Anthropic says it detected and disrupted attempts to misuse its systems across cyber operations, influence campaigns, surveillance, scams and other harmful activity between December 2025 and August 2026. The report is valuable because it offers concrete cases. It also needs to be read with the right caveat: these are selected incidents described by the company operating the service, not a measurement of all AI misuse on the internet.
Quick scan
In brief
The report covers seven categories of harmful activity and cases observed from December 2025 through August 2026.
The examples describe AI as one component inside wider operations, often used for research, translation, scripting or persuasion.
Anthropic says it disrupted the activity it describes; the report does not establish how common each pattern is across other models or platforms.
The operational change is compression
Most of the cases do not depend on a brand-new criminal capability. They compress work that already existed. A fraud operator can draft several tones of a message, translate it, inspect a target’s public profile and refine a response without moving between specialist tools. A low-skill attacker can ask for explanations of a script and iterate faster. That is a meaningful change even when the underlying tactic is old.
This distinction matters because the dramatic framing — autonomous agents attacking everything on their own — can hide the more immediate risk. The practical near-term problem is throughput. A person who once managed a handful of conversations can potentially manage many more, with better grammar and faster adaptation. Detection systems built around crude language or obvious templates become less reliable.
Where the report is strongest — and where it is not
The strongest parts are the workflow descriptions. They show where a model entered the chain, what the operator asked it to do and how the provider responded. That is more useful to defenders than a raw count because it suggests controls: rate limits, monitoring for repeated high-risk transformations, stronger identity signals and better escalation paths between platforms.
The report cannot tell us the denominator. We do not know what share of harmful attempts these examples represent, how many succeeded before they were stopped or how the same actors use systems outside Anthropic. Provider reports also naturally emphasize the incidents their own tooling can observe. Readers should treat the document as a casebook, not a census.
Evidence map
What to separate
| Layer | Focus | What the evidence says |
|---|---|---|
| Signal | The operational change is compression | Most of the cases do not depend on a brand-new criminal capability. |
| Constraint | Where the report is strongest — and where it is not | The strongest parts are the workflow descriptions. |
| Proof point | What changes for ordinary users | The sensible response is not to distrust every polished message. |
What changes for ordinary users
The sensible response is not to distrust every polished message. It is to move verification away from writing style. A message can be fluent and still be fraudulent. Check a request through a second channel, navigate to an account directly instead of using a supplied link and slow down when a conversation introduces urgency, secrecy or an unexpected payment method.
Organizations should make those verification paths obvious before an incident. Publish the domains you use, give customers a simple way to report suspicious messages and design support flows that do not train people to disclose one-time codes. AI makes persuasion cheaper; clear institutional habits make successful persuasion harder.
The next question to watch
The most important unresolved issue is whether providers can share abuse signals without creating a new privacy problem. Cross-platform campaigns are difficult to see from a single service. Yet broad data sharing can expose legitimate users or create opaque enforcement systems. Useful progress will require narrow, auditable indicators and transparent appeal mechanisms, not simply more collection.
For now, the report is a reminder that AI safety is partly a product-operations discipline. Model behavior matters, but so do account controls, incident response, identity, user education and the mundane design of a warning that appears at the right moment.



