Seven weeks into the generative AI era, the security market has settled on its story for the year: attackers now have artificial intelligence, so defenders must buy artificial intelligence. Expect that sentence, in some form, in every vendor briefing between now and December. The premise is half true and the conclusion does not follow from it. Both halves are worth separating carefully, because the budget conversations that follow from this will run for the next two years.
AI did not change what attackers do. It removed the cost of doing it at scale
Nothing in the last two months has given an attacker a capability they lacked. Credential phishing, business email compromise, supplier payment fraud and pretexting all worked perfectly well before. What changed is the unit cost of producing convincing, personalised, fluent text in any language, which has fallen to approximately nothing. That is an economics change, and economics changes show up as volume and coverage rather than as novelty. The practical consequences, in order of how soon you will feel them: Volume. Campaigns that were previously worth running against a hundred targets are now worth running against ten thousand. Personalisation at that volume. Public profile, employer, job title, recent company news and a plausible reason to be writing — previously the mark of a targeted attack, now available as a default. Language coverage. Markets that were partially protected by the difficulty of writing natively in the local language are no longer protected at all. Iteration speed. Lures that fail can be rewritten and retested faster than most organisations update a filter rule. What has not changed is equally important: initial access still depends on credentials, sessions, unpatched services and misconfiguration; malware capability is unaffected; and exploitation still requires the same technical work it required last year.
Volume is not a detection problem
The instinctive response is to detect machine-generated text. This will be sold aggressively this year and it will not work. Detection accuracy degrades as models improve, false positives land on legitimate colleagues who used a writing assistant, and the answer, even when correct, tells you nothing useful: plenty of machine-written email is entirely legitimate, and human-written fraud remains common. The defences that survive the shift are the ones that never depended on judging the message. A payment instruction is verified through a channel the requester did not choose, regardless of how well written it is. A bank detail change requires a call-back to a number held on file, not the number in the email. Privileged access requires a phishing-resistant factor, so a convincing page collects nothing reusable. Each of these is indifferent to who or what composed the text, which is precisely why it keeps working. There is one piece of training content that should be retired this quarter: telling staff to look for poor grammar and awkward phrasing. That advice is now actively harmful, because it teaches people that fluent means genuine.
Where defensive AI actually earns its place
Setting aside the marketing, there are genuinely useful applications available now, and they are unglamorous. Alert triage and summarisation. Turning a noisy alert into a readable narrative for the analyst, with the relevant context assembled. This is the highest-value security use available today. Query and rule generation. Writing the log query, the detection logic or the parsing rule, where the output is testable and a mistake is visible. Documentation and reporting. Incident write-ups, executive summaries, control descriptions. Anomaly detection, relabelled. Behavioural analytics has been in these products for years. It is being renamed this year. It was worth having before and remains so. Autonomous response. Isolating hosts and disabling accounts without human confirmation, on the strength of a probabilistic judgement. Available, occasionally sensible for narrow cases, and a reliable way to create your own outage. The metric that matters for the first three is mean time to triage, not detection rate. If your team cannot say what that number is today, the AI purchase has no baseline and will be evaluated on impressions.
The asymmetry that explains the lag
Attackers use these tools without governance, contracts, data classification or approval. Defenders must resolve where the data goes before feeding an alert stream into anything, which is a legitimate constraint and also a real handicap. The workable conclusion is to sequence adoption by data sensitivity: start with uses that do not require sensitive input — rule writing, documentation, general research, training content — while the enterprise arrangement for anything touching logs or incident data is negotiated properly. That sequencing gets value this quarter instead of waiting two.
Practical Guidance for AI Defense Strategy
- Verify instructions out of band, through a channel the requester did not supply.
- Retire grammar-based guidance from awareness training immediately.
- Deploy phishing-resistant factors for administrators, finance and executives first.
- Baseline mean time to triage before buying anything described as AI-powered.
- Do not buy AI-text detection as a control.
- Sequence AI adoption by data sensitivity, starting where no sensitive input is needed.
- Review alert-volume assumptions in managed detection contracts.
- Rehearse a payment-fraud scenario with finance, not just an IT incident.
The Regional Angle
Three things make this shift land differently here. The first is that the region's defensive tooling is built for English and the attack surface has just become bilingual. Secure email gateways, content filters and data-loss rules in most regional deployments were tuned on English-language corpora; awareness training is delivered in English to workforces where English is a second or third language; and the analyst reviewing reported messages may not read Arabic comfortably. Until this year, poor Arabic was itself a control — an unconvincing lure in formal Arabic simply failed. That control has quietly expired, and nothing has replaced it. The immediate actions are unexciting and effective: confirm your reporting and triage path can handle Arabic submissions competently, translate awareness material properly rather than machine-translating it, and test your filtering against non-English lures before an attacker does it for you. The second is a contractual exposure specific to how detection is bought here. A large share of regional organisations run managed detection through offshore providers priced per seat, per device or per alert volume, with volume assumptions written into a schedule nobody has reread since signing. A sustained increase in phishing volume changes the economics of that contract mid-term, and the provider has three options: absorb it, charge for it, or tune down sensitivity. The third is the one that happens silently and the one that hurts. Read the volume assumptions this month, ask the provider directly what happens if reported-message volume triples, and get the answer in writing before it is tested. The third is about authorisation culture rather than technology. Regional business runs on speed and personal authority: an instruction from the chairman, the owner or the group managing director carries weight that no written procedure fully overrides, and a great deal of it arrives by messaging app from a number nobody formally verified. Fluent, personalised impersonation at scale meets that culture at exactly its weakest point. The fix is not technical and it is not a training module. It is an explicit, written, senior-sponsored rule that any payment instruction or bank-detail change must be verified through a fixed call-back, that verification is mandatory regardless of who is asking, and — the part that actually matters — that no employee will ever be criticised for delaying a payment to verify it. Without that last clause, the procedure exists on paper and fails in practice, because the junior accountant will always weigh the risk of fraud against the certainty of annoying the chairman.
The objection worth taking seriously
The strongest objection is that this is a vendor-manufactured panic. The evidence that AI-enabled attacks are actually succeeding more often is anecdotal and self-reported by companies selling the remedy. The controls that work — out-of-band verification, strong authentication, payment discipline — were the right answer three years ago and are unchanged. Nothing in the threat model is new, so the honest response is to keep executing the existing roadmap and ignore the noise. That is correct about the controls, and any security leader who uses this moment to request a large new budget line for AI defence is exploiting the moment rather than responding to it. But two consequences are real and land on operations rather than on the threat model. Volume increases cost, and cost shows up in triage capacity and in managed service contracts written on old assumptions. And one widely taught piece of user guidance is now wrong, which means the training deployed across most organisations is actively miscalibrating the workforce. Neither of those requires a purchase. Both require somebody to act this quarter.
Common Questions
Can we detect AI-generated phishing?
Not reliably, and the reliability will decrease. Build controls that do not depend on judging the text.
Does this change our security roadmap?
It changes sequencing rather than content. Phishing-resistant authentication and payment verification move up; everything else stays where it was.
Should we buy an AI-powered security product this year?
Possibly, for triage and analyst productivity, with a measured baseline. Not for detecting machine-written text, and not for autonomous response.
What should we expect over the next twelve months?
Expect every major security vendor to announce an AI assistant during the year, with the useful ones focused on triage and query writing rather than on detection. Expect AI-text detection products to be marketed hard and to disappoint publicly. Expect at least one widely reported fraud involving a cloned voice or video of a named executive, which will do more to change board behaviour than any briefing. And expect insurers and regulators to begin asking about verification controls and authentication strength rather than about hours of awareness training — a shift that will reward organisations who fixed the payment process over those who bought the course.
AI Defense Strategy Consultation — we separate the controls that survive fluent, high-volume attacks from the products being renamed to sell into the panic.
