For years, "AI in cybersecurity" mostly meant one thing: better defense. Smarter detection, faster response, fewer false positives. That story is still true, but it's now only half the picture.
The same generative AI tools that help security teams work faster are helping attackers work faster too. Phishing emails that once took hours to write and still sounded slightly off now take minutes and read like they came from a colleague. Voice cloning and deepfake video, once expensive and clumsy, are now good enough to fool finance teams on a live call.
The result is a threat landscape that looks less like a technical arms race and more like a trust crisis because the weak point AI attacks most effectively isn't a firewall, it's a person.
Here's what that actually looks like right now and what organizations can do about it.
AI Has Made Phishing Faster, Cheaper, and Far More Convincing

Traditional phishing had a tell: awkward phrasing, generic greetings, obvious urgency cues. Generative AI has largely erased that tell. Recent industry breach research puts AI-generated content in the large majority of phishing emails now in circulation, and separate testing has found that fully AI-automated spear-phishing campaigns can perform on par with — or better than — phishing written by experienced human attackers.
The economics have shifted too. Research from AI-security firm Brightside found that generative tools have cut the time needed to research, personalize, and send a convincing targeted attack from roughly sixteen hours down to under five minutes. That means one attacker can now run the kind of personalized, well-researched campaign that used to require a small team — against dozens of targets at once, in multiple languages, referencing real details about the target's company or role.
The channels have expanded as well. It's no longer just email. QR-code phishing ("quishing") surged sharply in early 2026, exploiting the fact that many email security tools scan links and text but not images. Attacks are also spreading into SMS, WhatsApp, and workplace chat tools like Teams and Slack — channels with none of the filtering that email gateways provide.
Deepfakes Have Moved From Novelty to Boardroom Risk
The case that put deepfake fraud on every CISO's radar is by now well known: in 2024, a finance employee at engineering firm Arup authorized transfers totaling roughly USD 25.6 million after joining a video call where every other "participant" — including someone who appeared to be the company's CFO — was AI-generated. It was widely treated as a dramatic outlier at the time.
It no longer is. Similar deepfake-enabled fraud cases have since been documented and adjudicated elsewhere, and industry surveys now show a large and growing share of businesses encountering deepfake fraud attempts in some form - audio, video, or both. Part of the reason this works is uncomfortably simple: independent testing has found that people are remarkably poor at spotting AI-generated faces and voices. Even when they're specifically looking for signs of manipulation.
For finance, HR, and executive teams — the people most likely to be targeted in impersonation scams because they can authorize payments or access sensitive data — this changes the calculus entirely. A familiar voice or face on a video call can no longer be treated as verification on its own.
AI Attacks Are Now a Boardroom-Level Cost, Not Just an IT Problem
This isn't a fringe concern.
Multiple 2026 industry breach studies report that a majority of organizations have experienced at least one AI-driven cyberattack attempt in the past year and breaches involving confirmed attacker use of AI now carry a noticeably higher average cost than breaches overall. Global spending on AI-related cybersecurity capabilities is climbing sharply as a result, with analysts projecting it will make up a large and growing share of total cybersecurity budgets within the next few years.
The pattern across nearly all of this research points to the same conclusion: attackers are not using AI to invent entirely new categories of attack. They're using it to make old, well-understood attacks — phishing, impersonation, social engineering, business email compromise — faster, cheaper, and far more convincing at scale. Which means the defense has to evolve too, not just at the technical layer, but at the human one.
How Organizations Can Fight Back
The good news is that the same AI capabilities attackers are exploiting can be turned around and used defensively — often more effectively than attackers can use them offensively, because defenders have the advantage of controlling their own environment and data.
- Deploy AI-driven threat detection. Machine learning and behavioral analytics can flag anomalies — unusual login patterns, atypical data transfers, subtle deviations from a user's normal behavior — far faster than manual monitoring, often catching threats before damage is done.
- Automate incident response. AI-based automated response systems can contain a threat (isolating a device, blocking an account, quarantining malware) in seconds rather than the hours a manual process typically takes — a critical difference when attacks move this fast.
- Verify out-of-band, every time. For any request involving money, credentials, or sensitive data — even one that arrives by video call — build in a second, independent verification channel that doesn't rely on recognizing a voice or face alone.
- Train people to recognize AI-enabled social engineering. Awareness training built around today's AI-driven tactics (not the phishing red flags of five years ago) remains one of the highest-leverage investments an organization can make, precisely because the human decision point is still where most of these attacks succeed or fail.
- Build an AI implementation roadmap, not a one-off tool purchase. Effective AI-driven security requires a coordinated strategy across detection, response, data privacy, and governance — not just switching on a new product and hoping it works.
The Bottom Line
AI hasn't just given defenders new tools — it's given attackers new tools too, and right now, attackers are moving quickly. Closing that gap starts with understanding both sides of the equation: how AI is actively being weaponized against organizations, and how the same underlying technology can be deployed to detect, respond to, and prevent those very attacks.
That's exactly the gap iTrainingExpert's AI in Cybersecurity: Threat Detection & Response program is built to close — a 2-day, hands-on course covering AI-driven threat detection, automated incident response, vulnerability management and a practical framework for implementing AI across your organization's security strategy.
Learn more and book your seat today: https://www.itrainingexpert.com/course/ai-in-cybersecurity-threat-detection-response/?c=ODIx&s=MzM2MA==
iTrainingExpert is Malaysia's #1 corporate training provider with 25+ years of experience delivering 2,800+ courses across 50+ countries. We offer public, online, and customised in-house training programmes, all HRD Corp claimable. Contact us at info@itrainingexpert.com or call +6012 686 9628.