Anthropic has published Detecting and countering misuse of AI: September 2026, its latest threat intelligence report. It covers operations the company identified and disrupted over the past eight months, in which threat actors tried to use Claude for malicious activity.

What is in it

Case studies of real attempts rather than hypotheticals, plus an account of how misuse patterns have evolved since the 2025 reports. That comparison over time is the part worth reading: it shows what adversaries stopped doing because it stopped working, and what they moved to instead.

The framing is disruption, not just detection. Anthropic says the operations were identified and shut down, which implies enforcement rather than passive monitoring.

Why a model provider publishes this

Partly accountability, partly deterrence, partly product. A vendor that publishes what it caught is making a claim about its own detection capability that customers can weigh.

It is also the second Anthropic publication in this vein in six weeks, after the late-July analysis of three real-world cybersecurity incidents. The cadence suggests this is becoming a standing report rather than an occasional one.

What it means for anyone deploying AI

The practical lesson is not about Claude specifically. Any capable model is a target for misuse, and any organisation deploying one with real permissions inherits part of that exposure.

Two things follow. First, evaluate a provider's enforcement posture alongside its benchmarks — a model that gets abused freely creates reputational and legal exposure for everyone building on it. Second, assume your own deployment is in scope: an agent with access to internal systems is a more attractive target than a chat window, and the controls should reflect that.

Worth watching

Whether the other frontier labs publish comparable reports. Right now there is no shared standard for what a provider discloses about misuse, which makes vendor comparison on this dimension mostly impossible.