Security1 publisher2 min readPublished
Horizon3 builds its machine-speed cyber case on Anthropic's 80-90% estimate
A Horizon3.ai whitepaper argues offensive operations have entered a machine-speed era. The one figure in it tied to a real campaign is Anthropic's estimate that AI ran 80 to 90 percent of the tactical work.
The Watch · Security desk

What happened
- Horizon3.ai published a whitepaper, "CyberCom 2.0 and the Revolution in AI-Enabled Offensive Cyber Operations", arguing that AI is changing the economics, speed and scale of offensive cyber operations.
- It cites Anthropic's documentation of a state-sponsored campaign in which AI executed an estimated 80 to 90 percent of tactical operations, with human operators still responsible for key decisions.
- The paper also places AI systems inside the attack surface, listing prompt injection, software supply-chain manipulation, poisoned recommendations and attacks built to influence autonomous agents.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability A crew that offloads most tactical steps to machines can run more simultaneous operations than its headcount implies, so defensive triage capacity sized against adversary staffing is sized against the wrong variable.
- decision The 10 to 20 percent left with humans tells a defender where disruption still lands on a person: objective setting, risk acceptance and authorities. Tool execution is not on that list.
- exposure The assistants, agents and MCP connectors bought to keep defensive pace are themselves in the target set, so each integration adds a reachable path into development and operations workflows.
- constraint Any capacity plan built on this figure inherits Anthropic's methodology unseen. The paper reports the number and omits the campaign details that would let a reader test it.
Eighty to ninety percent describes a share of tactical operations and does not measure what the campaign achieved [2]. It is one aggregate number spanning six phases of the intrusion lifecycle [3][2]. Human operators kept the key decisions, which leaves 10 to 20 percent of the tactical work with people [2][1].
For a defender, that split is a capacity input. If the repetitive technical work runs on machines, the volume of parallel activity a small crew can sustain stops tracking its headcount. The economics claim underneath it is that AI cuts the time and specialized expertise needed for reconnaissance, vulnerability research, code generation, reverse engineering and attack-path analysis [7]. Horizon3 goes further and projects that AI-enabled operations compress timelines from days to minutes and adapt faster than human-only operations [6]. That projection is Horizon3's own, and the 80 to 90 percent came from Anthropic [2].
The figure also arrives secondhand: Anthropic documented the campaign and Horizon3 cites it. The whitepaper page identifies the operation only as state-sponsored, with no actor, victim or date named [2][11]. So it is no evidence about any particular adversary's tooling, though it holds as an order of magnitude for how much of an intrusion can run without a person in the loop.
The paper's second argument runs the other direction. It puts AI assistants, autonomous agents, MCP-connected tools, development workflows and AI-enabled infrastructure in the target column, and names software supply-chain risk as the form that exposure takes [5][4].
The proposed answer is organizational. U.S. Cyber Command describes CYBERCOM 2.0 as its revised cyber force generation model, focused on new approaches to recruiting, developing, retaining and sustaining specialized cyber talent [8]. "AI will not eliminate the need for skilled cyber operators. It changes what those operators are responsible for," the paper says [9]. The responsibilities it leaves with humans are setting objectives, assessing risk, applying judgment and exercising authorities that cannot be delegated to an autonomous system [10].
What to watch
- Whether Anthropic publishes the per-phase breakdown, or the operator logs, behind the 80-90% estimate.
- Whether a second report documents a comparable AI-executed share in a different campaign, since one campaign is a thin basis for capacity planning.
- Whether CYBERCOM 2.0 produces published requirements or role definitions for operators commanding AI-enabled capabilities.