# Anthropic's threat report shows several levels of attacker autonomy

> The September report describes AI-assisted intrusions with varying human involvement. The response should focus on access and observable behaviour.

Source: https://fmcybersecurity.com/en/insights/ai-security/anthropic-report-five-groups-ran-ai-agents-on-real-targets/
Locale: English
Other locale: https://fmcybersecurity.com/insights/ai-security/anthropic-rapport-fem-grupper-kjorte-ai-agenter-mot-ekte-mal/

## Metadata

- Date: 2026-09-11
- Author: fredrik-standahl
- Topic: ai-security
- Format: news
- Scope: international

*The cover image is an AI-generated editorial illustration. Screens and documents are illustrative concepts.*

[Anthropic's September threat report](https://www.anthropic.com/threat-intelligence-report-september-2026) describes AI use in real intrusion campaigns, from assisted tool development to agents executing extended workflows. The company also stresses that humans retained important decisions, including targeting and monetisation.

That distinction makes the report more useful. “Autonomous” is not a single category, and greater autonomy does not automatically mean greater harm. An operator directing each step can still cause a serious breach.

## Ask which part of the work became easier

For a defender, it matters whether AI helped write a tool, select an approach or run activity against a system. Those uses can affect different parts of the response.

We recommend mapping the reported behaviour to your own exposed services and identities. Which access would make the sequence possible? What would be visible? Who could interrupt it?

An impressive account of agent coordination should not distract from a straightforward weakness that remains unresolved. Check the relevant system before turning the report into a general claim that all existing security has failed.

## Include your own AI access in the review

The business's AI tools also need clear permissions. Record which services and data an assistant can reach, which credentials it uses and whether it can take consequential actions without approval.

This is a separate issue from an external attacker using AI, but both deserve attention. An inventory of approved chatbots does not describe the capabilities of connected agents.

Finally, examine response outside normal working hours. Use a scenario based on a system you operate and trace the handovers from detection to containment. Google's [credential-harvesting case](/en/insights/ai-security/ai-agents-six-hour-credential-harvest/) provides another reason to examine those delays.

The most useful outcome from a threat report is a specific change you can verify, not a stronger adjective in the risk register.

---

For the full documentation index, see https://fmcybersecurity.com/llms.txt
For the complete corpus as a single document, see https://fmcybersecurity.com/llms-full.txt
