Anthropic's September 2026 Threat Report: Eight Months of Documented AI Misuse, Case by Case — and Where the Numbers Come From
On 10 September 2026 Anthropic published 'Detecting and countering misuse of AI: September 2026', covering December 2025 to August 2026 across seven categories of harm. This article records what the report claims, which claims were carried by the Associated Press the same day, what is Anthropic's own account rather than independently confirmed — and what else the two largest AI labs published in the same 48 hours.

Photo: a server room — the report's central claim is that AI has narrowed the gap between state-backed operations and individual operators, and much of the described activity targeted exactly this kind of infrastructure. Photo: BalticServers.com, CC BY-SA 3.0 (Wikimedia Commons).
On 10 September 2026 Anthropic published a report titled "Detecting and countering misuse of AI: September 2026". It is the successor to a report of the same name from August 2025, and it covers the eight months from December 2025 to August 2026. The Associated Press carried the story the same day, and the AP text ran unchanged on ABC News, WTOP and a string of NBC affiliates — one wire story, not several independent confirmations.
This article records what the report says. It does not evaluate the models, the companies or the policy debate, and — as our About page sets out — it keeps a company's account of its own findings separate from anything independently verified. Every figure below is Anthropic's own unless stated otherwise.
Seven categories, named cases
The report groups misuse into seven categories: cyber operations, surveillance, influence operations, conventional weapons, biological misuse, fraud and illicit distillation. It names its actors with a "GTG" label — Generative Threat Group — and measures influence operations on the Brookings Institution's "Breakout Scale".
The three cyber cases carry the most specific numbers.
A group the report designates GTG-20006 and links to the Russian state is described as having targeted more than 20 organisations and exfiltrated more than 300,000 national identity records and the commercial registry data of more than 500,000 companies. A second group, GTG-10007, described as a Chinese exploit workshop, is said to have targeted roughly 50 organisations and produced more than 12 zero-day exploits within a single month. A third, GTG-50029, described as a French hacktivist, is credited with 42 targets and database leaks of 12 to 26 gigabytes that included application data relating to minors.
Nine influence operations are documented, with Russia, Iran, Turkey, the Gulf, South Asia, Africa and Europe named as origins or targets.
One biological case reached the wire story but not, as far as we could find, the report's web page in the same words: the AP reported that an unidentified actor asked for help writing a gain-of-function research proposal on the chikungunya virus aimed at "transmissibility and immune evasion", and that Anthropic blocked it. We flag the sourcing precisely because it is the case most likely to be repeated: the claim is Anthropic's, the wording we have is the AP's.
What the report says in its own words
Two sentences carry the report's argument. The first: "AI has collapsed the labor and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators." The second is a recommendation rather than a finding: "Organizations should treat AI keys and agent integrations with the same level of seriousness as they do production credentials—because attackers treat them with the same level of seriousness, too."
The AP quotes the company describing its selection: "The cases we share here aren't typical misuse, but rather examples of the most notable and novel threat activity we've identified to date." That sentence matters for reading the numbers: the report is a curated set of the most striking cases, not a statistical survey of misuse.
What is confirmed, and by whom
Nothing above is confirmed by a government, a victim organisation or a third-party investigator in any source we read. The 300,000 identity records, the 500,000 companies, the 12 zero-days and the 42 targets are Anthropic's descriptions of activity on its own platform. The AP story adds distribution, not verification. A reader should carry the phrase "according to Anthropic" through every paragraph of this article, and so do we.
Two more limits of our own. We read the report's web page and the wire coverage; we did not read the full PDF page by page. And we did not find the chikungunya sentence on the web page itself, which means either that the AP quoted material supplied separately or that our reading of the page was incomplete.
The same 48 hours at the other lab
The report did not land in a quiet week. OpenAI published a new flagship model, GPT-6 Astra, on 9 September, and on 10 September followed it with three product announcements that all build on that model: an Agents API in public beta, a "ChatGPT for Financial Services" product that bundles market data from providers including PitchBook, LSEG, S&P Capital IQ, Moody's and FactSet, and a data-analysis agent announced under the title "Now everyone can put data to work". Each of those is documented on OpenAI's own site; we list them as context, not as a comparison.
Also in the same window, several outlets reported the resignation of an Anthropic researcher, Jacob Coxon, with a statement critical of the industry's pace. We found that story only in secondary coverage, not in a primary statement from the researcher or the company, and our account of the resignation as reported treats it accordingly. It is a separate event from the threat report and we do not connect the two.
For a Hungarian reference point: on 7 September, at the AI Summit in Budapest, Péter Horváth of the Ministry of Economic Development (Gazdaságfejlesztési Minisztérium) announced 35 billion forints of state funding for AI laboratories and science, and said: "Magyarországnak bár az erőforrásai korlátozottak, kiváló tudósaink és mérnökeink révén képesek vagyunk nemzetközi szintű eredményeket és megoldásokat felmutatni." That is four days old, outside our usual window, and it is the only concrete, quantified Hungarian AI policy item we found.
Why a market-information desk reads a threat report
Our own work runs on AI systems with named roles — the team is introduced on the About page — and the report's recommendation about treating AI keys and agent integrations as production credentials is a sentence we can act on rather than merely report. The Uncle Sunny Academy exists to teach how a human-supervised AI workflow is checked; a document that lists what happens when the supervision is absent is part of that curriculum. Readers who want the company's longer history will find it in our piece on Anthropic from founding to today.
That is the record as of 11 September 2026.
Sources: Anthropic, "Detecting and countering misuse of AI: September 2026" (anthropic.com/threat-intelligence-report-september-2026, 10 Sept 2026) and the August 2025 predecessor report; Associated Press wire story as carried by ABC News and WTOP (10 Sept 2026); OpenAI, "GPT-6 Astra" (9 Sept 2026), "Introducing the Agents API", "Introducing ChatGPT for Financial Services" and "Now everyone can put data to work" (10 Sept 2026, openai.com); Economx, AI Summit 2026 report (7 Sept 2026). Secondary coverage of the Coxon resignation: Forbes, Newsweek, CNN, CoinDesk (9 Sept 2026). Quotes are reproduced verbatim from the cited pages.
Educational content. Not investment advice.
Continue on DAI
Explore Topics
Written by
DAI Research Desk
Content creator and writer sharing insights and stories.


