Adversary AI / 2026

Assume attackers can move faster. Make trust harder to fake.

AI is lowering the cost of convincing content, analysis and automation. The answer is stronger identity, faster remediation, independent verification, useful telemetry and rehearsed containment.

IdentityVerify ExposureReduce TelemetryObserve ResponseRehearse

Attack patterns

AI accelerates existing cyber activity and pressure.

Use controls that still stop the outcome when messages, voices, code and reconnaissance become more convincing.

01

AI phishing & social engineering

High-quality personalised messages can be generated cheaply and at scale.

  • Independent verification
  • Phishing-resistant authentication
  • Payment/change controls
02

Cloned voice & deepfake video

Familiar audio or video can create false confidence.

  • Known callback channel
  • Second approval
  • Shared verification phrases
03

Automated reconnaissance

AI can summarise public and technical exposure faster.

  • Reduce exposure
  • Asset inventory
  • Monitor leaked credentials
04

Credential attacks

AI can improve targeting around login and recovery workflows.

  • Passkeys/phishing-resistant MFA
  • Session monitoring
  • Recovery hardening
05

Vulnerability discovery & chaining

Capable models can help find and combine weaknesses faster.

  • Patch high-risk issues
  • Harden configurations
  • Reduce attack paths
06

Malicious-code assistance

AI can lower barriers for modifying or understanding code.

  • Application control
  • Endpoint detection
  • Least privilege and segmentation

Defensive priorities

Shorten the distance between signal and safe action.

Combine prevention with fast verification and containment.

01

Identity first

Protect high-impact accounts and recovery paths.

02

Patch and harden

Reduce weaknesses that AI can discover but does not create.

03

Out-of-band verification

Move consequential requests to a separate trusted channel.

04

Useful detection

Prioritise signals that change a decision.

05

Rehearsed response

Know who can revoke access, isolate systems and preserve evidence.

Leadership questions

AI changes speed, scale and risk tolerance.

Leaders should test whether current assumptions hold when adversaries can analyse and act faster.

01

Exposure

Could AI-assisted attackers discover weaknesses faster than we remediate?

02

Chaining

Could several minor weaknesses combine into serious impact?

03

Supply chain

Do we understand AI-provider and technology dependencies?

04

Response speed

Can detection and incident decisions keep pace?

05

Exercises

Have response and continuity plans been tested against AI-enabled scenarios?

Human-controlled AI defence

Build capability without losing authority.

Start with the real workflow, data, identities, tools and consequences. Then place controls where they can stop harm.