The cyber security impact of generative AI may be less about discovering a single new class of attack than about changing the economics of attacks that already exist. Anthropic’s latest threat intelligence report says it has identified malicious uses of Claude that move beyond conversational assistance into direct execution and multi-agent orchestration.

The report covers activity Anthropic says it identified and disrupted between December 2025 and August 2026. It includes examples involving reconnaissance, exploitation, data exfiltration, scams, fake personas and forged documents. In one deceptive dating-app operation, Anthropic says it found more than 4,700 distinct AI personas interacting with at least 25,000 people. The company cautions that the cases are notable examples rather than representative of normal Claude use.

That caveat matters. Provider threat reports show what a vendor has observed on its own platform and through its own investigations; they do not provide a complete picture of malicious AI use across the internet. Even so, the report is useful because it illustrates how automation can change the scale and labour requirements of offensive activity.

The Sovereign AI Reality Check- Governance, cost, and the limits of control
Carolyn Duby, Field CTO at Cloudera, joins Stewart Tinson for a candid look at what sovereign AI actually protects, and where the concept stops being useful. Carolyn frames sovereign AI as a risk mitigation strategy rather than a silver bullet: it reduces the exposure that comes from handing data to third parties, but it doesn’t replace insider threat monitoring, access controls, or offboarding discipline. She’s direct about the limits, pointing out that basic cyber hygiene has to be in place before sovereign infrastructure adds any real protection, and that a sovereign AI system is simply another piece of IT requiring the same auditing and monitoring as everything else. The conversation covers the practical trade-offs businesses face when moving off SaaS models onto owned infrastructure, including the cost predictability that comes with saturating owned GPUs versus the unpredictability of pay-as-you-go pricing. Carolyn also discusses model provenance and supply chain risk when downloading open source models, why guardrails have to be built around what a system should do rather than relying on a model’s built-in defaults, and Cloudera’s work on an AI gateway designed to route requests to the most appropriate model based on sensitivity, cost, and performance. She closes on the growing importance of data in motion for agentic and autonomous systems, arguing that stale context undermines decision quality just as much as poor governance of data at rest. Key takeaways: sovereign AI mitigates specific risks but doesn’t replace basic security hygiene, cost predictability often matters more than raw cost, and model choice increasingly depends on matching sensitivity and task to the right infrastructure.

In a conventional attack campaign, skilled operators may have to perform reconnaissance, write or modify code, maintain infrastructure and coordinate multiple tasks. Anthropic says AI is increasingly being used to execute or orchestrate those steps, including multi-agent workflows that run reconnaissance, exploitation and data exfiltration in parallel.

The security implication is therefore economic as much as technical. If the cost of attempting an attack falls, defenders may face more campaigns, more personalised lures and faster iteration even when the underlying vulnerabilities are familiar. The same dynamic applies to fraud. AI does not need to invent a completely new fraud method to have an impact; it can make impersonation, document creation and personalised social engineering cheaper to produce at scale.

For financial services and insurers, that raises a strategic question about where controls should focus. Organisations will still need to detect individual bad transactions or claims, but they may also need better ways to identify the infrastructure and behavioural patterns that allow high-volume deception to scale across channels.

The report also reinforces the case for stronger identity and agent controls on the defensive side. As attackers automate more of their workflows, enterprises will be tempted to automate more defensive decisions in response. That can improve speed, but it also makes the governance of defensive agents more important. Security teams need to know what an automated system can block, quarantine or change without human intervention, and how those decisions are reviewed afterwards.


The Sovereign AI Reality Check- Governance, cost, and the limits of control
Carolyn Duby, Field CTO at Cloudera, joins Stewart Tinson for a candid look at what sovereign AI actually protects, and where the concept stops being useful. Carolyn frames sovereign AI as a risk mitigation strategy rather than a silver bullet: it reduces the exposure that comes from handing data to third parties, but it doesn’t replace insider threat monitoring, access controls, or offboarding discipline. She’s direct about the limits, pointing out that basic cyber hygiene has to be in place before sovereign infrastructure adds any real protection, and that a sovereign AI system is simply another piece of IT requiring the same auditing and monitoring as everything else. The conversation covers the practical trade-offs businesses face when moving off SaaS models onto owned infrastructure, including the cost predictability that comes with saturating owned GPUs versus the unpredictability of pay-as-you-go pricing. Carolyn also discusses model provenance and supply chain risk when downloading open source models, why guardrails have to be built around what a system should do rather than relying on a model’s built-in defaults, and Cloudera’s work on an AI gateway designed to route requests to the most appropriate model based on sensitivity, cost, and performance. She closes on the growing importance of data in motion for agentic and autonomous systems, arguing that stale context undermines decision quality just as much as poor governance of data at rest. Key takeaways: sovereign AI mitigates specific risks but doesn’t replace basic security hygiene, cost predictability often matters more than raw cost, and model choice increasingly depends on matching sensitivity and task to the right infrastructure.
Share this post
The link has been copied!