Cyber Security

New survey reveals 39% of employees have received no training against AI-powered cyber threats

  • A survey of 1,000 employees found that 39% have received no training on AI-powered cyber threats in the last 12 months.
  • Only 25% have received dedicated training on AI-driven cyber risks.
  • 35% lack confidence in spotting an AI-generated phishing email.
  • 61% of non-management employees have received no AI threat training.
  • Just 31% understand what their organisation's AI policy covers.

Artificial intelligence is making employees more productive, helping businesses automate routine tasks and unlocking new ways of working. But the same technology is also changing the cyber threat landscape.

New research reveals that 39% of employees have received no training on AI-powered cyber threats in the last 12 months, despite growing concern about the sophistication and scale of modern attacks.

The findings suggest many organisations may be leaving employees exposed to a new generation of cyber risks, where phishing emails, social engineering scams and fraudulent communications are increasingly enhanced by AI.


Dedicated AI cyber training remains the exception, not the rule

While AI-driven threats are becoming more common, only 25% of employees say they have received training specifically focused on these risks.

For many organisations, AI-related threats are still covered as part of broader cyber awareness programmes rather than addressed directly. As attackers leverage AI to create increasingly convincing messages, employees may not be receiving the specific knowledge needed to recognise the warning signs.

This growing skills gap is becoming more apparent as AI-generated phishing attempts become harder to distinguish from legitimate communications.

Confidence remains low when spotting AI-generated phishing attacks

The survey found that more than one-third of employees lack confidence in their ability to identify an AI-generated phishing email.

When asked how confident they would be in recognising an AI-created phishing message, 35% admitted they were either not very confident or not at all confident.

This should concern employers. Despite advancements in security technologies, employees remain one of the most important lines of defence against cyber attacks. If staff are unsure what AI-enabled threats look like, organisations could face increased exposure to security breaches, data loss and financial fraud.

A growing disconnect between leaders and frontline employees

One of the most striking findings from the research is the difference in confidence between senior leaders and the wider workforce.

Almost half (48%) of owners and partners believe they would be very confident in identifying an AI-generated phishing email. Among non-management employees, however, that figure drops to just 9%.
The training gap is equally significant.

Six in ten (61%) non-management employees report receiving no training on AI-driven cyber threats, suggesting that those most likely to encounter suspicious emails and messages in their day-to-day roles may be receiving the least support.

AI governance is still maturing

The survey also highlights broader challenges around organisational AI readiness.
Over one in five employees (22%) say their organisation has no AI policy in place. A further proportion are unsure whether one exists at all, meaning almost half of employees either lack an AI policy or are unaware of one.

Even where policies are established, understanding appears limited. Just 31% of respondents say their organisation has an AI policy and that they know what it covers.
Without clear AI governance, organisations risk creating uncertainty around the safe and responsible use of AI technologies.


Job level 

Very confident they'd spot an AI-written phishing email 

Had specific training on AI-driven threats 

Know what their AI policy covers 

Owner or partner 

48% 

48% 

59% 

Board director 

33% 

44% 

37% 

Senior manager 

31% 

29% 

40% 

Manager 

18% 

24% 

28% 

Non-management 

9% 

8% 

15% 

The need for stronger AI cyber awareness

The research paints a clear picture. AI is no longer an emerging technology. It is already reshaping both the way organisations work and the way cyber criminals operate. Yet training, awareness and governance are not always keeping pace.

With 39% of employees receiving no training on AI-powered cyber threats, and only a quarter receiving dedicated instruction on these risks, organisations have an opportunity to strengthen their human defences before the next generation of AI-enabled attacks becomes the norm.

As AI tools continue to evolve, building employee awareness may prove just as important as investing in new security technologies.

Get in touch with our experts to prepare your organisation against AI cyber security threats

A TLF survey of 1,000 workers conducted 24/09/2026

Get in touch to build your team's awareness of emerging AI cyber security threats

By submitting this form, you agree to QA processing your data in accordance with our Privacy Policy.

Related articles

Why the human-like behaviour of AI agents is the new insider cyber threat, creating hidden enterprise risk.

The unwitting AI accomplice behind the modern insider threat

26 June 2026

The question is no longer whether you are secure, it‘s how long you remain exposed after you know you are not.

Taking the Myth out of Claude Mythos

28 April 2026

Discover how stealth cyber espionage is evolving – and steps your organisation can make to protect against hidden cyber security threats.

Sophisticated silent cyber espionage

1 October 2025

ISO 42001 is the world’s first certifiable AI management system standard, a playbook for running AI safely, securely, and at scale. Think ISO 27001 for AI, a repeatable, auditable framework that blends innovation with oversight. 

ISO 42001 - Balancing AI Speed & Safety

19 August 2025

Agentic AI is transforming cyber defence - not just by amplifying threats, but by empowering defenders with faster, smarter, and more autonomous response capabilities. As adversaries evolve, so must the tools and mindsets of those on the front lines.

The rise of the agentic AI defender

18 August 2025

As companies outsource more services and integrate cloud-based platforms that connect via APIs, third-party vendors, and their AI services, become part of the extended attack surface. And while these partnerships support agility and innovation, they also introduce silent threats that many cyber insurance policies are not prepared to fully address.

Cyber insurance in crisis with AI blind spots

21 July 2025

After another high-profile cyber attack, Richard Beck argues for proactive threat hunting to detect stealth ransomware – before it's too late.

How do you know you haven’t already been compromised?

7 May 2025

Richard Beck raises the alarm on the unique security risks posed by AI, and why we need a new approach to detect threats hiding under the radar of legacy frameworks.

AI security is the new zero-day, and we’re not ready

21 March 2025

Richard Beck explores how US semiconductor tariffs could fuel Chinese innovation & reshape the global computer chip race.

How the new ‘tariff wars’ will affect cyber security

18 February 2025

How updated cyber security frameworks can protect against data manipulation, supply chain attacks, and other threats posed by malicious AI.

Adversarial AI threatens our financial services. We need a response.

22 January 2025

About the Author

Sam Store

Sam combines a journalism background with expertise in SEO and marketing analytics, transforming research, survey data and industry trends into insight-led content
More about the author