AI THREAT INTELLIGENCE
AI changes the pace.
Judgment sets the priority.
Track how adversaries use AI, how AI systems become targets, and which controls reduce exposure now.
Distance from the center shows operational maturity based on the cited reporting. Angle only separates categories; it is not a severity score. Select the matching surface below for signals and defensive priorities.
Scope: Anthropic accounts with sufficient detail, March 2025–March 2026. These figures describe that investigated dataset and are not estimates of all cyber activity.
What defenders should separate.
Current reporting shows routine AI assistance at scale and early agentic experimentation. The distinction matters when setting controls and urgency.
AI is already a force multiplier.
- Phishing, translation, impersonation, and social engineering content
- Malware and script development, debugging, and adaptation
- Reconnaissance, stolen-data analysis, and operational research
- Identity fabrication and support for fraudulent remote-worker operations
Human operators still commonly choose objectives, targets, and deployment.
Agentic workflows are moving deeper.
- Autonomous vulnerability discovery and exploit development
- Tool-driven reconnaissance and post-compromise actions
- Theft or misuse of proprietary models, research, and training data
- Compromised cloud environments used to run unauthorized AI infrastructure
Reporting shows experimentation and adoption, but capability and scale vary by actor.
Four surfaces. One control plan.
Select a surface to see the immediate defensive priority.
Control the agent. Protect the decision.
Start with access, visibility, and containment. Apply these actions to sanctioned AI and shadow use.
- 01
Inventory AI use
Identify applications, models, agents, plugins, data sources, owners, and business decisions they influence.
- 02
Constrain privileges
Use least privilege, short-lived credentials, narrow tool access, and approval gates for consequential actions.
- 03
Treat inputs as untrusted
Assume prompts, retrieved documents, websites, and tool results can contain hostile instructions or poisoned data.
- 04
Log the full chain
Record prompts, retrievals, model responses, tool calls, identity context, and final actions for investigation.
- 05
Protect models and data
Limit training-data exposure, restrict model downloads, scan dependencies, and monitor unusual cloud compute or egress.
- 06
Practice containment
Test how to suspend an agent, revoke credentials, isolate connected tools, preserve evidence, and restore safely.
2026 reporting, with scope intact.
Direct links open the original research. Vendor observations are attributed and should be evaluated alongside your own telemetry.
AI as tradecraft
Observed use across phishing, malware support, research, translation, and identity fraud; agentic use remains early.
READ SOURCE ↗ JUN 03 · ANTHROPICAI use mapped to ATT&CK
Analysis of 832 enforced accounts shows deeper use across malware writing and post-compromise activity.
READ SOURCE ↗ MAY 11 · GOOGLE GTIGAI and initial access
Reporting on the integration of AI into adversarial workflows, including suspected use of agentic tools.
READ SOURCE ↗ SEP 07 · GOOGLE GTIGFrom prompting to autonomy
Tracks model and research theft, cloud abuse, and the evolution of adversarial AI operations.
READ SOURCE ↗ APR 16 · MANDIANTEnterprise AI vulnerabilities
Explains how capable models change vulnerability discovery and why organizations need a prepared defense.
READ SOURCE ↗ APR 22 · MICROSOFTAI-accelerated defense
Documents how AI can find weaknesses, chain issues, and compress the disclosure-to-exploitation window.
READ SOURCE ↗Prioritize what can act, access, and decide.
Use this page with the Zero-Day Clock and Priority Action Board to connect emerging capability to immediate defensive work.
GET THE BRIEFING