📊 Full opportunity report: The Frameworks Can’t See the Thing That Matters: A Year of AI-Enabled Cyber Threats on ThorstenMeyerAI.com — validation score, market gap, and execution plan.
TL;DR
A recent analysis shows AI is making cyber attackers more dangerous and harder to distinguish. The old threat assessment methods no longer reliably identify high-risk actors, as AI democratizes advanced attack techniques.
A new analysis from Anthropic reveals that artificial intelligence is significantly increasing the danger posed by cyberattackers, rendering traditional threat assessment methods ineffective. The study examined 832 accounts involved in malicious activity over a year, finding that AI enables both basic and highly complex attack techniques to be performed by less skilled actors, fundamentally changing how threat levels are gauged in 2026.
The report, based on mapping malicious accounts onto the MITRE ATT&CK framework, shows that AI is primarily used to automate the creation of malware and facilitate lateral movement within networks. While 67.3% of the studied accounts used AI for attack preparation, a notable 6.5% employed AI for advanced tasks like navigating deep into compromised systems. Over the year, the proportion of higher-risk actors increased from 33% to 56%, with a shift toward AI use in post-intrusion activities rather than initial access.
Crucially, the data indicates that the traditional markers of threat—such as the number of techniques used or the platform employed—no longer reliably distinguish between high- and low-risk actors. Both skilled and less skilled actors now utilize similar techniques, often with AI assistance, making threat assessment based on technique diversity obsolete. Instead, the report highlights that the most dangerous actors focus AI on operationally demanding tasks, but even this is becoming less distinctive as more actors adopt similar strategies.
The frameworks can’t see the thing that matters
For decades, danger meant which techniques an attacker commands. A year of real AI-enabled attacks — 832 banned accounts mapped onto MITRE ATT&CK — shows that signal breaking, just as a new, harder-to-see one takes over.
A year of real misuse, mapped to the standard taxonomy
A window, not a census — these are the cases with enough detail to assess techniques thoroughly. Inside it, the risk level climbed fast.
WHAT WAS STUDIED
THE RISK CLIMB · MEDIUM-OR-HIGHER ACTORS

AI-POWERED CYBERSECURITY OPERATIONS: Threat intelligence anomaly detection and automated incident response systems
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
“More techniques” stopped meaning “more dangerous”
The old heuristic: count the techniques, judge the tooling. AI dissolved it — because the model supplies the techniques either way. Watch the old signal fail, then watch what it misses.
Risk score vs. technique count
Two ways to read the same attacker. One is going blind. Press play.

WatchGuard Firebox T145 with 1 Year Basic Security Suite – Tabletop Firewall, 2.5Gb, 1Gb & SFP Ports, Enterprise Security for Branch Locations (WGT145031)
Watchguard T145 Firebox with 1 Year Basic Security Suite License (WGT145031) – The Firebox T145 delivers enterprise-grade protection…
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Deeper into the attack — and into less-skilled hands
Across the year, AI use drifted from getting in toward acting once already inside — the operationally demanding stages that used to require an expert.
The attack lifecycle · where AI is now applied
The center of gravity moved right — toward post-compromise work.

Network Intrusion Detection
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
From “what they know” to “what they’ve built”
The report sorts the signals into three tiers — one dead, one fading, one durable.
Technique count & tooling
16 vs. 20 between novice and expert; platform doesn’t correlate. The model supplies the techniques either way.
Where in the lifecycle AI is applied
Concentrating on operationally demanding, post-compromise stages is a better signal — but it’s eroding as the whole population heads there.
The scaffolding around the model
Architectures that let the model chain stages and run with minimal human input. Not what they know — whether they’ve built a system that lets AI run the attack.

Operationalizing Threat Intelligence: A guide to developing and operationalizing cyber threat intelligence programs
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Fixing the map before the territory moves again
A taxonomy that can’t name the most dangerous behavior on the field will quietly mislead the people relying on it. The response runs in two directions.
Fed back into the models
The findings informed safeguards on the most capable models, built to detect & block some of what was observed:
- Blocking malware development
- Blocking mass data exfiltration
- Putting tools in defenders’ hands first (Project Glasswing)
Taking it to the source
Following the Verizon work, Anthropic says it’s in discussions with MITRE about how ATT&CK might evolve:
- A vocabulary for agentic orchestration
- Naming the scaffolding that makes a model an operator
- An interactive technique visualization on the Red blog
Reading it in proportion
- The 832 cases are a detailed subset, not the full population — the precise percentages are directional, not definitive.
- “More autonomous” is not “fully autonomous” — even the standout case needed human input at key moments, which is itself a place for defenders to intervene.
- This is one vendor’s window — the company with visibility into misuse of its own model, publishing what it found. The right thing to do with the data, and worth remembering as you read it.
Implications of AI-Driven Threat Democratization
This development means that cyber threat assessment, which relied heavily on counting techniques and analyzing tools, is no longer effective. The ability for less skilled actors to perform complex, high-impact attacks with AI increases the overall threat landscape and complicates defense strategies. Organizations must now reconsider how they evaluate threat levels, as traditional heuristics no longer apply, and the risk is more evenly distributed across actors with varying skill levels.
Evolution of Cyberattack Techniques in the AI Era
Historically, threat assessment focused on the number of techniques used and the sophistication of tools, assuming that more techniques indicated a higher threat. The MITRE ATT&CK framework provided a standardized way to categorize attacker tactics. Over the past year, AI’s integration into cyberattack workflows has disrupted this model, enabling less skilled actors to perform complex operations previously reserved for experts. This shift coincides with broader adoption of AI in cybercrime, reflecting a new frontier in threat dynamics.
“Traditional heuristics no longer reliably identify high-risk actors because AI levels the playing field.”
— Anthropic report author
Unclear Impact on Future Threat Assessment Models
It is not yet clear how organizations will adapt their threat detection strategies to account for AI-driven attack capabilities. The long-term evolution of attacker behavior and the development of countermeasures remain uncertain, as the landscape shifts rapidly and data is still emerging.
Next Steps for Cyber Defense Strategies in 2026
Security teams will need to develop new frameworks that focus less on technique count and more on behavioral and operational signals. Ongoing research and real-time monitoring will be critical to understanding how threat actors evolve as AI becomes more integrated into cyberattack workflows. Further studies are expected to clarify how best to adapt threat assessment in this new environment.
Key Questions
How does AI change the way attackers operate?
AI enables attackers to automate complex tasks like lateral movement and account discovery, making these activities accessible to less skilled actors and increasing overall threat levels.
Why can’t traditional threat assessment methods identify high-risk attackers anymore?
Because AI allows less skilled actors to perform techniques previously associated only with advanced hackers, the correlation between technique diversity and threat level has broken down.
What should organizations do to improve threat detection?
Organizations need to shift toward behavioral analysis and operational signals, focusing on how attackers build and use AI-driven scaffolding rather than just counting techniques or tools.
Is this trend likely to accelerate?
Given current developments, it is probable that AI integration in cyberattacks will continue to grow, further blurring the lines between skilled and amateur threat actors.
Source: ThorstenMeyerAI.com