Dear {{ first_name | reader }},
On 10 September 2026, Anthropic published a document that most communication professionals will read as a story about Anthropic. That is the wrong frame.
Read it as a story about your organisation and you will find a detailed catalogue of crises that have already happened to real organisations – crises they were not prepared for, at speeds their response doctrines were never built to handle.
The report documents AI-orchestrated intrusions that escalated from a single stolen token to full administrative control in under three hours. Supply-chain attacks reached 200 downstream customer organisations before the root victim knew anything had happened. Executives were impersonated by synthetic personas trained on thousands of their own messages, then deployed in live conversations with their real contacts. Fabricated news networks ran content in twenty languages. Fabricated dossiers citing real but manipulated documents were submitted to regulators against named individuals.
None of these are forecasts. They are documented, completed operations, disrupted between December 2025 and August 2026 – which means someone has already run them against real organisations, and those organisations were not ready.
So, what does this mean for Risk and Crisis Communicators?
Let’s find out…
WAG THE DOG NEWSLETTER | ISSUE WEEK 38, 2026
KEY TAKEAWAYS
The traditional response window is gone, and most crisis plans have not noticed. The documented breaches complete in two to three hours, with AI agents performing most of the work. A 24-to-48-hour internal alignment window before a first public statement is not caution – it is an artefact of a speed regime that no longer exists for a growing class of incidents.
Supply-chain crises will now reach you through an extortionist's announcement, not your vendor's notification. A SaaS compromise cascaded to roughly 200 downstream organisations; a second exfiltrated data from thousands of downstream customers. Your crisis may begin as someone else's breach disclosure, or as a threat actor staging your data publicly to pressure a third party you have barely met.
"Sophisticated attacks no longer require sophisticated attackers" has a direct communication corollary. In Bangladesh, one operator created over 1,500 fake headlines and 300 false narratives using an automated system. During future crises, the volume of harmful content could overwhelm your ability to correct it. "Respond to everything" is not a strategy; it's a way to exhaust your team on content that isn't being widely shared.
Naming a state-linked actor in a corporate disclosure converts it into a diplomatic instrument, whether you intended that or not. The window for framing the conversion on your terms is just hours. China's Commerce Ministry responded within 48 hours, threatened countermeasures, and a named company banned employee use of the product. Disclosure doctrine should be decided calmly without a deadline, not improvised during the incident.
The organisations that handled these crises best are not in the report at all. They are the ones whose situations were disrupted upstream, before any audience formed. The next best position is one built before the machines arrive: relationships with the right people, response windows that match the threat's speed, and doctrine that does not require a 2am committee decision on something you should have resolved six months ago.

