Every Request Looked Benign. The Campaign Did Not.
A safety system can make a reasonable decision about each individual interaction and still fail to recognize the meaning of the sequence those interactions form together.
In its September 2026 threat-intelligence report, Anthropic described malicious actors decomposing harmful work across multiple interactions and sessions. In one documented campaign, Claude refused most directly malicious requests, but safeguards were less consistent when the user divided the work into smaller requests so that no single session exposed the full malicious objective.
This is a reported real-world misuse case from the model provider’s own threat investigation. It is not an independently adjudicated finding, and GovKM treats the vendor’s attribution and characterization accordingly.
Session boundaries became context boundaries
The operational problem is broader than cybersecurity. If the system evaluates only the immediate interaction, it may correctly classify each local request while failing to reconstruct the cumulative intent expressed across prior actions.
In continuity terms, the break sits between Record, Institutional Memory, and current Context. Previous interactions existed as records, but the current decision did not necessarily inherit enough of their meaning to evaluate the trajectory as a whole.
The topology can be expressed as: Record / prior sessions → Institutional Memory → Context / current request → Decision. When that relationship is incomplete, locally acceptable actions can compose into a globally unacceptable sequence.
Fragmentation can be an active control weakness
Organizations often treat session boundaries, ticket boundaries, repositories, applications, and business units as convenient containers. Those boundaries are not necessarily meaningful to the underlying institutional activity. An actor, objective, obligation, threat, or decision can persist across all of them.
GovKM interprets the Anthropic report as evidence that contextual continuity can be a security control. A continuity-aware system should be capable of reconstructing relevant lineage across interactions while still applying appropriate privacy, minimization, authority, and retention rules.
The principle is simple: each transaction may be permissible while the continuous sequence is not.
Source
Anthropic Threat Intelligence, “Detecting and Countering Misuse of AI: September 2026,” September 2026.



