· Solveion · Perspectives  · 6 min read

The threat report is also an advertisement

When a lab announces that its model was used to run a near-autonomous intrusion campaign, it is publishing a warning and a capability claim in the same sentence. The genre cannot separate them, and several of these documents contain nothing a defender can act on.

When a lab announces that its model was used to run a near-autonomous intrusion campaign, it is publishing a warning and a capability claim in the same sentence. The genre cannot separate them, and several of these documents contain nothing a defender can act on.

There is a genre of document that barely existed three years ago and is now a fixture. A frontier lab publishes a report describing how its own model was used by attackers: which state actor, how many targets, how much of the intrusion the model carried out by itself. The tone is grave. The content is alarming. And read from a slightly different angle, it is one of the most effective pieces of capability marketing the industry produces.

We do not think this is cynicism. We think it is a structural feature of the format, and it is worth naming because a lot of people are now reading these documents as though they were intelligence products.

How the genre developed

OpenAI started it, publishing its first public threat report in February 2024 and settling into a roughly quarterly cadence; by late 2025 it had disrupted more than forty networks abusing its models. Those early reports were fairly conventional platform trust-and-safety work: accounts banned, patterns described, nothing extravagant claimed.

The escalation came in November 2025, when Anthropic reported that a group it designated GTG-1002, which it attributed with high confidence to a Chinese state-sponsored actor, had used Claude Code against roughly thirty organizations — and that the model had executed something like 80 to 90 per cent of the attack tasks itself. Anthropic described it as the first documented large-scale cyberattack carried out without substantial human intervention. This year the company followed up by mapping 832 accounts banned for malicious cyber activity onto the MITRE ATT&CK framework.

Google is already in this business too, with threat-intelligence publications on AI-enabled attacks running through 2026. So is every major security vendor. The genre is now standard.

Read that sentence twice

Here is the thing about “a state actor used our model to autonomously execute most of an intrusion campaign against thirty organizations.”

As a warning, it says: this capability exists, defenders should prepare. As a product claim, it says: our model can plan and execute a multi-stage operation against hardened targets with minimal supervision. Those are the same sentence. There is no way to publish the first without publishing the second, and the second happens to be precisely the capability the entire industry was selling that quarter.

We want to be careful here. We are not saying anyone fabricated anything. We are saying the format has an incentive structure that nobody has to act on deliberately for it to shape what gets published, how confidently, and when. The most alarming possible finding is also the most flattering possible demonstration. That is an unusual position for a document to be in, and it warrants more scepticism than these reports generally receive.

The part that actually bothers us

The stronger objection is technical rather than motivational.

When Anthropic published the GTG-1002 report, security researchers noticed what was missing: no IP addresses, no domains, no malware hashes, no indicators of compromise of any kind. The attribution to a Chinese state actor was asserted with high confidence and without published evidence. Several practitioners said so publicly, and some went further, questioning whether a sophisticated state group would run an operation through a monitored commercial API in the first place.

There are legitimate reasons to withhold indicators — ongoing investigations, victim confidentiality, not tipping off the actor, legal exposure. We take those seriously. But the consequence is unavoidable: a threat report with no indicators cannot change anyone’s defensive posture. You cannot search your logs for it. You cannot write a detection for it. You cannot verify it or refute it. It can only change what you believe.

Threat intelligence without indicators is not intelligence. It is a position statement in the visual language of intelligence, and the visual language is doing a lot of work.

Where this goes next

The prediction that Google would join is already overtaken; Google has been publishing on AI-enabled threats for months. The more interesting escalation is that the genre has become geopolitical in both directions. In July, Chinese authorities issued their own warning about security risks in Claude Code. Read that alongside a Western lab’s report attributing an autonomous campaign to Chinese state actors and the shape becomes clear: these documents are now instruments of national narrative as much as technical communication, and the Chinese labs producing their own versions is a matter of time rather than possibility.

None of which means the underlying trend is invented. It plainly is not. Google, CrowdStrike and Mandiant report adversarial AI use independently, from telemetry that has nothing to do with any model vendor’s marketing calendar. Attackers are using these tools, the tempo is increasing, and the defensive implications are real. The problem is not that the story is false. It is that the most-cited version of it is unverifiable and comes from an interested party.

How to read these documents

Three questions are enough, and they take a minute.

Does it contain anything I can act on? Indicators, techniques mapped to a framework, detection logic. If it does, it is intelligence and should be treated as such — Anthropic’s ATT&CK mapping work is a real contribution in a way the headline campaign report was not. If it contains only a narrative, file it under vendor communications.

Would this claim be commercially inconvenient if true? The reports worth the most attention are the ones that cost the publisher something. A report describing a capability the vendor is currently selling is not that. A report describing a failure of their own controls is.

What does it tell me about what they can see? This is the underrated one. A lab that can characterise an attacker’s full workflow from its own logs can characterise yours too. Every one of these publications is also a disclosure about the visibility your vendor has into your usage, which is a governance question worth raising before it is raised for you.

The broader point is the one we keep landing on. Your threat model should be built from your own telemetry, and your assessment of a tool should come from your own evaluation. A vendor’s account of what its product can do is useful information, but it is not neutral, and it does not become neutral because the news in it happens to be bad.

Back to Blog