Cybersecurity has been focused on protecting systems since the field began. Firewalls, endpoint tools and monitoring platforms are all built to protect infrastructure. But attackers have adapted. They have realised that the fastest way into an organisation is often no longer through technology, but through people.
Artificial intelligence is now speeding up this tactical shift. It’s making deception techniques more persuasive, easily scalable and much more difficult to catch. What used to take time, attention and a level of skill can now be automated and improved to a level that is at a breakneck pace.
At its core, AI is not causing new problems. Social engineering has always relied on exploiting human behavioural vulnerabilities. What has changed is the speed, quality and scale of attacks. AI provides attackers a means to mimic the tone, language and even identity of someone in a manner that can be perceived to be authentic.
The Growing Levels of Sophistication
We are now witnessing attacks that work at different levels of sophistication. At the lower end, people can clone voices and produce fake videos of people using freely available tools. These tools are frequently used for scams or blackmail of individuals, and although they may not be perfect, they can still fool enough people to make their use profitable.
On a more advanced level, AI is being applied to convert phishing into something much more targeted. These lure emails are no longer generic and instead attackers are using automation to send more closely targeted emails. The language is smoother, the context is more applicable and the odds are much better that a recipient will fall victim to the lure. AI-supported spear phishing can fool more than half of its targets, according to recently published research.
At the highest level, the line between “real” and “fake” is drawn all the more vaguely. There have been deepfaked video calls to convince employees to transfer large sums of company cash where multiple attackers have impersonated senior executives in real time. Now these attacks are not about fooling a person with a poorly written email. In these cases, it is about offering a credible experience to the target that feels totally legitimate in the moment.
Why These Attacks Work
What makes these attacks effective is not just the technology, but the way they exploit human behaviour. People are more likely to trust familiar names and faces. They respond to urgency, particularly when it appears to come from a senior figure. They are also operating in environments where decisions need to be made quickly, often with incomplete information.
Decision fatigue plays a role as well. Employees are dealing with a constant stream of emails, messages, alerts and requests. Over time, it becomes harder to scrutinise every interaction in detail. Attackers understand this and design their approaches accordingly.
When People Become the Entry Point
This creates a challenge for organisations. Even with strong technical controls in place, a single action by a user can bypass them. If someone is persuaded to share credentials, approve access or install software, the attacker does not need to break in. They are effectively invited.
That is why relying on technology alone is no longer enough. Security needs to account for human behaviour. This starts with recognising that mistakes will happen and designing systems with that in mind.
Rethinking Defence Around Human Behaviour
Stronger verification of identity is essential for this. Organisations need to go beyond authentication with additional verification procedures to detect sensitive activities. Requests for access, payments or system changes should not depend on a single point of trust, especially if they originate from email or messaging platforms.
User Awareness Also Needs to Evolve
Traditional training often focuses on spotting obvious phishing attempts, but modern attacks do not always look suspicious. Training should reflect the reality of what people are likely to encounter, including voice cloning and impersonation. At the same time, organisations need to reduce the potential severity of a mistake.
Recommended reading
- UK Unveils New Cyber Bill to Protect Critical Services
- UK Public Wants More Regulation to Feel Okay About AI
- UK Gov Launches £5M Challenge Fund to Strengthen AI Security
That does, of course, mean controlling access, watching behaviour, and establishing the processes to check and respond to unusual activity quickly. There are also opportunities to leverage AI as a defensive tool. The same technology that enables attackers can also be used to identify patterns, flag anomalies and aid with faster decision making. But AI needs to figure into a wider strategy, not be viewed as a silver bullet in isolation.
A Human Problem, Not Just a Technical One
Defending against these attacks is no longer just a technical challenge. It is a human one. Understanding how people think, how they make decisions and where they are most vulnerable is becoming just as important as understanding networks and systems.
The organisations that adapt to this shift will be better placed to manage risk. Those that continue to focus solely on technology may find that their biggest vulnerability is not in their infrastructure, but in the everyday interactions of their people.





