TL;DR: AI is being used by cybercriminals to scale phishing, social engineering, and other attack tactics, and Knowbe4’s whitepaper argues that AI-assisted security awareness training and simulated phishing can help organisations harden the human layer. The deeper issue is that human risk programs now have to contend with faster, more adaptive deception at machine speed.
NHIMG editorial — based on content published by Knowbe4: AI vs. AI: Combating Cybercriminals with an AI-Powered Human Risk Management Program
Questions worth separating out
Q: How should organisations adapt security awareness training for generative AI phishing?
A: Security teams should move from static annual training to continuous, behaviour-focused reinforcement.
Q: Why do AI-generated email attacks increase identity risk?
A: AI-generated email attacks increase identity risk because they make malicious requests more convincing at the exact point where people decide whether to trust, approve, or act.
Q: What do security teams get wrong about human risk management?
A: They often treat it as a training completion problem instead of a resilience problem.
Practitioner guidance
- Build AI-aware phishing simulations Use simulations that reflect current lure styles, role-specific context, and the kinds of messages employees now encounter in email, chat, and collaboration tools.
- Track behaviour-based risk signals Measure report rates, time to report, repeat susceptibility, and risky interactions with lures so the programme reflects resilience rather than attendance.
- Connect human risk data to IAM controls Feed repeated susceptibility and suspicious interaction patterns into access review, step-up authentication, and conditional access decisions where those controls are available.
What's in the full article
Knowbe4's full whitepaper covers the operational detail this post intentionally leaves for the source:
- Examples of AI-assisted attacker tactics that can be used to design more realistic simulations.
- A closer look at how AI can support security awareness training and phishing exercises at scale.
- Discussion of how generative AI can be used to reinforce security culture and user engagement.
👉 Read Knowbe4's whitepaper on AI-powered human risk management and phishing →
AI-driven phishing: what it means for human risk programs?
Explore further
AI has turned human risk management into an identity-adjacent control problem. Once phishing or pretexting succeeds, the consequence is rarely limited to user error. It becomes credential theft, session abuse, or fraudulent access enrolment, which places the problem squarely in the IAM and access governance conversation. Human training remains necessary, but it now functions as one layer in a wider identity control stack.
A question worth separating out:
Q: How can teams reduce the damage when phishing succeeds?
A: Combine user training with phishing-resistant authentication, tighter help desk verification, and rapid detection of unusual account activity. If a lure succeeds, fast containment matters more than retrospective awareness. Teams should also predefine escalation paths for password resets, MFA changes, and suspicious session behaviour.
👉 Read our full editorial: AI-powered human risk management and the new phishing problem