What was reported
Anthropic’s September report describes misuse it says it disrupted between December 2025 and August 2026. Its cyber case studies describe AI supporting or coordinating multiple stages of operations. The company cautions that these are selected notable cases, not a picture of typical use.
Source: Anthropic · September 2026The club take
OUR INTERPRETATION & WORKSHOP IDEASOur takeaway: evaluate the workflow around a model, as well as the model itself. A capable assistant connected to accounts, files, and tools has a different risk profile from a chatbot with no ability to act.
For a club workshop, we would start with a fictional organisation and map which actions an assistant can take. Where would a person need to approve an action? What evidence would show that a boundary worked? Keep the exercise isolated, use synthetic data, and write down uncertainty alongside findings.