By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “New Year, New Threats: Security Predictions for 2025” (June 26, 2026)

TL;DR: Attackers are already using AI to increase the scale and sophistication of cybercrime, while the webinar also weighs whether tools like ChatGPT are a genuine threat and how tactics may evolve, according to Abnormal AI. The real issue is not AI hype but how quickly adversaries can industrialise deception, targeting, and response bypass.


At a glance

What this is: This on-demand webinar looks at how cybercriminals are using AI to scale attacks and sharpen deception, while questioning how much generative AI itself changes the threat picture.

Why it matters: It matters because security teams need to separate real attacker capability shifts from vendor hype, then adjust detection, response, and AI-assisted defence plans accordingly.


Context

This webinar is about the operational impact of AI on cybercrime, not a product feature announcement or a generic AI debate. The central question is whether attackers are already using AI to improve the scale, speed, and persuasiveness of attacks in ways that change day-to-day security operations.

For IAM and security teams, the governance issue is how AI-assisted attack behaviour affects phishing, impersonation, and response bypass. The useful lens is not whether generative AI is inherently dangerous, but whether it amplifies existing identity and social-engineering failure modes faster than current controls can adapt.


Key questions

Q: How should security teams respond to AI-assisted phishing and social engineering?

A: Treat AI-assisted phishing as a scale and quality problem, not just a messaging problem. Tighten authentication at the point of approval, train users on high-risk workflows such as payment and recovery, and monitor sessions for abnormal behaviour after credentials are entered. The goal is to make the attacker’s next step harder even if the lure succeeds.

Q: Why does generative AI make cybercrime harder to stop?

A: Generative AI lowers the cost of producing convincing lures, translating messages, and testing variations at scale. That makes campaigns more adaptive and less predictable, which reduces the value of static keyword filters and one-time awareness training. The defence answer is stronger identity verification, better anomaly detection, and faster containment workflows.

Q: What are the signs that AI is being used to support early-stage cyber attacks?

A: Common signs include unusually polished phishing text from weak operators, malware code that looks like lightly modified samples, and repeated small rewrites across languages or shells. Security teams should also watch for prompts or forum discussions about bypassing guardrails, generating code fragments, or translating scripts. These patterns suggest attackers are using AI for acceleration rather than advanced exploitation.

Q: How can organisations reduce the impact of AI-enabled cybercrime?

A: Shorten the path from suspicious activity to identity containment. Use stronger authentication, narrow privilege, and rapid session review so a successful lure does not automatically become a successful breach. When attackers move faster, response has to be anchored in the identity layer, not only in email filtering or awareness training.


Background and context

How AI changes attacker scale and targeting

AI lowers the cost of producing convincing lures, adapting language, and iterating on outreach at volume. That does not mean every attack becomes autonomous, but it does mean the economics of phishing, impersonation, and fraud shift materially. Attackers can test more variants, personalise more messages, and refine what works faster than manual campaigns allow. For defenders, the technical challenge is less about the model itself and more about the acceleration it gives to familiar abuse patterns across email, identity, and response workflows.

Practical implication: tune detection for higher-volume, faster-iterating social engineering rather than assuming old campaign patterns will persist.

Generative AI as an attack enabler, not the whole threat

Generative AI is best understood as an enabler that improves drafting, translation, scripting, and operational consistency across crime workflows. In many cases, the attacker still relies on stolen credentials, impersonation, or social engineering rather than novel model exploits. That distinction matters because it keeps control design grounded in identity, access, and behaviour monitoring instead of chasing the model layer alone. The real question is which parts of the attack chain become cheaper, faster, or more convincing once AI is added.

Practical implication: anchor controls in identity verification, abuse detection, and anomaly response instead of treating generative AI as a standalone root cause.

Why defender use of AI has to be paired with governance

If attackers are using AI to increase tempo and adaptability, defenders need governed AI use that improves triage, enrichment, and response without creating new blind spots. That means clear rules for what the model may touch, what it may recommend, and where human approval stays mandatory. The control problem is not simply adopting AI for defence, but making sure AI-assisted workflows do not weaken accountability or create over-trust in automated conclusions. Security operations should treat AI as an amplifier of existing process discipline, not a substitute for it.

Practical implication: define approval boundaries and audit trails for AI-assisted security workflows before scaling them into operations.


NHI Mgmt Group analysis

AI in cybercrime is primarily a force multiplier for familiar attack paths, not a new category of crime. The article points to scale and sophistication gains, which usually show up first in phishing quality, impersonation success, and campaign churn. That means the operational risk lives in how quickly existing abuse patterns can be automated and refined. Practitioners should treat AI as an acceleration layer on established attacker tradecraft, not as a separate threat silo.

The governance gap is not model awareness, it is response tempo. Most security programmes still assume attackers iterate slowly enough for human review, manual triage, and workflow handoffs to keep up. AI compresses that timeline and increases the number of credible variants defenders must absorb. The implication is that detection, validation, and containment processes now need to be designed for higher iteration speed, not just higher message quality.

Identity systems remain the decisive control surface when AI is used for fraud and intrusion. If AI helps attackers sound legitimate, the defence problem moves toward stronger authentication, better verification of intent, and tighter controls on risky requests. This is where human IAM and NHI governance intersect, because the same manipulation techniques that work on users also pressure service workflows and support channels. Practitioners should re-center trust controls on proof, context, and escalation rather than content quality.

Named concept: attacker tempo inflation. This is the widening gap between the speed at which attackers can test, adapt, and relaunch campaigns and the speed at which defenders can inspect and respond. The concept matters because many controls were built for slower adversary cycles. Security teams should measure whether their review and escalation loops can still operate at the pace AI enables.

Defensive AI only helps when it is governed like a security control, not a convenience layer. The article’s direction is clear: organisations will lean on AI to counter AI-driven abuse, but that only works when the output is constrained, reviewed, and auditable. Automated assistance without governance creates false confidence and weaker accountability. Security leaders should assume AI will become part of both the attack chain and the defence chain, and manage it accordingly.

What this signals

Attacker tempo inflation: AI changes cybercrime by compressing the time needed to test, adapt, and relaunch campaigns. Security programmes built around slower review cycles will feel the strain first, especially where email, help desk, and impersonation controls still depend on manual judgement.

The programme-level response is to treat AI as an adversary capability multiplier and design for faster verification, faster triage, and faster containment. That means aligning identity proofing, fraud detection, and response workflows so they still hold when the attacker can iterate much more quickly.


For practitioners

  • Harden identity verification for high-risk requests Add stronger verification steps for password resets, payment changes, session resets, and sensitive approvals that AI-generated lures often target.
  • Tune detections for high-volume campaign variation Adjust alerting to spot rapid message iteration, unusual sender behaviour, and campaign reshaping that signals AI-assisted social engineering.
  • Constrain AI use in security operations Define where AI can draft, summarise, or prioritise work, and require human approval for containment, account actions, and external communication.
  • Review fraud and impersonation playbooks Update response steps for AI-assisted deception, especially where attackers aim to bypass help desk processes or redirect staff into unsafe actions.

Key takeaways

  • AI is amplifying familiar cybercrime patterns by making phishing, impersonation, and campaign iteration cheaper and faster to run.
  • The practical risk is not abstract hype but a higher-volume, more adaptive attack cycle that outpaces slow human review.
  • Security teams should respond by tightening verification, improving detection for campaign variation, and governing their own AI-assisted workflows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI09 — Human-Agent Trust ExploitationAI-assisted deception increases trust abuse even without full agent autonomy.
Recommendation — Apply ASI09 thinking to constrain trust-based workflows that attackers can exploit with AI-generated deception.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsStronger request verification and access checks reduce the blast radius of impersonation attacks.
Recommendation — Tighten PR.AA-05 controls around sensitive requests and approval paths.
MITRE ATT&CKTA0006;TA0009 — Credential Access; CollectionThe article centres on AI-enhanced campaigns that improve credential capture and abuse.
Recommendation — Map AI-assisted phishing and impersonation to TA0006 and TA0009 in detection and hunting workflows.
NIST AI RMFGOVERN — AI Governance and AccountabilityDefensive AI use needs governed boundaries, approval, and accountability.
Recommendation — Establish GOVERN controls for AI-assisted security workflows before scaling them into operations.

Key terms

  • Attacker Tempo Inflation: The acceleration of campaign creation, testing, and relaunch that AI gives to adversaries. It matters because many security controls were designed around slower human-led attack cycles, so the defender’s review and containment windows can shrink below workable thresholds.
  • AI-powered social engineering: AI-powered social engineering is the use of generated text, voice, video, or interface content to manipulate a target into taking an unsafe action. The goal is not just deception, but trust transfer, where the attacker convinces a legitimate identity holder to approve, disclose, or execute something harmful.
  • Defensive AI: AI used to help security teams detect, prioritise, or investigate threats more quickly. In practice, it is useful when it reduces analyst time to decision by correlating behaviour across email, identity, and endpoint data, rather than acting as a standalone security control.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org