For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/ai-security/anthropic-report-five-groups-ran-ai-agents-on-real-targets.md.
AI Security ↗

Anthropic's threat report shows several levels of attacker autonomy

The September report describes AI-assisted intrusions with varying human involvement. The response should focus on access and observable behaviour.

AI-generated illustration: Analyst comparing incident timelines and automated actions.

The cover image is an AI-generated editorial illustration. Screens and documents are illustrative concepts.

Anthropic’s September threat report describes AI use in real intrusion campaigns, from assisted tool development to agents executing extended workflows. The company also stresses that humans retained important decisions, including targeting and monetisation.

That distinction makes the report more useful. “Autonomous” is not a single category, and greater autonomy does not automatically mean greater harm. An operator directing each step can still cause a serious breach.

Ask which part of the work became easier

For a defender, it matters whether AI helped write a tool, select an approach or run activity against a system. Those uses can affect different parts of the response.

We recommend mapping the reported behaviour to your own exposed services and identities. Which access would make the sequence possible? What would be visible? Who could interrupt it?

An impressive account of agent coordination should not distract from a straightforward weakness that remains unresolved. Check the relevant system before turning the report into a general claim that all existing security has failed.

Include your own AI access in the review

The business’s AI tools also need clear permissions. Record which services and data an assistant can reach, which credentials it uses and whether it can take consequential actions without approval.

This is a separate issue from an external attacker using AI, but both deserve attention. An inventory of approved chatbots does not describe the capabilities of connected agents.

Finally, examine response outside normal working hours. Use a scenario based on a system you operate and trace the handovers from detection to containment. Google’s credential-harvesting case provides another reason to examine those delays.

The most useful outcome from a threat report is a specific change you can verify, not a stronger adjective in the risk register.

← Back to all insights
Questions or inquiry? [email protected] Contact us →