New survey reveals 39% of employees have received no training against AI-powered cyber threats
- A survey of 1,000 employees found that 39% have received no training on AI-powered cyber threats in the last 12 months.
- Only 25% have received dedicated training on AI-driven cyber risks.
- 35% lack confidence in spotting an AI-generated phishing email.
- 61% of non-management employees have received no AI threat training.
- Just 31% understand what their organisation's AI policy covers.
Artificial intelligence is making employees more productive, helping businesses automate routine tasks and unlocking new ways of working. But the same technology is also changing the cyber threat landscape.
New research reveals that 39% of employees have received no training on AI-powered cyber threats in the last 12 months, despite growing concern about the sophistication and scale of modern attacks.
The findings suggest many organisations may be leaving employees exposed to a new generation of cyber risks, where phishing emails, social engineering scams and fraudulent communications are increasingly enhanced by AI.
Dedicated AI cyber training remains the exception, not the rule
While AI-driven threats are becoming more common, only 25% of employees say they have received training specifically focused on these risks.
For many organisations, AI-related threats are still covered as part of broader cyber awareness programmes rather than addressed directly. As attackers leverage AI to create increasingly convincing messages, employees may not be receiving the specific knowledge needed to recognise the warning signs.
This growing skills gap is becoming more apparent as AI-generated phishing attempts become harder to distinguish from legitimate communications.
Confidence remains low when spotting AI-generated phishing attacks
The survey found that more than one-third of employees lack confidence in their ability to identify an AI-generated phishing email.
When asked how confident they would be in recognising an AI-created phishing message, 35% admitted they were either not very confident or not at all confident.
This should concern employers. Despite advancements in security technologies, employees remain one of the most important lines of defence against cyber attacks. If staff are unsure what AI-enabled threats look like, organisations could face increased exposure to security breaches, data loss and financial fraud.
A growing disconnect between leaders and frontline employees
One of the most striking findings from the research is the difference in confidence between senior leaders and the wider workforce.
Almost half (48%) of owners and partners believe they would be very confident in identifying an AI-generated phishing email. Among non-management employees, however, that figure drops to just 9%.
The training gap is equally significant.
Six in ten (61%) non-management employees report receiving no training on AI-driven cyber threats, suggesting that those most likely to encounter suspicious emails and messages in their day-to-day roles may be receiving the least support.
AI governance is still maturing
The survey also highlights broader challenges around organisational AI readiness.
Over one in five employees (22%) say their organisation has no AI policy in place. A further proportion are unsure whether one exists at all, meaning almost half of employees either lack an AI policy or are unaware of one.
Even where policies are established, understanding appears limited. Just 31% of respondents say their organisation has an AI policy and that they know what it covers.
Without clear AI governance, organisations risk creating uncertainty around the safe and responsible use of AI technologies.
|
Job level |
Very confident they'd spot an AI-written phishing email |
Had specific training on AI-driven threats |
Know what their AI policy covers |
|
Owner or partner |
48% |
48% |
59% |
|
Board director |
33% |
44% |
37% |
|
Senior manager |
31% |
29% |
40% |
|
Manager |
18% |
24% |
28% |
|
Non-management |
9% |
8% |
15% |
The need for stronger AI cyber awareness
The research paints a clear picture. AI is no longer an emerging technology. It is already reshaping both the way organisations work and the way cyber criminals operate. Yet training, awareness and governance are not always keeping pace.
With 39% of employees receiving no training on AI-powered cyber threats, and only a quarter receiving dedicated instruction on these risks, organisations have an opportunity to strengthen their human defences before the next generation of AI-enabled attacks becomes the norm.
As AI tools continue to evolve, building employee awareness may prove just as important as investing in new security technologies.
Get in touch with our experts to prepare your organisation against AI cyber security threats
A TLF survey of 1,000 workers conducted 24/09/2026
Related articles
Why the human-like behaviour of AI agents is the new insider cyber threat, creating hidden enterprise risk.
The unwitting AI accomplice behind the modern insider threat
26 June 2026
The question is no longer whether you are secure, it‘s how long you remain exposed after you know you are not.
Taking the Myth out of Claude Mythos
28 April 2026
Discover how stealth cyber espionage is evolving – and steps your organisation can make to protect against hidden cyber security threats.
Sophisticated silent cyber espionage
1 October 2025
ISO 42001 is the world’s first certifiable AI management system standard, a playbook for running AI safely, securely, and at scale. Think ISO 27001 for AI, a repeatable, auditable framework that blends innovation with oversight.
ISO 42001 - Balancing AI Speed & Safety
19 August 2025
Agentic AI is transforming cyber defence - not just by amplifying threats, but by empowering defenders with faster, smarter, and more autonomous response capabilities. As adversaries evolve, so must the tools and mindsets of those on the front lines.
The rise of the agentic AI defender
18 August 2025
As companies outsource more services and integrate cloud-based platforms that connect via APIs, third-party vendors, and their AI services, become part of the extended attack surface. And while these partnerships support agility and innovation, they also introduce silent threats that many cyber insurance policies are not prepared to fully address.
Cyber insurance in crisis with AI blind spots
21 July 2025
After another high-profile cyber attack, Richard Beck argues for proactive threat hunting to detect stealth ransomware – before it's too late.
How do you know you haven’t already been compromised?
7 May 2025
Richard Beck raises the alarm on the unique security risks posed by AI, and why we need a new approach to detect threats hiding under the radar of legacy frameworks.
AI security is the new zero-day, and we’re not ready
21 March 2025
Richard Beck explores how US semiconductor tariffs could fuel Chinese innovation & reshape the global computer chip race.
How the new ‘tariff wars’ will affect cyber security
18 February 2025
How updated cyber security frameworks can protect against data manipulation, supply chain attacks, and other threats posed by malicious AI.
Adversarial AI threatens our financial services. We need a response.
22 January 2025
About the Author
Sam Store