Back to the news portal
Security & DefenceVerified reportMulti-source analysisGlobal securityUnited States
Translation is temporarily unavailable. The UK English original is shown below. UK English original.

AI is scaling cyber work for attackers and defenders—and evidence quality matters

Anthropic describes disrupted misuse campaigns while Palo Alto Networks launches continuous AI-led testing. Both sides are automating more of the workflow, but provider case studies do not reveal the full threat rate.

By The Impact of AI Editorial DeskReleased 24 September 2026 at 09:00 BST4 min read2 sources

Editorial responsibility: The Impact of AI Editorial Desk · Report a factual concern

Natural narration · full article · 5 min0%

Reads the full article in a natural voice. First play may take a moment to prepare.

ShareLinkedInX

At a glance

  • 1AI is being used to organise repeatable campaigns, not only to write individual messages or code snippets.
  • 2Defenders are responding with continuous AI-assisted testing, which can shorten discovery but also creates powerful system access.
  • 3Provider reports show real cases, but they are selected samples and cannot establish how common AI-enabled attacks are overall.

Living evidence record

Impact record IAI-0ARFB1D

Explore the full tracker

Evidence stage

Observed

Confidence

Supported

Reporting basis

Multi-source analysis

Independent support

Present

Record status

Updated

Last checked

27 September 2026

Source trail

2 direct sources across 2 source types.

People impact

Documented in this record.

Uncertainty

Limits and next checks are explicit.

Stages describe the evidence available—not whether a technology is good or bad. See the public method.

What the misuse report adds

Anthropic's September threat-intelligence report describes accounts and operations the company says it detected and disrupted across seven areas, including cyber activity, scams, surveillance, influence operations and attempts to copy model capabilities. The important change is not simply that a model can draft a phishing message. It is that an actor can use AI to organise research, content production, technical steps and repeated adaptation inside a broader campaign.

That can lower the amount of expertise or time needed for some operations and allow a small group to produce more variants. It does not make every attack sophisticated. Models can still produce incorrect code, miss context or trigger safeguards. The effect is best understood as uneven acceleration: parts of reconnaissance, translation, scripting and persuasion become faster, while access, operational security and exploitation may still require experienced people.[1]

Defenders are automating the same cycle

Reuters reports that Palo Alto Networks plans a service using cyber-focused models from Anthropic and OpenAI alongside open models to test web applications, APIs and cloud infrastructure continuously. The company says the system will identify weaknesses and attack paths as environments change, then suggest code fixes or virtual patches. Annual pricing will depend on the selected mix of models.

Continuous testing addresses a genuine gap: a yearly penetration test can become stale as soon as an application changes. AI may help defenders explore more paths and translate findings into remediation. Yet a testing agent needs extensive visibility and sometimes the ability to interact with sensitive systems. If compromised or poorly scoped, it becomes a new privileged asset. Customers should examine isolation, credentials, data retention, validation and how suggested fixes are reviewed before execution.[2]

How to interpret provider evidence

Threat reports from model providers offer visibility that outside researchers cannot easily obtain. Providers see prompts, account patterns and safeguard triggers across their own services. But published cases are curated. They may emphasise successful detection, omit activity on other platforms and use categories that are difficult to compare over time. They do not supply a denominator showing how many ordinary interactions occurred or how AI-assisted cases compare with non-AI crime.

Commercial security announcements have a different incentive: they explain a product's intended capability before customers have accumulated independent operating evidence. The right response is neither dismissal nor automatic acceptance. Organisations should use the reports to update threat models, then demand measurable tests, incident disclosures and independent assessment.[1][2]

What organisations can do now

Basic controls remain valuable. Staff accounts should have the minimum authority required, high-risk tool calls should require approval and agent actions should be logged in a form investigators can reconstruct. Organisations should inventory public-facing applications and APIs, patch exposed systems, protect secrets from model context and simulate prompt-injection or compromised-data scenarios. Security teams need a stop mechanism that works even when the agent's own interface is unavailable.

Defence also depends on people. Employees need an easy route to report suspicious communication without blame. Developers need secure defaults and time to repair findings. Leaders should distinguish a demonstrated compromise from a model-generated possibility so that continuous scanning does not overwhelm teams with noise. Faster discovery helps only when remediation capacity keeps pace.[1][2]

What this means for people

  • Individuals may face more convincing, personalised scams across languages, making trusted verification channels more important.
  • Security staff could find vulnerabilities faster but may also receive more alerts and pressure unless findings are prioritised well.
  • Customers and employees need prompt notification and practical support when AI-enabled systems contribute to a breach.

Global context

AI-enabled fraud and cyber operations cross borders quickly, while reporting duties and law-enforcement capacity differ. Provider visibility is concentrated in a few US companies, so global understanding also requires local incident reporting, multilingual research and cooperation with regional responders.

What the evidence does not yet show

  • Anthropic's cases are a provider-selected sample and cannot establish prevalence across the wider internet.
  • The Palo Alto service description is a launch announcement; independent evidence of effectiveness in production is not yet presented here.

What to watch next

  • Comparable incident statistics that separate AI-assisted activity from conventional cybercrime.
  • Independent red-team results and customer evidence for continuous AI security testing.
  • Standards for logging, disclosure and responsibility when defensive agents take or recommend consequential action.

Evidence trail

Sources used for this report

Links checked 27 September 2026

This report is labelled multi-source analysis. We summarise and analyse source material in our own words; company statements remain attributed claims until independently supported. Translated summaries preserve the meaning of the original source and link back to it. Read our editorial standards.

Continue the story

Related reporting

All reports

Reader discussion

Add evidence, experience or a question

No account is required. Reader notes are published after a brief civility, relevance and safety check; disagreement is welcome.

Do not include personal, confidential or unlawful information.

Published reader notes

0

No published reader notes yet. You can start the evidence-led discussion above.

Prefer a private correction or response? Contact the newsroom.