PositioningSeptember 14, 2026

The vendor is watching. Are you?

A quick take on Anthropic’s September 2026 threat report — and the uncomfortable half of it that every CISO should be asking about.

Anthropic just published the most useful enterprise-AI security document of the year, and almost no one is treating it that way.

The September 2026 misuse report covers eight months of threat activity Anthropic detected and disrupted on their own API. Seven harm categories. Suspected state-sponsored groups. Commercial spyware vendors. Financially motivated criminals. A hacktivist with a stolen API key running multi-victim campaigns that a year ago would have required a well-funded team.

Read the report as an operator and one line jumps out:

“Sophisticated attacks no longer require sophisticated attackers.”

That is not a slogan. It is a load-bearing observation about labor economics. The floor of what one person with a laptop can do has moved. Case study GTG-20006 — attributed to Midnight Blizzard — describes a Russian operator running an AI-orchestrated kill chain against Ukrainian government, defense, and drone-supply-chain targets. Reconnaissance, phishing infrastructure, credential theft, malware that automatically rebuilds itself when defenders detect it. All of it stitched together by Claude Code skills the operator was refining in place.

What Anthropic actually did

They watched the traffic. They saw the prompt patterns. They correlated tool calls across sessions. They banned the accounts. They notified authorities. They wrote it up.

They could do all of that for one reason: they sit in the middle of every request to their models. The vantage point is the point.

The uncomfortable half of the report

The report is silent on the question every CISO should be asking: when the API key in that case was stolen, whose was it?

Anthropic can tell you a sk-ant-* key was abused. They cannot tell your legal team which of your developers pasted it into a public repo, which contractor still has it on a decommissioned laptop, which shadow agent on a designer’s machine has been using it to summarise customer PII into a Google Doc. That visibility is not the vendor’s job. It never was. The vendor protects the vendor.

If adversaries are already orchestrating multi-agent kill chains through stolen enterprise keys — and Anthropic just documented that they are — the mirror problem is unavoidable. Every organisation with more than a handful of developers has key sprawl. Most have zero inventory of the agents actually running on employee machines. And every one of those keys, every one of those agents, is now a potential entry point for exactly the workflows this report describes.

Your own middle

The lesson from cloud is instructive. AWS did not solve the “who did what with this credential” problem by asking each service to log itself. They put IAM, CloudTrail, and org policies in the middle of every API call. That is what made governance possible. LLM vendors have not shipped that layer, and given competitive pressure, they are unlikely to ship the enterprise-facing version any time soon.

Which leaves the customer with two options:

  1. Trust that the vendor’s disruption reports are the whole story.
  2. Sit in your own middle.

Option one is what most enterprises are doing today. Option two is a proxy — vendor-agnostic, in front of every LLM call, logging every prompt, scoping every key to a real identity, catching the orchestration patterns before they leave your perimeter, and giving you a first-class inventory of the agents (sanctioned and shadow) that exist inside your walls.

Conduct is one such middle. There are others. The specific product matters less than the architectural choice.

The takeaway

Anthropic’s report is not a story about their models being unsafe. It is a story about what an adversary can do with a legitimate API key and a laptop. The organisations that come out of the next twelve months well will be the ones who read this report, looked at their own key inventory, and put the same kind of eyes on their own traffic that Anthropic put on theirs.

The vendor is watching their side. Someone on your side needs to be watching yours.

The vendor is watching. Are you? | Conduct | ConductAI