AI phishing & social engineering
High-quality personalised messages can be generated cheaply and at scale.
- Independent verification
- Phishing-resistant authentication
- Payment/change controls
Adversary AI / 2026
AI is lowering the cost of convincing content, analysis and automation. The answer is stronger identity, faster remediation, independent verification, useful telemetry and rehearsed containment.
Attack patterns
Use controls that still stop the outcome when messages, voices, code and reconnaissance become more convincing.
High-quality personalised messages can be generated cheaply and at scale.
Familiar audio or video can create false confidence.
AI can summarise public and technical exposure faster.
AI can improve targeting around login and recovery workflows.
Capable models can help find and combine weaknesses faster.
AI can lower barriers for modifying or understanding code.
Defensive priorities
Combine prevention with fast verification and containment.
Protect high-impact accounts and recovery paths.
Reduce weaknesses that AI can discover but does not create.
Move consequential requests to a separate trusted channel.
Prioritise signals that change a decision.
Know who can revoke access, isolate systems and preserve evidence.
Leadership questions
Leaders should test whether current assumptions hold when adversaries can analyse and act faster.
Could AI-assisted attackers discover weaknesses faster than we remediate?
Could several minor weaknesses combine into serious impact?
Do we understand AI-provider and technology dependencies?
Can detection and incident decisions keep pace?
Have response and continuity plans been tested against AI-enabled scenarios?
Human-controlled AI defence
Start with the real workflow, data, identities, tools and consequences. Then place controls where they can stop harm.