Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security How should security teams build an AI cybersecurity…
Cyber Security

How should security teams build an AI cybersecurity awareness program for employees who use generative AI tools every day?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Cyber Security

Start with role based training that reflects how people actually use AI at work, then layer in phishing simulations, policy nudges, and just in time coaching. The program should address deepfakes, AI generated phishing, unsafe data sharing, and prompt hygiene. Tie training to real risk signals so interventions are targeted, timely, and measurable rather than one size fits all.

Why This Matters for Security Teams

Employees are now using generative AI in the flow of work, which means security awareness can no longer focus only on email phishing, passwords, and device hygiene. The bigger risk is that people may paste sensitive data into public tools, trust AI-generated content too quickly, or follow malicious prompts that arrive through chat, documents, or voice. Current guidance from the CISA cyber threat advisories shows that adversaries are already using AI to scale deception, impersonation, and social engineering.

A useful awareness program has to reflect how employees actually use AI at work: drafting messages, summarising meetings, generating code, searching knowledge bases, and automating routine tasks. That creates new failure points around data handling, output validation, and overreliance on AI-generated recommendations. Security teams also need to account for deepfakes and synthetic identity cues, because a convincing voice or image can now bypass the instinctive checks that traditional awareness relied on.

In practice, many security teams encounter AI misuse only after sensitive data has already been exposed or a fraudulent request has already been acted on, rather than through intentional early reporting.

How It Works in Practice

An effective program starts by segmenting training by role, AI use case, and data sensitivity. A finance employee using a chatbot for reporting needs different guidance from a developer using an AI coding assistant or a support agent using summarisation tools. The goal is not generic AI fear messaging. It is to teach practical decision points: what data may be shared, when AI output must be verified, how to recognise manipulated content, and when to escalate suspicious behaviour.

Security teams should combine awareness with lightweight controls that shape behaviour at the moment of use. That includes policy nudges in approved tools, warnings when users paste regulated or confidential data, and just in time coaching when risky prompts or outputs are detected. Simulated attacks should also evolve. Traditional phishing exercises should be expanded to cover AI-generated phishing, deepfake voice requests, fake executive messages, and malicious content embedded in chat workflows. The threat model should be informed by sources such as the MITRE ATLAS adversarial AI threat matrix and the Anthropic report on the first AI-orchestrated cyber espionage campaign.

  • Teach prompt hygiene: avoid secrets, credentials, customer data, and unpublished business information.
  • Require validation of AI output before it is sent, merged, or used in a decision.
  • Use short scenario-based lessons tied to real workflows, not annual awareness slides.
  • Measure reporting, click-through, escalation, and unsafe sharing patterns over time.

Best practice is evolving, but NIST’s NIST AI 600-1 Generative AI Profile is useful for mapping awareness to governance, risk treatment, and user guidance. These controls tend to break down when employees use unsanctioned consumer AI tools because security teams lose visibility into prompts, outputs, and data flows.

Common Variations and Edge Cases

Tighter AI use controls often increase friction for employees, requiring organisations to balance productivity gains against data-loss and misuse risk. That tradeoff is especially visible in teams that depend on rapid drafting, brainstorming, or software generation, where overly restrictive policy can drive shadow AI use. Current guidance suggests focusing on approved tools, clear data-classification rules, and simple escalation paths rather than banning generative AI outright.

There is no universal standard for every sector yet, but organisations in regulated environments should add stronger rules for personal data, financial information, legal material, and customer records. If the workforce includes contractors, frontline staff, or distributed teams, the program should account for inconsistent device control, language differences, and variable security maturity. Awareness also needs to recognise that AI can be both a productivity tool and an attack vector, so training should cover fraudulent prompts, poisoned knowledge sources, and impersonation through voice or video. NIST’s NIST Cyber AI Profile is a good reference point when teams want to connect user guidance to broader cyber defence planning.

Where trust is highly contextual, such as executive assistants, customer operations, or incident response teams, awareness must be paired with verification habits and out-of-band confirmation. That is the most practical lesson: AI awareness works only when employees know what to do with a suspicious output, not just what a risky tool looks like.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATLAS and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST AI RMF, NIST AI 600-1 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST AI RMFGOVERNAwareness needs governance, roles, and accountability for AI use.
NIST AI 600-1The GenAI profile maps user guidance to safe generative AI use.
MITRE ATLASATLAS-TA0001Adversarial AI tactics inform awareness about prompt abuse and manipulation.
NIST CSF 2.0PR.ATAwareness and training are core protective controls for employee behaviour.
OWASP Agentic AI Top 10LLM06Agentic and LLM risks include unsafe output use and prompt abuse.

Translate GenAI risk guidance into practical employee rules, prompts, and validation checks.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org