
We covered the collective defence letter on 1 September, and last week's Featured slot went to GPT-6 Astra's Critical cyber rating. Both were arguments about what AI might do. Anthropic's threat report, published on 10 September, is a list of what it already did.
It covers seven types of misuse that the company says it disrupted between December 2025 and August 2026, including cyber operations, surveillance, biological misuse, weapons development and illicit distillation. Claude Haiku, Sonnet and Opus were the models involved. Anthropic says none of the cases involved its Fable or Mythos-class models, with the exception of one distillation case.
The reason it matters to a QS or a project director is less compelling than the geopolitical angle. This is the most detailed public account yet of how AI accounts get abused, and it is what clients, insurers and procurement teams will quote at you when they ask how you control yours.
The numbers everyone will repeat
Most of the coverage led on distillation. TechCrunch counted nearly 200 million exchanges across five campaigns. The largest, attributed to Alibaba, ran to over 151 million exchanges between May and July 2026, peaked at nearly three million a day from more than 3,500 fraudulent accounts, and fed training data into the Qwen models.
The Moonshot case is an exception. Anthropic says Moonshot quietly forwarded its own customers' requests to Claude and showed them the answers as though Kimi had written them, relaying almost 300,000 requests in ten days through 5,380 fraudulent accounts. Two days earlier, the NSA, CISA and FBI had named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI in a joint advisory and said the activity was carried out 'likely with the knowledge of the Chinese government'.
The case your IT team should read twice
Buried in the cyber section is the part with your name on it. Investigating criminal operators linked to the ShinyHunters collective, Anthropic found they were stealing AI API keys from the companies they broke into, then spending that access as compute for the next attack. Every one of those keys, the report says, came from a customer's environment rather than from Anthropic.
Pace matters as much as scale. One affiliate breached a software provider and reached data belonging to roughly 200 of its downstream customers. Another dumped over 2,100 Azure AD token sets across more than 40 corporate tenants in about 34 hours, with AI agents doing nearly all the work.
Very few firms in our sector run a frontier model. Plenty hold a key to one, sitting in a Revit plugin, a takeoff script, a CDE integration or a proof of concept somebody stood up in March and never decommissioned.
Surveillance, weapons and the caveats worth keeping
Two cases will do the rounds. In Mali, Anthropic says a single subscriber, likely a Bamako-based consultant working with the state intelligence service, used Claude as the engineering workforce for a domestic surveillance platform covering roughly 25 million SIM cards across all three national mobile operators. Banning the account did not switch the system off, because it runs on-premises on local models.
In northern Yemen, a cell used Claude Code instead of software engineers to write guidance software for a tactical guided rocket, test-fired it, and came back within hours to work out why it had failed.
Authoritarian states are using AI for surveillance, repression and influence operations today.
Klein told Axios that AI is automating parts of the job inside the intelligence apparatus rather than changing who governments target. Keep Anthropic's hedges attached when you repeat this. On the five biological cases, the company withheld the institutions, countries and agents involved, described the individuals as working scientists, and said it does not assert that they intended harm.
The vendor's own dirty laundry
The day before, Anthropic published an alignment assessment of four incidents in which Claude models reached real third-party systems during cybersecurity evaluations. A misconfiguration had connected environments meant to be offline to the open internet, and the models were running without the cyber safeguards that ship with released products. Anthropic scanned roughly 481 million transcripts looking for others, and has signed METR, an independent evaluations nonprofit, to investigate over an initial eight weeks.
As a buyer, this is worth exploring. The vendor found its own failure, published it, and paid an outsider to mark the homework. When a supplier tells you their AI is safe, ask what they published when it wasn't.
The questions clients are about to ask
None need a data scientist. They do need an owner:
Where do our AI API keys live, who can read them, and how fast can we rotate one on a Friday afternoon?
Which of our software vendors send our prompts to a model, and can they say which model receives them?
Does our acceptable-use policy mention using model outputs to train something else, which Anthropic's own terms prohibit without permission?
How many people are using personal subscriptions on project work rather than the corporate tenant?
If a supplier's AI integration is breached and our project data goes with it, whose incident is that under the contract?
Takeaway
Nothing here argues for pulling AI out of your delivery workflow. It argues for treating model access the way you treat any other privileged credential, and for expecting the question in your next PQQ. The controls are unglamorous: keys in a vault rather than a config file, a named owner for every integration, an acceptable-use policy that mentions distillation and personal accounts, and a supplier question asking who the model provider is behind the badge on the login screen. Most of that already sits inside an ISO 27001 scope. What has changed is that a client can now cite chapter and verse when they ask for proof.
We pull apart stories like this every week in the Project Flux newsletter, with the governance detail that gets lost behind the headline numbers. Subscribe here and read it before your client does.
Links and Stuff
All content reflects our personal views and is not intended as professional advice or to represent any organisation.


