Anthropic's Misuse Report and the Horizontal Expansion of Algorithmic Risk
The Report That Changes the Governance Conversation
Anthropic released findings this week documenting a structural shift in how AI systems are being misused. The report moves well beyond the familiar narrative of individual bad actors running simple scams. According to Anthropic, AI misuse has entered a new operational phase, one characterized by coordinated deployment across cybercrime, surveillance infrastructure, propaganda generation, and weapons development. The defining feature of this shift is not the severity of any single incident but the collapse in the cost required to scale attacks. What previously demanded significant human coordination and technical expertise now requires neither.
This is a specific empirical claim, and it deserves specific analytical attention. The question I want to address here is not whether AI misuse is bad - that is obvious. The question is why existing governance structures are systematically unprepared for this particular kind of threat expansion, and what organizational theory tells us about why that gap persists.
Boards Were Built for a Vertical World
A separate piece circulating in business news this week carries a headline worth sitting with: "Boards were built for a vertical world. Risk has gone horizontal." The framing is more precise than it might appear. Traditional corporate governance assumes that risks can be traced upward through chains of accountability. A product fails, a division is responsible, an executive is answerable. The board reviews outcomes that fit neatly into organizational hierarchies. The Anthropic misuse findings describe something structurally different. When AI lowers the cost of surveillance and propaganda to near zero, the threat does not originate inside any vertical chain. It distributes across actors, platforms, and jurisdictions simultaneously.
This is not a technology problem dressed up as a governance problem. It is a genuine coordination failure at the level of institutional design. Rahman (2021) described how algorithmic systems function as invisible cages - structuring behavior without legible rules - and the misuse patterns Anthropic documents are precisely the inverse: actors using AI's structural opacity as an offensive weapon against organizations that still assume risks arrive in legible, traceable forms.
The Awareness-Capability Gap at the Institutional Level
My dissertation research focuses on a specific puzzle in platform coordination: workers consistently develop awareness of algorithmic systems without developing the capability to respond effectively to them. I call this the awareness-capability gap. The Anthropic report suggests this gap operates at the institutional level as well. Boards and executive teams are increasingly aware that AI misuse is a threat category. Awareness has diffused widely. What has not diffused is the structural schema required to act on that awareness in consequential ways.
The distinction matters. Kellogg, Valentine, and Christin (2020) established that algorithmic systems at work create asymmetries where those inside the system - workers, users, organizations - lack the structural visibility that those designing or weaponizing the system possess. Anthropic's findings suggest that malicious actors are operating with far more structural understanding of AI capabilities than the governance bodies nominally responsible for managing organizational risk. That is not an awareness problem. It is a schema problem, and schemas require deliberate induction, not passive exposure.
Why Procedural Responses Will Fail
The predictable institutional response to a report like Anthropic's is procedural: add AI to the risk register, update the cybersecurity policy, brief the board quarterly. This is the organizational equivalent of what Hatano and Inagaki (1986) called routine expertise - competence defined by following established procedures in familiar conditions. Routine expertise fails precisely when conditions shift structurally, which is what Anthropic is documenting. The misuse landscape is not cycling through familiar attack patterns. It is reorganizing around a new cost structure.
Adaptive expertise, by contrast, requires understanding the structural principles that generate surface-level phenomena. For governance bodies, this means developing accurate schemas about how AI systems amplify coordination capacity for adversarial actors, not just familiarity with the specific attack types listed in last quarter's threat briefing. Gentner's (1983) structure-mapping theory is useful here: transfer of understanding to novel situations depends on recognizing structural analogies, not surface similarities. A board that has only learned to recognize last year's AI threat patterns will not transfer that knowledge to next year's configurations.
What This Actually Requires
The Anthropic report is useful precisely because it names a structural transition rather than cataloguing individual incidents. The implication for organizational governance is direct: institutions need what I would describe as schema-level literacy about AI systems, not procedural checklists derived from past incidents. Schor et al. (2020) noted that platform dependence creates precarity because workers lack structural understanding of the systems governing their outcomes. The governance analog is organizations becoming precarious relative to AI-enabled threats because their risk frameworks describe a topology that no longer matches the actual terrain. Knowing that risk has gone horizontal, to use this week's framing, is the beginning of the problem, not the solution to it.
References
Gentner, D. (1983). Structure-mapping: A theoretical framework for analogy. Cognitive Science, 7(2), 155-170.
Hatano, G., & Inagaki, K. (1986). Two courses of expertise. In H. Stevenson, H. Azuma, & K. Hakuta (Eds.), Child development and education in Japan (pp. 262-272). Freeman.
Kellogg, K. C., Valentine, M. A., & Christin, A. (2020). Algorithms at work: The new contested terrain of control. Academy of Management Annals, 14(1), 366-410.
Rahman, K. S. (2021). The invisible cage: Workers' reactivity to opaque algorithmic evaluations. Administrative Science Quarterly, 66(4), 945-988.
Schor, J. B., Attwood-Charles, W., Cansoy, M., Ladegaard, I., & Wengronowitz, R. (2020). Dependence and precarity in the platform economy. Theory and Society, 49(5), 833-861.
Roger Hunt