CACCYBER · AI · CLUBAUSTRIA / EST. 2026Register Auf Deutsch lesen
All news & blog
AI & SECURITY / CLUB COMMENTARY

AI misuse is changing. Our questions need to change with it.

A new threat report puts the focus on how AI is used across an operation.

My reading list ↗
An assistant reaching into every stage of an operation, with an approval step between it and the actions it can take.
The question this report raises for defenders: which actions sit behind a person, rather than behind the model.

What was reported

Anthropic’s September report describes misuse it says it disrupted between December 2025 and August 2026. Its cyber case studies describe AI supporting or coordinating multiple stages of operations. The company cautions that these are selected notable cases, not a picture of typical use.

Source: Anthropic · September 2026

The club take

OUR INTERPRETATION & WORKSHOP IDEAS

Our takeaway: evaluate the workflow around a model, as well as the model itself. A capable assistant connected to accounts, files, and tools has a different risk profile from a chatbot with no ability to act.

For a club workshop, we would start with a fictional organisation and map which actions an assistant can take. Where would a person need to approve an action? What evidence would show that a boundary worked? Keep the exercise isolated, use synthetic data, and write down uncertainty alongside findings.

FROM HEADLINE TO CONVERSATION

Which action should an AI assistant always ask a human to approve?

Start the conversation