Loading the Elevenlabs Text to Speech AudioNative Player...

AI is becoming part of how people work, but Anthropic’s latest report shows that its usefulness is no longer limited to writing emails, generating code, or answering questions. 

In its September 2026 report, “Detecting and countering misuse of AI,” Anthropic detailed several cases in which people used Claude across cyber operations, influence campaigns, surveillance, scams, and other activities. The company says the cases represent some of the “most notable and novel threat activity” identified between December 2025 and August 2026, rather than typical examples of AI misuse. 

For people building careers in technology, the report offers a few lessons about how AI is changing the value of technical skills, and the type of work people may be expected to handle. Here are seven takeaways we sourced directly from the report. 

Why Anthropic Researcher Jacob Coxon Quit, and Who Agreed
Coxon’s warning comes as both OpenAI and Anthropic have faced incidents involving their AI systems gaining access to other organisations’ systems.

/1. The skill gap between amateurs and nation-states is closing, and that changes hiring 

Anthropic's central finding is that AI has narrowed the historical advantage that well-resourced state hacking teams held over individual operators. The report describes solo actors and small criminal crews running multi-victim campaigns that would previously have required entire teams' breaches completed in two to three hours, with dozens of victims managed in parallel by a single person.

For talent, this means defensive teams can no longer assume a "sophisticated actor" profile before taking a threat seriously. Employers will increasingly value people who can reason about capability and intent separately from resourcing, because a lone operator with an AI agent can now behave like an advanced persistent threat (APT) group. 

/2. Fluency in agentic, multi-agent systems is becoming a baseline skill 

The report is explicit that misuse went beyond simple chatbot Q&A. Several operations used multi-agent frameworks that executed reconnaissance, exploitation, and data exfiltration with a human setting targets and reviewing results rather than performing each step.

One actor even built a workflow that automatically rebuilt and redeployed its toolkit whenever security products detected it. If attackers are orchestrating agents rather than typing prompts, defenders and builders alike need to understand agent orchestration, tool use, and autonomous workflows, not just prompt engineering, to stay relevant. 

/3. Speed is the new differentiator, and it rewards automation-literate people 

Cases in the report describe breaches escalating from a single stolen developer token to full administrative control of a victim's cloud environment in roughly three hours.

That kind of compression means incident response, detection engineering, and security operations roles will favor candidates who can build and operate automated detection and response pipelines, because manual, human-paced workflows simply can't keep up with AI-paced attacks anymore. 

Subscribe for free to continue reading this article

Subscribe Subscribe

Already have an account? Log in