Views Bangladesh Logo

Bangladesh on global map of AI misuse

Rased Mehedi

Rased Mehedi

Our discussion of artificial intelligence usually gets stuck at two extremes. At one end is the story of limitless possibilities: more jobs, easier access to services, and faster national development. At the other is the fear of a distant future—whether machines will one day surpass humans. What receives far less attention is the space in between: who is using AI to cause harm today, and how. The information needed to answer that question largely sits on the servers of technology companies. Unless they choose to disclose it, the rest of us know very little.

On September 10, US-based AI company Anthropic published a report titled Detecting and Countering Misuse of AI: September 2026. It documents cases of misuse of its AI model Claude that the company detected and disrupted between December 2025 and August 2026. The report covers seven areas: cyberattacks, influence operations, surveillance, fraud, biological misuse, weapons development and model theft.

This time, Bangladesh appears by name as a full case study. That makes the report more than just another foreign technology report for us.

A natural question arises first: why would a company voluntarily publish a catalogue of how its own product has been misused?

Anthropic's stated rationale is that it considers disclosure part of its responsibility. The more capable AI models become, the greater the risks they pose, and those risks cannot be managed unless developers and society confront them together.

There are practical calculations behind this as well. Governments around the world are developing laws to regulate AI. A company that demonstrates a willingness to disclose what is happening inside its own ecosystem inevitably approaches the regulatory table from a different position. A second reason is collective defence.

According to the report, Anthropic shut down accounts involved in the incidents, strengthened its security measures and, where appropriate, shared information with relevant authorities and industry partners. A third objective is to identify patterns so that other developers can recognise similar behaviour on their own platforms.

Yet one point must remain clear: this is voluntary disclosure, not an independent audit. What is disclosed, how much is disclosed and how it is presented are all decisions made by the company itself. We can and should use the information as journalists, but without losing sight of the nature of the source. Bangladesh still lacks an independent capacity to verify information of this kind. That is our first vulnerability.

The report's central observation can be put simply: AI is not necessarily creating entirely new forms of crime; it is lowering the cost of committing old ones.

The techniques described in the attacks are familiar—stolen passwords, unpatched devices, exposed services and phishing. What has changed is the economics. Tasks that once required considerable labour—gathering information, identifying vulnerabilities, developing tools and organising stolen data—were largely within the reach of well-resourced organisations. They can now be carried out in parallel by AI agents.

The result is a narrowing of the capability gap. According to Anthropic, three very different categories of actors—a hacktivist using a stolen API key, an independent criminal motivated by financial gain and a state-linked operative—have all conducted multi-target campaigns that, only a year ago, would likely have required a skilled team. The key difference between them is increasingly not capability, but intent.

There is another development that is even more troubling from a defensive perspective. In one Russian espionage campaign, an AI agent reportedly monitored whether security software was detecting the malware being used. When detection occurred, the agent modified the malware and redeployed it until it was no longer detected.

For years, one of the most effective defensive advantages has been the ability to impose costs on attackers—to force them to adapt to new detection methods and thereby slow them down. That advantage is now shrinking.

The AI supply chain itself has also become a target. Stolen API keys and session tokens can give attackers three things at once: something that can be sold, computing resources paid for by someone else, and a layer of anonymity, because the activity appears to originate from the legitimate owner of the compromised credentials.

As Bangladesh's banks, mobile operators, mobile financial services providers and government projects rush to integrate AI, the warning is directly relevant to us: AI keys must be protected with the same seriousness as production passwords. Buying AI services cheaply through unauthorised intermediaries can effectively amount to handing the keys to one's own house to a stranger.

Among the nine incidents described in the report's influence-operations section is one centred on Bangladesh, internally identified as GTG-54006.

According to Anthropic, an individual operating from Gaibandha used 29 Claude accounts over roughly 16 months to produce fake news content in Bangla—at least 1,500 headlines, 300 fabricated reports and 1,500 image-generation prompts. The accounts were rotated in an apparent effort to evade both usage limits and detection.

The nature of the operation is particularly revealing. This was not an impulsive social-media campaign or the occasional fabricated post by an individual. It functioned more like a production line.

A programme named “fake_news_3.py” reportedly generated content in batches: 15 headlines, three articles and 15 image prompts at a time. Since Claude does not generate images, those prompts were presumably intended for use with other AI systems. A second script uploaded videos to YouTube according to a schedule set a month in advance.

Third-party services were used to conceal the operator's location. In other words, planning, production, distribution and concealment had all been automated.

The content was distributed through Facebook Live, YouTube and TikTok, targeting rural audiences with limited literacy. The material was broadly aligned with the interests of the Awami League and hostile towards its opponents. The BNP, Jamaat-e-Islami and the National Citizens' Committee were portrayed as seeking to establish Taliban-style rule and infiltrate the security forces.

Other narratives alleged assassination attempts against members of the interim government and leaders of the student movement, portraying them as agents of foreign intelligence services.

The report says the operator was fully aware that the content was fabricated. One of the operator's own notes reportedly stated: “no one knows the news is fake.” The instructions also called for language that was heated and aggressive and easily understandable to rural audiences.

This is the most disturbing aspect of the case. Disinformation was not a side effect of the operation; it was the product. And rural, less-literate audiences were not accidental victims. They were the intended consumers.

Professionalism in dealing with a report like this requires knowing where its evidence ends. Anthropic explicitly says that although the content was consistent with the interests of the Awami League, it found no evidence that the party itself operated or funded the campaign.

The report also notes that some narratives were consistent with pro-India geopolitical interests. But it does not name any Indian individual, organisation or platform, nor does it allege Indian involvement. It likewise found no evidence of government direction or financing.

The report is cautious about the campaign's reach as well. Not all accounts involved in the dissemination could be identified, and Anthropic says it has no evidence showing how far the content travelled beyond the identified network. On the Brookings Breakout Scale, the incident was placed in the third category: it spread across multiple platforms, but there was no evidence of extensive, verified public engagement.

That restraint is something our own media should learn from. It is easy to take a sentence from a foreign report and turn it into a political weapon. But doing so risks obscuring the report's more important lesson.

This is where the most important question lies.

The operation was detected at the production stage—before the content had fully spread. Anthropic says that while social-media platforms often detect content after it has been disseminated, its systems were able to identify the operation while it was being developed.

That means an operation running for roughly 16 months within Bangladesh's information environment was detected not by any Bangladeshi institution, but by the internal systems of a private company thousands of miles away.

This is not simply a coincidence. It is structural.

Our regulatory framework has largely been built around responding after publication: removing links, shutting down pages and, where necessary, filing cases. But a system that sees only the outcome and not the production process will never be able to keep pace with an automated content factory. By the time it takes to remove one piece of content, another 15 may already have been generated.

We have made this mistake repeatedly in the telecommunications sector. Even as technology changed, regulatory structures remained rooted in older assumptions. Ordinary users ultimately paid the price.

Bangladesh needs a national coordination point for regular threat-intelligence sharing with AI companies and major digital platforms. If Anthropic or another technology company identifies an operation involving Bangladesh, who should it notify—the Bangladesh Telecommunication Regulatory Commission, the cyber-security agency or the Election Commission? There is no sufficiently clear answer today.

There needs to be one, and it needs to be visible.

Digital campaign spending and vendor transparency must also become mandatory in elections. The report's description of a Malaysia-based commercial platform offers a direct warning. The platform reportedly created profiles for 222 constituencies using genuine census and voter data, operated roughly a thousand fake accounts and targeted audiences along ethnic and religious fault lines.

The lesson for Bangladesh is straightforward: influence can now be purchased as a service, and concealing the identity of the buyer can itself be one of the service's principal selling points.

News organisations also need to rethink their verification priorities. Instead of chasing individual pieces of fake news one by one, greater attention should be paid to distribution networks and recurring behavioural patterns. Multiple accounts appearing simultaneously, headlines generated from the same template and videos uploaded according to the same schedule may now provide more meaningful clues than any single piece of content.

Institutions, meanwhile, need to strengthen the security of their AI integrations. Once an AI key is compromised, it is not merely data that may be lost; the identity and credibility of the institution itself can be compromised.

One final point requires particular caution. The Bangladesh section of the Anthropic report is not a charge sheet against any political party. It is a technical account showing how one individual, a laptop and several accounts can potentially operate a large-scale disinformation factory. The tools that were in the hands of one side today can be in anyone else's hands tomorrow. The technology itself has no political preference.

The question, therefore, is not partisan. As Bangladesh moves into an election year, can we build an institutional response to this new reality—or will we, as before, wait for each incident to occur and then satisfy ourselves with issuing another statement?

Rased Mehedi

Telecommunications and Information Technology Sector Analyst; Editor, Views Bangladesh



Leave A Comment

Avatar

Trending Views