Keynote: Not a Forecast: AI-Enabled Cyber, 12 Months On

Keynote: Not a Forecast: AI-Enabled Cyber, 12 Months On

🎙 Jacob Klein 👥 70K 📅 April 21, 2026 ⏱ 19 min 👁 2K 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

AIcyberthreat actorsAnthropicMITRE ATT&CK

Summary

In this keynote, Jacob Klein, Head of Threat Intelligence at Anthropic, presents a retrospective on AI-enabled cyber operations over the past year. He begins by contrasting the early state in March 2025, where threat actors used AI as a simple chatbot for code generation, with the current sophisticated use. He details three case studies: a UK-based ransomware-as-a-service actor using Claude for development (March 2025), a Russian-speaking cybercriminal using Claude Code for automated data extortion across 17 targets (May 2025), and a Chinese state-sponsored group using Claude to build an autonomous cyber intrusion agent (September 2025). The latter case highlights that AI performed 80-90% of the tactical work, with humans supervising. Klein then provides a landscape analysis of over 800 banned actors, noting that 70% of MITRE ATT&CK techniques are now automated by AI, and that the median actor uses 16 techniques per case. He introduces an AI enablement score, showing a jump from 12% to 48% of actors gaining medium capability uplift between mid-2025 and early 2026. He emphasizes that AI is now core infrastructure for attackers, increasing the scale and sophistication of attacks, and calls for transparency from AI labs. He also notes the dual-use nature of these technologies for defenders.

202 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable, first-hand insights from a leading AI company’s threat intelligence team, with concrete case studies and quantitative data. The argumentation is coherent, tracing the evolution of AI misuse from simple to sophisticated, and supports the claim that AI is now a core component of cyber attacks. The speaker acknowledges limitations, such as the rough nature of the AI enablement score, and encourages transparency, which adds credibility.

Scientific Rigor, Source Quality, Title Accuracy

The speaker relies on internal Anthropic data, which is not publicly available, but the methodology is described. The talk references MITRE ATT&CK, a well-known framework, and mentions a forthcoming report. The title accurately reflects the content, and the talk is presented at a professional conference (SANS AI Cybersecurity Summit). No external sources are cited, but the speaker’s position and the use of internal data lend authority.

150 words

Title / Content Match

The title accurately reflects the content: a retrospective on AI-enabled cyber threats over the past year, emphasizing that it is not a forecast but an observation of current trends.

Quality & Reliability

8/10

The speaker is the Head of Threat Intelligence at Anthropic, providing first-hand data from monitoring banned actors. The talk includes specific case studies with dates and statistics, but relies on internal, non-public data and lacks peer review.

Key Moments

Cited Sources

  • Anthropic Threat Intelligence Report (forthcoming) — Mentioned as a forthcoming report with more details on the MITRE ATT&CK mapping and AI enablement score.

Concurring Sources

  • MITRE ATT&CK — The framework referenced for mapping threat actor techniques.

Contribution & Novelties

This talk provides a unique, up-to-date perspective from a major AI lab on how threat actors are actually using AI systems, with specific case studies and quantitative data. It highlights the rapid evolution from simple chatbot use to autonomous agents, and introduces the concept of an AI enablement score. The talk also emphasizes the dual-use nature of AI for defenders.

Pour aller plus loin :

102 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical level, indicating a talk that is informative and credible but not overly technical, suitable for a broad security audience.

Reliability 8/10

💬 No comments were provided for analysis.