Back to Blog
AI Security

Anthropic's AI Misuse Report: Agents Do the Work, Humans Steer

Anthropic's report on detected Claude misuse describes AI agents handling reconnaissance, exploitation and data theft while humans pick targets and review output. Here is what security teams should take from it.

PyramidLedger Research3 min read
Share

Key Takeaways

  • Anthropic's report describes AI agents handling reconnaissance, exploitation, data theft and research, while humans select targets, set goals and review important outputs.
  • The reported activity includes industrialised credential theft, cloud compromise, phishing and vulnerability research, plus extraction of sensitive data from downstream organisations.
  • Influence operations in the report used agent memory, synthetic personas and multilingual content at scale, though engagement remained limited.
  • For defenders, the practical change is tempo and scale rather than a new class of attack, so basic hygiene and detection speed matter more.

What the report says

Earlier this month Anthropic published a long report detailing the misuse of Claude that it detected. Bruce Schneier flagged it, and Daniel Miessler condensed it into 117 findings. We have worked from those two summaries and the report itself, and we cite only what they state.

The central pattern is a division of labour. AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows and research, while humans selected targets, set goals and reviewed important outputs. The human is still in the loop, but mostly as a supervisor.

Where attackers applied it

  • Intrusion tradecraft: the report describes attackers using AI to industrialise credential theft, cloud compromise, phishing and vulnerability research, and to extract sensitive data from downstream organisations.
  • Influence operations: persistent agent memory, fabricated news outlets, synthetic personas, political profiling and multilingual content at scale. Engagement remained limited.
  • Surveillance and repression: automated dossier creation, biometric analysis, communications monitoring, transnational targeting and coercive recruitment.
  • Dual-use science: AI supported advanced scientific and military research, but the report found no evidence of completed biological weapons or active battlefield deployment.

Why it matters to defenders

Nothing in the summaries suggests a novel exploit class. Credential theft, phishing and cloud compromise are familiar problems. What changes is throughput. If an agent can run reconnaissance and first-pass exploitation continuously, the cost of probing each additional organisation falls, and the low-hanging fruit gets found faster.

The mention of downstream organisations also deserves attention. Data extracted from one compromised environment can expose its customers and suppliers, which raises the stakes for third-party and supply-chain risk assessments.

Practical takeaways

  1. 1Treat credentials and cloud identity as the primary battleground: enforce phishing-resistant MFA, review long-lived keys and alert on anomalous token use.
  2. 2Shorten patch and exposure-management cycles, because vulnerability research is one of the activities reported as AI-assisted.
  3. 3Assume phishing will be fluent and multilingual, and rely on controls that do not depend on spotting bad grammar.
  4. 4Map which of your suppliers hold your data, and what they would do if compromised.
  5. 5Include AI-assisted attackers in your threat models and exercises, so that detection and response are tested at machine tempo.

Caveats

This is a vendor's account of what it detected on its own platform. It cannot show what happens on other models or self-hosted tooling, and it likely undercounts activity that went unnoticed. It is still a useful primary data point on how attackers are working with AI agents in practice, and it is worth reading in full rather than through summaries.

Frequently Asked Questions

What did Anthropic's misuse report find?

According to the summaries, AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows and research, while humans chose targets, set goals and reviewed important outputs.

Did the report find AI-enabled biological weapons?

No. The report notes dual-use risks in advanced scientific and military research, but found no evidence of completed biological weapons or active battlefield deployment.

What should security teams do differently?

Focus on fundamentals at higher tempo: phishing-resistant MFA, cloud identity hygiene, faster patching, third-party risk review, and incident-response exercises that assume AI-assisted attackers.

Sources

  1. 1On Anthropic's AI Misuse Report — Schneier on Security
  2. 2Anthropic: Detecting and countering misuse (report PDF) — Anthropic
  3. 3Anthropic Misuse Report, September 2026: 117 findings — Daniel Miessler
Share

Read next