The emergence of generative artificial intelligence has profoundly changed the cybersecurity playing field.
Contents

At first, the discussion focused on its transformative potential for organizations; soon after, we began to see clearly its flip side: the ability to multiply the speed, scale, and credibility of cyberattacks. For management committees, this development can no longer be approached as an exclusively technological issue. We are facing a strategic change that affects trust, decision-making processes and the real resilience of organizations.

 

When the warning signs stop working

For years, we've taught employees how to identify suspicious emails by looking for spelling mistakes, unnatural translations, generic greetings, or glaring inconsistencies. This approach, although still useful in some cases, is clearly becoming insufficient.

Today, language models make it possible to generate impeccable messages, adapted to the language, the sector, the context of the company and even the communication style of a specific interlocutor. Research published by Harvard experts has indicated that AI-generated phishing emails can reach levels of effectiveness comparable to those written by human specialists, while reducing the cost of the process by more than 95%. The consequence is clear: the attacker can produce better campaigns, faster and at a lower cost.

This also removes a barrier that previously partially protected many organizations: language. Today, AI can write culturally credible communications in virtually any language, without the attacker needing to know the local market or master its nuances. In practice, AI has reduced the friction of cybercrime and greatly expanded its reach.

 

From mass phishing to surgical attack

Another of the great transformations has to do with the phase prior to the attack: information gathering. In the most sophisticated incidents, attackers don't act blindly. They analyze who makes decisions, who authorizes payments, which suppliers are active, what projects are underway, and what internal relationships they can exploit.

Until recently, that prior intelligence required time and human ability. Generative AI completely changes the equation. It can analyze public information from professional networks, corporate pages, press releases, or social media, and turn it into highly personalized messages in a matter of minutes. What was previously reserved for highly targeted spear phishing campaigns is beginning to be profitable against any organization.

Consider an employee who receives a message apparently sent by their CEO, with a credible tone, referring to a real trip, a confidential operation, or an ongoing project. That information may have been automatically collected, cross-referenced, and structured by AI. The case of the engineering firm Arup, in which fifteen transfers totaling $25.6 million were made after a videoconference with executives recreated using artificial intelligence, illustrates the extent to which credibility can be manufactured.

 

When seeing and hearing is no longer enough

Deepfakes are no longer a threat linked solely to disinformation or media manipulation. Increasingly, they are part of corporate fraud. A manager's voice, their image on a video call or an instruction apparently issued in real time can no longer be considered sufficient proof of identity on their own.

The most relevant issue is not only the sophistication of the technology, but also the fall in barriers to entry. The generation of synthetic voice, manipulated images or realistic video is becoming more accessible, cheaper and faster. This forces us to review a basic premise: trusting because "I have seen it" or "I have heard it" is no longer enough.

In this new context, defense cannot rest on human perception. It has to be supported by robust validation processes, alternative confirmation channels and controls that do not depend solely on the appearance of authenticity. Trust must be verified, especially when there are urgent, confidential or financially significant instructions.

 

Automation also reaches the technical attack

The impact of generative AI is not limited to social engineering. It is also accelerating the more technical phases of attacks: reconnaissance, vulnerability analysis, malicious code generation, lateral movement and information exfiltration.

We are seeing certain offensive tools incorporate AI capabilities to analyze environments, identify weak points, and chain actions at a speed that exceeds the response capacity of many security teams. The threat not only gains precision; it gains pace.

In November 2025, Anthropic reported the detection and interruption of a cyberespionage campaign in which, according to the company, an actor linked to a state used AI agent capabilities to execute a large part of the attack cycle against some thirty targets. The company estimated that between 80% and 90% of certain tactical operations were executed by AI with limited human intervention. This type of incident confirms a new phase: AI no longer only helps the attacker, it can also act as an operational multiplier.

 

What leaders should do

The answer cannot be solely technological. Generative AI forces a review of how organizations verify identity, authorize sensitive operations, and prepare their teams. There are three priorities that are particularly relevant for management.

Rethink awareness. It is no longer enough to train employees to detect obvious errors in an email. Training should focus on verification habits, critical thinking, and managing pressure situations. Any sensitive request, especially if it is urgent, confidential or economically relevant, must be confirmed by an alternative and pre-validated channel.

Strengthen controls over critical operations. Payments, changes of bank accounts, exceptional authorisations or decisions outside the usual circuit must have double validation mechanisms and segregation of duties. In an environment where appearance can be manipulated, the process becomes the main line of defense.

Demand evolution of security vendors and capabilities. Not all organizations will be able to develop advanced defensive AI capabilities internally, but all must require their security solutions to evolve at the pace of the threat. EDR, SOC, mail gateways, detection tools, and managed services must incorporate behavioral analytics, anomaly detection, and real-time responsiveness. Just as important as hiring technology is periodically measuring its effectiveness.

 

Regaining balance

Generative AI has disrupted the economics of cyberattack: it reduces costs, increases scale, and makes threats more credible. This creates an obvious asymmetry in favor of the attacker, especially when organizations continue to rely on controls designed for a previous context.

Regaining balance requires combining technology, governance and culture. It's not just about incorporating AI into defenses, but about reviewing authorization processes, strengthening identity verification, training people against new forms of manipulation, and measuring whether controls are actually responding to the current speed of the threat.

The question is no longer whether artificial intelligence will transform cybersecurity. It is already doing so. The real question is whether organizations will be able to adapt before their attackers do.