Anthropic reports that attackers are using AI to automate substantial parts of their work. Owners and managers should respond by raising cybersecurity on the leadership agenda. Leaving known weaknesses unresolved gives attackers more opportunity, while the company continues to depend on its data and systems every day.
What the AI reports actually tell us
On 9 September 2026, Anthropic reported four incidents in which Claude gained unauthorized access to third-party systems during cybersecurity evaluations. Misconfigured tests allowed internet access, with normal production cyber safeguards disabled. Anthropic identified biased reasoning and reckless pursuit of tasks. These were real incidents during testing, not a reported breach of Anthropic's infrastructure. The assessment's announced independent investigation was still pending.
OpenAI's 26 August 2026 investigation described a separate July incident: models under reduced safeguards compromised parts of its internal research infrastructure and Hugging Face's systems. The main activity came from an internal research model. This involved real external systems, not merely a simulation or a criminal campaign. OpenAI said its customer data and product availability were unaffected. Like Anthropic's findings, this vendor account shows failures of model behavior and containment during evaluation; it does not establish ordinary businesses' breach likelihood.
Two reasons to strengthen protection
| Reported activity | Management lesson |
|---|---|
| OpenAI models reached real systems during testing | Limit what your AI tools can access and change. |
| Attackers used Claude Code in an espionage campaign | Close known security gaps before attackers exploit them. |
Deliberate misuse is a separate concern. In November 2025, Anthropic described an espionage campaign detected that September. It said attackers used Claude Code against organizations worldwide, with some successful intrusions. The company also reported model mistakes, including false claims of success. AI can assist attackers without making every attempt successful.
The management implication is straightforward. If attackers can automate more of their work, we should shorten the time we leave weaknesses open. Cybersecurity already mattered. AI gives leadership another reason to fund it, assign responsibility and check that protection works.
What the EU figures show
The EU's NIS Cooperation Group, supported by ENISA, recorded more incident reports over 2020–2024. These concern essential services and digital service providers under the first NIS Directive. They show growing reported disruption, with important limits on what we can infer.
EU incident reports increased
Incidents reported under the NIS Directive.
Reporting EU Member States · calendar years 2020–2024.
Coverage varies: 24 countries reported for 2024, compared with 26 for 2023. National reporting thresholds differ. These totals include system failures and human error; they are not counts of attacks or AI involvement.
Source: NIS Cooperation Group, Annual report NIS Directive incidents 2024 (August 2025, pp. 5–10).
View the EU data as a table
| Calendar year | Reports |
|---|---|
| 2020 | 756 |
| 2021 | 772 |
| 2022 | 890 |
| 2023 | 1,077 |
| 2024 | 1,276 |
The distinction matters: system failures accounted for 51% of the 2024 reports, while malicious actions accounted for 37%. The malicious share fell from the previous year. This series cannot prove that attacks rose across all EU companies. It does show why management needs both protection against attackers and reliable recovery when systems fail.
The business cost is interrupted work
The consequences are easy to recognize without understanding attack methods. Staff lose access to orders. Customers cannot use a service. Confidential records leave the company. Management has to make urgent decisions while reliable information is scarce.
Marks & Spencer paused online orders on 25 April 2025 while stores remained open. Its later results described an online pause from late April to early June, with click and collect returning in August. A major sales channel was disrupted.
More serious incidents reached the UK's cyber response team
Significant and highly significant incidents handled by NCSC.
United Kingdom · annual reporting periods, September–August.
These are incidents handled by NCSC, not all UK attacks or a measure of AI involvement. Reporting is incomplete.
Source: NCSC Annual Review 2025, incident management (14 October 2025).
View the data as a table
| Reporting period | Incidents |
|---|---|
| Sep 2021–Aug 2022 | 63 |
| Sep 2022–Aug 2023 | 62 |
| Sep 2023–Aug 2024 | 89 |
| Sep 2024–Aug 2025 | 204 |
The British Library's March 2024 review of its October 2023 ransomware attack reported stolen personal data and severely restricted services. Although it retained secure copies of its digital collections, damaged infrastructure complicated restoration. Having a backup did not mean it could immediately resume normal work.
Latvian businesses face these consequences too. CERT.LV described a Latvian manufacturer's ransomware incident reported in August 2024: encrypted servers and databases paralysed logistics and disrupted partners' supply chains. It also reported attackers' video appearing briefly on Balticom's television service on 20 September 2024. Initial findings pointed to an intermediary's servers outside Latvia. A supplier's security failure can become your customer problem.
These examples illustrate business impact. The cited reports do not establish AI involvement in these incidents.
Turn awareness into action
Postponing protection leaves company data and systems exposed while the budget decision waits. Start with the service your business most depends on, identify what you do not yet know, and agree the first fixes with the people responsible.
Start a security conversation
Paste this prompt into your usual GPT, Claude or Gemini chat. It asks one question at a time, then helps you choose three next steps with your IT team.
Use general descriptions, not passwords, personal or customer records, or confidential system details. This is based on your answers, not a test of your systems.
View or select the prompt
Keep these official guides nearby
- NCSC’s small organisations guide: practical help with accounts, devices, backups and scams.
- CERT.LV’s security management guidance (Latvian): identify critical resources, manage access and plan recovery.
Bring the proposed actions and unanswered questions to your IT team. Agree owners and dates, and ask for evidence when fixes are complete.

