TL;DR: AI is being used to create more sophisticated attacks at higher volume, and this on-demand webinar explores FraudGPT, how it works, and how malicious AI differs from benign generative tools, according to Abnormal AI. The governance question is no longer whether AI can accelerate cybercrime, but which identity controls can still constrain runtime misuse.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Exploring the Cybercrime Underworld: A Deep Dive into FraudGPT”.
Key questions
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.
Q: Why do generative AI tools increase cybercrime risk even without full autonomy?
A: They lower the cost of producing convincing attack content and let attackers iterate much faster than manual methods.
Practitioner guidance
- Inventory sanctioned and unsanctioned AI use Map which teams, workflows, and channels are using generative AI, then separate approved business use from abuse-prone or unowned activity.
- Define AI invocation governance Restrict who can invoke AI tools, what data they can reach, and which output channels they can feed, using policy and logging as enforcement.
- Strengthen abuse attribution Preserve audit trails across prompts, outputs, downstream delivery, and account context so investigators can connect misuse back to the invoking identity.
Bottom line: FraudGPT is presented as an example of malicious AI that scales cybercrime, not as proof that AI has become an autonomous attacker.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Malicious AI is an abuse multiplier, not a new identity class. The article shows that FraudGPT matters because it lowers the cost and raises the throughput of attack creation. That is a criminal operating model change, but it does not by itself turn the system into an autonomous identity. The implication is that defenders should avoid over-agentifying the threat and instead govern the workflow where human intent, model output, and downstream delivery intersect.
A question worth separating out:
Q: Should organisations treat AI-driven exposure as a data governance issue or an identity issue?
A: They should treat it as both, but data visibility should come first because identity controls need a known asset to protect. The better model is to connect DSPM, DAG, IAM, and PAM so exposure, entitlement, and privilege are evaluated together.
👉 Read our full editorial: FraudGPT and the rise of AI-assisted cybercrime