where performance is improving and where risk evidence remains incomplete.
4 min · 1 source
Security & Defence
NATO DIANA selects dual-use technologies for decision support
NATO's Defence Innovation Accelerator selected innovators working on technologies intended to improve decision advantage, including AI-enabled sensing, analysis and resilient communications.
4 min · 1 source
Reader discussion
Add evidence, experience or a question
No account is required. Reader notes are published after a brief civility, relevance and safety check; disagreement is welcome.
Published reader notes
0No published reader notes yet. You can start the evidence-led discussion above.
Prefer a private correction or response? Contact the newsroom.