Cyber Security

The human factor in AI-driven cyber security: turning awareness into stronger defence

  • AI makes cyber attacks more convincing, but most breaches still depend on a person taking action, such as clicking a link or approving a request.
  • People remain a critical line of defence, with human judgement often determining whether an attack succeeds or fails.
  • Many employees aren't prepared for AI-powered threats, making modern, role-based cyber security training more important than ever.

AI has changed cyber security. It can write convincing phishing emails, analyse targets in minutes, and help attackers scale their efforts in ways that were unimaginable just a few years ago.

But despite all that technological change, one thing remains consistent. Human decisions remain play a major role in an organisation’s defences.

As AI makes cyber attacks faster, cheaper, and more convincing, human judgement is a key differentiator. Organisations need to give people the training, processes, and support to spot potential attacks and respond appropriately. The best layer of defence is when people, processes, and technology work together.

AI has changed the game, but not the prize

For ethical hackers – cyber security professionals who are hired to hack into organisations to test their defences – and actual cyber criminals, the method hasn't changed as much as you would think.

Most of the time, a successful attack still needs someone to click a link, approve a payment, download a file, or reveal credentials. The difference is that AI has dramatically improved an attacker's ability to get to that point.

Poor spelling is no longer a reliable warning sign that a message isn’t legitimate. By drawing on information gathered from public sources or compromised communications, attackers can create messages that look authentic, reference real projects, and mimic colleagues with surprising accuracy. Research that once took hours can now take minutes. An attacker can quickly gather information about an organisation, identify likely targets, and send communications at scale.

While exposed services or vulnerabilities can be exploited without a victim responding, attacks that rely on social engineering – the exploitation of human behaviour –still depend on someone taking an action and AI makes it easier for cyber criminals to make those requests convincing.

Why humans remain the attack surface

When people think about cyber security vulnerabilities, they often think about software flaws, unsecured servers, or outdated systems. Ethical hackers often think differently.

A hurried employee, a helpful service desk, a new starter unfamiliar with internal processes, or a supplier with weak controls, can all inadvertently offer attackers a foothold.

Recent attacks continue to demonstrate that social engineering still plays a major role in security breaches. The technology does what it's supposed to do but people can be persuaded to circumvent it.

Training needs to evolve

One of the biggest challenges organisations face is that many employees are still being trained for yesterday's threats.

Traditional cyber awareness training often focuses on spotting suspicious spelling, unusual formatting, or obvious phishing attempts. Modern AI-powered attacks are not as easy to spot.

QA’s survey of 1,000 UK workers discovered that many organisations underestimate this challenge.

It found that 39% of workers had received no training on AI-powered cyber threats in the previous 12 months. Of those polled, 35% said they were not very confident or not at all confident they could recognise an AI-generated phishing email.

And while more sophisticated cyber attacks will no doubt continue to rise, the UK’s Cyber Security Breaches Survey 2025 found that 85% of businesses that identified a cyber security breach or attack had experienced phishing.

Keep training role-focused and grounded in real-life scenarios

Organisations need training that reflects today's threat landscape, particularly around AI-enabled impersonation, social engineering, and verification behaviours. Training should be tailored to realistic scenarios workers are likely to encounter in their jobs. Finance teams should receive periodic training on verifying bank-detail changes, service desks on following identity checks, and all employees on reporting suspicious requests.

Here’s a practical example: A finance employee receives an email appearing to come from a senior manager. It refers to a real supplier and asks for an urgent invoice payment to a new bank account. AI has helped the attacker produce a convincing message, with polished language and details gathered from public sources.

Rather than relying on how authentic the email looks, the employee should follow their organisation’s payment verification process. They should contact the supplier using a number already held in their records, rather than the one in the suspicious message, to verify that the bank details have changed, and if they find out anything out of order, they must report the email. If they’ve already acted, they should report it immediately so the security team can respond.

The lesson is simple: a convincing message should never replace an established verification process.

People are one of your best layers of defence

For all the discussion about AI agents, automation, and machine learning, the most important cyber security question remains simple:

What will your people do when a suspicious request arrives?

Organisations that invest in awareness, judgement, and practical security behaviours have something attackers still struggle to overcome: a workforce that knows when to stop, think, and verify.

Check out our resources and free course on Cyber Security training.

Cyber Security Awareness Month Oct 2026

Talk to our training experts

By submitting this form, you agree to QA processing your data in accordance with our Privacy Policy and Terms & Conditions. You can unsubscribe at any time by clicking the link in our emails or contacting us directly.

Related articles

New research reveals that 39% of employees have received no training on AI-powered cyber threats in the last 12 months, despite growing concern about the sophistication and scale of modern attacks.

New survey reveals 39% of employees have received no training against AI-powered cyber threats

2 October 2026

Why the human-like behaviour of AI agents is the new insider cyber threat, creating hidden enterprise risk.

The unwitting AI accomplice behind the modern insider threat

26 June 2026

AI-powered tools like Claude Mythos are transforming cybersecurity by dramatically accelerating vulnerability discovery and exploitation. Richard Beck explores why organisations must focus less on finding threats and more on reducing exposure, strengthening governance, and improving resilience against machine-speed attacks.

Taking the Myth out of Claude Mythos

28 April 2026

Discover how stealth cyber espionage is evolving – and steps your organisation can make to protect against hidden cyber security threats.

Sophisticated silent cyber espionage

1 October 2025

ISO 42001 is the world’s first certifiable AI management system standard, a playbook for running AI safely, securely, and at scale. Think ISO 27001 for AI, a repeatable, auditable framework that blends innovation with oversight. 

ISO 42001 - Balancing AI Speed & Safety

19 August 2025

Agentic AI is transforming cyber defence - not just by amplifying threats, but by empowering defenders with faster, smarter, and more autonomous response capabilities. As adversaries evolve, so must the tools and mindsets of those on the front lines.

The rise of the agentic AI defender

18 August 2025

As companies outsource more services and integrate cloud-based platforms that connect via APIs, third-party vendors, and their AI services, become part of the extended attack surface. And while these partnerships support agility and innovation, they also introduce silent threats that many cyber insurance policies are not prepared to fully address.

Cyber insurance in crisis with AI blind spots

21 July 2025

After another high-profile cyber attack, Richard Beck argues for proactive threat hunting to detect stealth ransomware – before it's too late.

How do you know you haven’t already been compromised?

7 May 2025

Richard Beck raises the alarm on the unique security risks posed by AI, and why we need a new approach to detect threats hiding under the radar of legacy frameworks.

AI security is the new zero-day, and we’re not ready

21 March 2025

Richard Beck explores how US semiconductor tariffs could fuel Chinese innovation & reshape the global computer chip race.

How the new ‘tariff wars’ will affect cyber security

18 February 2025

About the Author

Ali Kazmi