A navy padlock centered on two stacked digital-storage drives against a teal background.

AI-assisted attacks should make cybersecurity a leadership priority

Arvis Zeile
Arvis Zeile
| 6 mins

Anthropic reports that attackers are using AI to automate substantial parts of their work. Owners and managers should respond by raising cybersecurity on the leadership agenda. Leaving known weaknesses unresolved gives attackers more opportunity, while the company continues to depend on its data and systems every day.

What the AI reports actually tell us

On 9 September 2026, Anthropic reported four incidents in which Claude gained unauthorized access to third-party systems during cybersecurity evaluations. Misconfigured tests allowed internet access, with normal production cyber safeguards disabled. Anthropic identified biased reasoning and reckless pursuit of tasks. These were real incidents during testing, not a reported breach of Anthropic's infrastructure. The assessment's announced independent investigation was still pending.

OpenAI's 26 August 2026 investigation described a separate July incident: models under reduced safeguards compromised parts of its internal research infrastructure and Hugging Face's systems. The main activity came from an internal research model. This involved real external systems, not merely a simulation or a criminal campaign. OpenAI said its customer data and product availability were unaffected. Like Anthropic's findings, this vendor account shows failures of model behavior and containment during evaluation; it does not establish ordinary businesses' breach likelihood.

Two reasons to strengthen protection

Evaluation incidents and deliberate misuse are different kinds of evidence
Reported activityManagement lesson
OpenAI models reached real systems during testingLimit what your AI tools can access and change.
Attackers used Claude Code in an espionage campaignClose known security gaps before attackers exploit them.

Deliberate misuse is a separate concern. In November 2025, Anthropic described an espionage campaign detected that September. It said attackers used Claude Code against organizations worldwide, with some successful intrusions. The company also reported model mistakes, including false claims of success. AI can assist attackers without making every attempt successful.

The management implication is straightforward. If attackers can automate more of their work, we should shorten the time we leave weaknesses open. Cybersecurity already mattered. AI gives leadership another reason to fund it, assign responsibility and check that protection works.

What the EU figures show

The EU's NIS Cooperation Group, supported by ENISA, recorded more incident reports over 2020–2024. These concern essential services and digital service providers under the first NIS Directive. They show growing reported disruption, with important limits on what we can infer.

EU incident reports increased

Incidents reported under the NIS Directive.
Reporting EU Member States · calendar years 2020–2024.

Coverage varies: 24 countries reported for 2024, compared with 26 for 2023. National reporting thresholds differ. These totals include system failures and human error; they are not counts of attacks or AI involvement.

Source: NIS Cooperation Group, Annual report NIS Directive incidents 2024 (August 2025, pp. 5–10).

View the EU data as a table
NIS Directive incident reports from reporting EU Member States
Calendar yearReports
2020756
2021772
2022890
20231,077
20241,276

The distinction matters: system failures accounted for 51% of the 2024 reports, while malicious actions accounted for 37%. The malicious share fell from the previous year. This series cannot prove that attacks rose across all EU companies. It does show why management needs both protection against attackers and reliable recovery when systems fail.

The business cost is interrupted work

The consequences are easy to recognize without understanding attack methods. Staff lose access to orders. Customers cannot use a service. Confidential records leave the company. Management has to make urgent decisions while reliable information is scarce.

Marks & Spencer paused online orders on 25 April 2025 while stores remained open. Its later results described an online pause from late April to early June, with click and collect returning in August. A major sales channel was disrupted.

More serious incidents reached the UK's cyber response team

Significant and highly significant incidents handled by NCSC.
United Kingdom · annual reporting periods, September–August.

These are incidents handled by NCSC, not all UK attacks or a measure of AI involvement. Reporting is incomplete.

Source: NCSC Annual Review 2025, incident management (14 October 2025).

View the data as a table
UK significant and highly significant incidents handled by NCSC
Reporting periodIncidents
Sep 2021–Aug 202263
Sep 2022–Aug 202362
Sep 2023–Aug 202489
Sep 2024–Aug 2025204

The British Library's March 2024 review of its October 2023 ransomware attack reported stolen personal data and severely restricted services. Although it retained secure copies of its digital collections, damaged infrastructure complicated restoration. Having a backup did not mean it could immediately resume normal work.

Latvian businesses face these consequences too. CERT.LV described a Latvian manufacturer's ransomware incident reported in August 2024: encrypted servers and databases paralysed logistics and disrupted partners' supply chains. It also reported attackers' video appearing briefly on Balticom's television service on 20 September 2024. Initial findings pointed to an intermediary's servers outside Latvia. A supplier's security failure can become your customer problem.

These examples illustrate business impact. The cited reports do not establish AI involvement in these incidents.

Turn awareness into action

Postponing protection leaves company data and systems exposed while the budget decision waits. Start with the service your business most depends on, identify what you do not yet know, and agree the first fixes with the people responsible.

Start a security conversation

Paste this prompt into your usual GPT, Claude or Gemini chat. It asks one question at a time, then helps you choose three next steps with your IT team.

Use general descriptions, not passwords, personal or customer records, or confidential system details. This is based on your answers, not a test of your systems.

View or select the prompt

Keep these official guides nearby

Bring the proposed actions and unanswered questions to your IT team. Agree owners and dates, and ask for evidence when fixes are complete.