TL;DR: AI-driven social engineering has turned persuasive deception into a scalable production line, lowering attacker skill, increasing volume, and compressing time to action while exploiting human workflows that still depend on judgment under pressure, according to Trusona. The core issue is no longer awareness alone but whether identity verification, recovery, and exception handling are defensible when deception is cheap and repeatable.
NHIMG editorial — based on content published by Trusona: AI Driven Social Engineering: The New Frontier in 2026
By the numbers:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes, and as quickly as 9 minutes in some cases.
Questions worth separating out
Q: How should security teams protect help desk identity workflows from AI-driven social engineering?
A: They should treat password resets, device enrollment, and account recovery as privileged workflows, not routine service tasks.
Q: Why do AI-generated pretexts increase identity risk so quickly?
A: Because they turn persuasive deception into a repeatable process.
Q: What do organisations get wrong about social engineering defence?
A: They often treat it as an awareness problem instead of a workflow problem.
Practitioner guidance
- Harden recovery and reset workflows Require strong verification for password resets, device re-enrollment, and account recovery.
- Eliminate discretionary overrides for sensitive requests Block ad hoc exceptions for VIPs, travel cases, and time-critical access changes unless they pass a documented step-up verification path.
- Separate conversational trust from identity proof Do not treat a familiar voice, fluent message, or known signature line as evidence of identity.
What's in the full article
Trusona's full blog post covers the operational detail this post intentionally leaves for the source:
- Workflow examples for hardening password reset, device enrollment, and access-change paths against AI-driven impersonation
- Operational guidance on separating service desk convenience from privileged identity decisions
- Examples of where verification should move out of the conversation and into policy-controlled approval steps
- The article's broader framing of why AI changes the economics of deception across email, voice, and chat
👉 Read Trusona's analysis of AI-driven social engineering in 2026 →
AI-driven social engineering in 2026: are identity workflows ready?
Explore further
AI-driven social engineering is now an identity governance problem, not just an awareness problem. The article is right to frame the issue around workflows that depend on human judgment under pressure. Training helps, but it does not scale against a threat model where pretexts can be generated continuously and adapted in real time. The practical conclusion is that identity governance must extend into support operations, recovery paths, and exception handling.
A question worth separating out:
Q: How can teams reduce the impact of AI-driven impersonation attempts?
A: Teams should combine user verification, conditional access, and response playbooks that isolate suspicious activity quickly. Once impersonation reaches credential capture or account access, the most effective control is the speed of containment, not just the quality of the initial detection.
👉 Read our full editorial: AI-driven social engineering exposes identity workflows in 2026