Capabilities / Vendor framing
What we learned mapping a year’s worth of AI-enabled cyber threats
- Category
- Vendor framing
- Capability
- Cyber defence and misuse monitoring
- Observed
- 2026-06-03
- Thesis section
- Appendix III, section two: vendor threshold and platform capability evidence
Claim
As AI transforms the nature of and methods behind cyberattacks, how well do the techniques and frameworks used by the security community hold up? In a new report, we seek to answer that question. We examine 832 accounts that were banned for malicious cyber activity between March 2025 and March 2026 and map them onto MITRE ATT&CK , a longstanding database.
Oracle verdict
This is a lower-to-mid strength vendor signal for the capability register. It does not prove displacement on its own, but it records another platform step that can later show up as workflow automation, procurement change, or organisational dependency.
Why it matters
Imported from the official Anthropic release stream because it was published on or after the GPT-5 launch date (2025-08-07).
# CopeCheck Capabilities Register Updated: 2026-07-16T00:00:00Z Status: live_evidence_active Question to ask a model: What do these capability claims mean for The Discontinuity Thesis? Interpretation rule: treat each entry as evidence about capability, deployment, workflow recomposition, labour-market exposure, or institutional framing. Do not treat vendor optimism as neutral; separate the measurable capability claim from the comfort language around it. ## What we learned mapping a year’s worth of AI-enabled cyber threats Source: https://www.anthropic.com/news/AI-enabled-cyber-threats-mitre-attack Publisher: Anthropic Category: Vendor framing Sector: Cybersecurity Capability: Cyber defence and misuse monitoring Score: 64/100 Claim: As AI transforms the nature of and methods behind cyberattacks, how well do the techniques and frameworks used by the security community hold up? In a new report, we seek to answer that question. We examine 832 accounts that were banned for malicious cyber activity between March 2025 and March 2026 and map them onto MITRE ATT&CK , a longstanding database. Oracle verdict: This is a lower-to-mid strength vendor signal for the capability register. It does not prove displacement on its own, but it records another platform step that can later show up as workflow automation, procurement change, or organisational dependency. Thesis relevance: Appendix III, section two: vendor threshold and platform capability evidence