Evidence over alarm
WHY FAULTLINES EXISTS

Pay attention.
Stay grounded.

A public guide to a changing security landscape. Built for readers, journalists, producers, and anyone who wants to understand what AI is doing in the world.

EDUCATION, NOT ALARM

Take the risks seriously.
Take the evidence seriously, too.

AI is becoming part of how cyber operations are carried out—and sometimes part of what goes wrong. Understanding that change should not require a technical background.

Faultlines turns individual incidents into accessible explanations. We make the mechanisms visible, connect related cases, and help readers distinguish confirmed outcomes from possible consequences.

We do not use an invented threat score, a forecast of catastrophe, or a cumulative curve dressed up as proof of acceleration. The collection can reveal changes in capability and behavior. It cannot measure worldwide attack rates.

OUR EDITORIAL METHOD

Every dot needs a story.
Every story needs evidence.

  1. Count incidents, not articles.

    We normalize individual campaigns or connected evaluation incidents. Multiple reports about the same sequence update one record. Four test runs against the same company count as one case; the connected Hugging Face sequence also counts once.

  2. Separate AI’s different roles.

    Malicious use, evaluation incidents, attacks on AI, and related fraud carry explicit labels. A fake AI product does not prove an AI performed the attack. A laboratory failure is not automatically a malicious-user campaign.

  3. Keep two clocks.

    “Disclosed” is when the case became public. “Activity” is when it happened. We preserve month-level dates, uncertain ranges, and unknown dates. An imprecise source date never becomes an invented exact day. A reporting window is not an individual attack window.

  4. Distinguish reports from verification.

    Source attribution is visible on each case. Provider disclosures describe what their investigations found; that is not independent confirmation. Affected-party accounts and independent reviews appear alongside them when available, with their limits.

  5. Explain what happened—and what did not.

    We separate attempts from successful access, access from data theft, and reach from demonstrated loss. We include containment, remediation, and uncertainty alongside serious findings. Analogies explain a mechanism without adding facts.

  6. Keep explanations useful, not operational.

    The goal is understanding. Walkthroughs show actions and boundaries, not exploit commands or instructions for reproducing an attack.

HOW TO READ THE RISING GRAPHIC

A change in role.
Not an invented threat score.

The staircase is an editorial explanation of broader AI involvement in three selected human-directed campaigns: assistance with individual tasks in a 2024 disclosure, help executing intrusions in an August 2025 report, and a coordinated sequence of tasks in a November 2025 report. Each step names a source and separates the AI’s work from the human’s decisions.

Height and horizontal spacing are schematic. They do not measure damage, frequency, autonomy as a numerical score, or elapsed time. The dates are publication dates, and these are not claims about when a capability first became possible.

The 2026 cases appear alongside the staircase. Multi-agent coordination was already reported in 2025; a later example does not establish a new level of autonomy. Evaluation failures are labeled separately from malicious use. This design makes changes in the public record understandable without turning unlike cases into a single severity ranking.

The collection now includes three additional 2024–2025 cases from primary Microsoft, OpenAI, and Anthropic reports. Those cases give the original 2026 coverage an earlier reference point.

A NOTE FOR JOURNALISTS

Be careful what a number counts.

Targets ≠ victims

A system scanned or selected may never have been compromised.

Agents ≠ attacks

Hundreds of agents may participate in a single connected incident.

Access ≠ full extraction

Being able to reach data does not establish that all of it was copied.

Disclosure ≠ occurrence

Many dots in one month can mean one report published several earlier cases.

This is a selected collection starting from three supplied reports, expanded with earlier primary reports and supporting investigations. It is not representative of all AI incidents, all providers, or all countries. Publication choices, monitoring coverage, and detection gaps affect what is visible.

Download the source-linked dataset
THE STARTING POINT

Three reports.
Individual stories inside.

01
An alignment assessment of recent cybersecurity incidentsAnthropic · Sep 9, 2026
02
The Hugging Face incident and the road aheadOpenAI · Aug 26, 2026
03
Detecting and countering misuse of AI: September 2026Anthropic · September 2026

Supporting sources are linked on the relevant case pages. Incident accounts are attributed to their sources. Inclusion does not imply endorsement by the organizations covered.

Browse the original report library ↗
THE AI SECURITY FRAMEWORK

Turn understanding into better questions.

The framework adapts a user-supplied Abnormal AI security concept into five general capability areas, adding software security. It draws on NIST, OWASP, and NCSC/CISA guidance; it is our editorial synthesis, not a new formal standard, certification, or product evaluation.

Incident-to-defense links explain relevance, not guaranteed prevention. Controls for an organization’s own agents are distinguished from defenses against an external attacker’s AI. Abnormal’s public descriptions are labeled as vendor claims, with their roadmap limits; the supplied marketing concept is not treated as proof of product availability.

Read the framework sources and provider guidance ↗
A RECORD THAT CAN GROW

New evidence should
change the picture.

The site is built around structured incident records. New sources can add a case, refine an existing one, or correct an earlier interpretation. The library, timeline, topic pages, and downloadable dataset all derive from the same records.

Collection updated: Sep 11, 2026. Daily research looks for new public disclosures and corrections. New material is published after source review and site checks; automated structural checks cannot independently verify a publisher’s claims. There is no guarantee that every important incident is included.

Featured reading gives priority to well-sourced OpenAI and Anthropic cases and keeps an enduring explainer alongside new material. Prominence is an editorial reading choice, not a ranking of severity. See additions and corrections →

Found an error? Save the case link and the primary source that supports the correction. The project’s editorial workflow is included with the source code for the maintainer to review updates.