Anthropic just confirmed its own AI models successfully hacked into three real companies during internal security tests. Not a nation-state. Not a criminal gang. The company’s own product. If you still think AI is just a chatbot, stop now and read this.
What Happened
In late 2025, Anthropic ran a series of red team exercises to measure how dangerous Claude had become. According to Anthropic’s own safety documentation, Claude successfully breached the defenses of three companies that volunteered as targets in controlled tests. The model identified security gaps, wrote working exploit code, and in some cases moved through systems without a human guiding it at every step.
Anthropic calls this “critical uplift” in offensive cyber capabilities. That is their language from their Responsible Scaling Policy. What it means in plain terms: their AI can function as an autonomous attacker.
This is not a leaked memo. Anthropic published this themselves. Their own safety framework requires disclosure when a model crosses certain capability thresholds. That transparency is worth acknowledging. It does not make the news any less alarming.
According to IBM’s 2024 Cost of a Data Breach Report, the average breach costs companies $4.88 million. With AI now able to automate the reconnaissance, exploitation, and movement that once required a skilled human attacker, that number is only going in one direction.
The Part Nobody Is Talking About
Everyone is asking the wrong question. The debate in tech circles right now is whether Anthropic was right to keep building Claude after it crossed this threshold. That is not the point.
The real question is: who else has this capability and is not telling you?
Anthropic disclosed because their safety policies required it. OpenAI, Google DeepMind, Mistral, and dozens of smaller labs are running the same tests. Some of them have the same results. Not all of them have Anthropic’s disclosure standards. According to Stanford’s AI Index 2025, the number of organizations releasing frontier or near-frontier AI models more than doubled between 2023 and 2024. Most have no public safety commitments at all.
Here is the mindset split I see every time a story like this breaks. Most people read it and say “the government needs to do something.” That is the employee mindset. You are waiting for someone else to protect you. The operator mindset asks: what does this mean for my business right now, and what can I do about it?
That answer matters because AI assisted attacks are already in the wild. According to Google’s Threat Intelligence Group, AI generated phishing attacks increased by over 60% in 2024 compared to the prior year. These are not theoretical. Small businesses are getting hit harder than enterprises because they have fewer defenses and more predictable patterns.
If you are building content, marketing, or product operations around AI tools, you are also building attack surfaces. Every API key, every connected platform, every SaaS integration is a door. AI can now try all those doors automatically, at scale, without sleeping.
I have been telling people for six months: AI adoption without AI risk awareness is how you hand your competitors a weapon. The companies that understand this now will be faster, safer, and more trusted than the ones that learn it the hard way.
What This Means for You
Here is what I would actually do if I were starting this process today.
First, audit what AI tools have access to your business systems. Most businesses have granted API access to ten or more AI tools and forgotten half of them. Each one is a potential entry point. Go through your connected apps this week and revoke anything you are not actively using.
Second, treat your team’s AI literacy as a security expense. Your employees are the most common entry point for AI assisted attacks. A short explainer about what AI generated phishing looks like can prevent more damage than most software subscriptions. I have used InVideo AI to build quick training videos for exactly this kind of team briefing. It takes under thirty minutes and your team will actually watch a video instead of ignoring a PDF policy doc.
Third, if you are a small or midsize business owner without an enterprise security budget, do not assume you have no options. AppSumo regularly features lifetime deals on AI governance and security audit tools that would normally cost thousands per year in subscriptions. Worth checking before you lock into monthly pricing.
Fourth, follow Anthropic’s Responsible Scaling Policy updates. They publish them publicly. Right now they are at ASL-3. If they move to ASL-4, that means their models crossed another capability threshold. You can act on that before the market does.
The Bottom Line
Anthropic told the world its AI can breach real companies. Most people will skim the headline and move on. I think that is a costly mistake. This is the clearest signal yet that AI capability and AI risk are moving together, not apart. The businesses that take this seriously in 2026 will not just be safer. They will be better positioned when the inevitable shakeout comes. Everyone else will pay the $4.88 million tuition.
Frequently Asked Questions
Did Anthropic’s AI actually hack real companies?
Yes, in controlled tests with consent. According to Anthropic’s own safety reporting, Claude successfully breached three companies that volunteered as targets during authorized red team exercises. These were not unauthorized attacks. The companies agreed and the tests were designed to measure the model’s offensive cyber capabilities.
Is Claude available to bad actors right now?
Claude is publicly available through Anthropic’s API and Claude.ai. Anthropic has safety filters designed to block the model from assisting with real attacks. The security test breaches used a less restricted version under controlled conditions. That said, jailbreaks exist, and other models with fewer restrictions are widely available to anyone.
Should I stop using AI tools in my business because of this?
No, but use them with more awareness. The risk is not that your AI tool will turn against you. The risk is that AI makes it easier for bad actors to target your business. Audit your connected tools, train your team, and treat AI security as an ongoing process rather than a one time setup.
What is Anthropic’s Responsible Scaling Policy?
It is Anthropic’s internal framework for deciding when a model is too capable to deploy without additional safeguards. According to Anthropic, when a model reaches certain thresholds (called ASL levels), they must either add new protections or pause development. The three-company test results contributed to their current ASL-3 classification.
How do AI assisted cyberattacks actually work?
AI models can automate tasks that once required skilled human attackers, including scanning for vulnerabilities, writing exploit code, crafting convincing phishing messages, and moving through networks after gaining access. According to Google’s Threat Intelligence Group, this has already made attacks faster and cheaper to run at scale. The barrier to a sophisticated attack has dropped significantly in the past two years.


