AI-driven cyberattacks growing more autonomous, harder to assess: Anthropic report

Share:
Audio Loading voice…
AI-driven cyberattacks growing more autonomous, harder to assess: Anthropic report

Synopsis

Anthropic's year-long analysis of over 800 banned accounts reveals AI is no longer just a prep tool for hackers — it is now driving autonomous, multi-stage attacks with minimal human input. Medium-to-high-risk actors nearly doubled in a year, and existing frameworks like MITRE ATT&CK are struggling to keep pace.

Key Takeaways

Anthropic banned over 800 accounts for malicious cyber activity between March 2025 and March 2026 .
Around 67 per cent of analysed accounts used AI for attack preparation, including malware development.
Medium-risk or higher threat actors rose from 33 per cent to 56 per cent within the study period.
AI-assisted phishing declined, while post-compromise activities like account discovery and lateral movement increased.
Attackers are deploying AI to chain multiple attack stages autonomously, with limited human intervention.
Existing frameworks including MITRE ATT&CK are reportedly inadequate for capturing AI-enabled, agentic threats.

Artificial intelligence is making cyberattacks increasingly autonomous, enabling threat actors to execute more sophisticated operations and fundamentally challenging traditional cybersecurity frameworks, according to a new analysis by Anthropic. The findings, covering a period from March 2025 to March 2026, signal a significant shift in how AI is being weaponised across the full cyberattack lifecycle.

Scale of the Threat

Anthropic's analysis identified over 800 accounts that were banned for malicious cyber activity during the study period. The data reveals that attackers are no longer limiting AI use to the early stages of an operation. Around 67 per cent of the analysed accounts used AI for attack preparation activities, including malware development — but the more alarming trend lies in what happens after initial access is gained.

The report found a marked shift towards operationally complex, post-compromise activities, including account discovery and lateral movement within compromised systems. Meanwhile, AI-assisted phishing activity declined, suggesting that threat actors are reserving AI's capabilities for deeper, harder-to-detect intrusion stages.

Rising Threat Levels

The data points to a rapid escalation in attacker capability. Actors classified as medium-risk or higher rose from 33 per cent in the first half of the analysis period to 56 per cent in the second half — a near doubling in under a year. Anthropic's report stated directly: 'We found evidence consistent with AI being used to help increase the threat level of attackers.'

Notably, this escalation is not confined to elite state-sponsored actors. AI is reportedly enabling lower-skilled operators to perform technically complex operations that would previously have required significant expertise, blurring the traditional lines between novice and advanced persistent threats.

Autonomy and the New Attack Architecture

A key concern flagged in the report is the growing autonomy of AI-driven attacks. Anthropic warned that attackers are deploying AI systems capable of chaining together multiple stages of an attack with limited human intervention. This shift towards agentic attack architectures — where AI agents make tactical decisions, orchestrate attack stages, and execute actions independently — represents a qualitative change in the threat landscape.

This is particularly significant because it compresses the time window available for defenders to detect and respond to intrusions, reducing the effectiveness of human-in-the-loop security operations.

Existing Frameworks Falling Short

The report argues that widely used cybersecurity frameworks, including MITRE ATT&CK, do not fully capture AI-enabled threats. Existing models were built around human-directed attack patterns and struggle to account for AI agents capable of autonomous tactical decision-making. Traditional indicators used to assess attacker sophistication are also becoming less reliable as AI levels the playing field for lower-skilled actors.

Security defenders worldwide are facing a moving target, with rapidly evolving AI capabilities continuously reshaping the threat environment and outpacing the update cycles of conventional defence frameworks.

What Security Teams Must Watch

The findings carry direct implications for enterprise security teams and national cybersecurity agencies. The shift from AI-assisted preparation to AI-enabled post-compromise activity means that perimeter defences and phishing filters alone are insufficient. Organisations will need to invest in behavioural detection capabilities that can identify anomalous lateral movement and account discovery patterns driven by autonomous agents, rather than relying solely on signature-based or rule-based detection systems. How quickly the security industry adapts its frameworks and tooling to this new reality will determine the cost of the next generation of breaches.

Point of View

Defenders are essentially using an outdated map for a terrain that has already changed.
NationPress
22 Jul 2026

Frequently Asked Questions

What did Anthropic's cybersecurity report find?
Anthropic's analysis found that AI is increasingly being used to make cyberattacks more autonomous and sophisticated, with over 800 accounts banned for malicious activity between March 2025 and March 2026. The report shows attackers are using AI beyond initial preparation, extending into post-compromise activities like lateral movement within systems.
How much did AI-enabled threat levels rise in the study period?
Actors classified as medium-risk or higher increased from 33 per cent in the first half of the analysis period to 56 per cent in the second half — a near-doubling within a single year, according to the Anthropic report.
Are lower-skilled hackers now more dangerous because of AI?
Yes, according to the report. Traditional indicators used to assess attacker sophistication are becoming less reliable as AI enables lower-skilled actors to perform technically complex operations that previously required advanced expertise.
Why are existing cybersecurity frameworks like MITRE ATT&CK falling short?
The report argues that frameworks like MITRE ATT&CK were designed around human-directed attack patterns and do not fully account for AI agents capable of autonomous tactical decision-making, orchestrating multi-stage attacks with limited human intervention.
What type of AI-driven activity is increasing most among attackers?
Post-compromise activities — including account discovery and lateral movement within compromised systems — are increasing the most. AI-assisted phishing, by contrast, has declined, suggesting attackers are shifting AI use to deeper, harder-to-detect stages of intrusion.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 6 days ago
  2. 1 month ago
  3. 1 month ago
  4. 1 month ago
  5. 2 months ago
  6. 2 months ago
  7. 4 months ago
  8. 1 year ago
Google Prefer NP
On Google