In January 2025 Arup, the British engineering consultancy, lost 25 million US dollars in a single transaction. A finance employee joined a video call they believed to be with the company’s CFO and other colleagues. Every person on the call was a deepfake. The voices were synthesised. The faces were AI-generated in real time. The employee authorised a wire transfer. By the time the fraud was discovered the money was gone.
This incident, which received widespread coverage at the time, has since been replicated in dozens of documented cases and an unknown number of undisclosed ones. The technology required to execute this attack is now available as a commercial service. Deepfake-as-a-service platforms emerged as a distinct criminal market segment in 2025, with AI-powered voice and video impersonation tools available for monthly subscription fees comparable to a streaming service. The sophistication barrier for this class of attack has collapsed entirely.
Moody’s 2026 cyber outlook placed AI-driven cyberattacks, including adaptive malware and autonomous threats, at the centre of its escalating risk assessment. The report warned that while AI-powered defences are essential, they introduce new risks including unpredictable behaviour that requires strong governance. The Trump administration’s decision to scale back or delay regulatory efforts on AI creates a divergence from the EU’s coordinated framework approach that Moody’s assessed as making global alignment on AI security standards unlikely in the near term.
AI Across the Attack Kill Chain
The chart below maps AI adoption by attackers across each stage of the attack kill chain alongside a threat volume index for each stage. Initial access, at 85 percent AI adoption, is the highest point on both measures. This reflects the maturation of AI-assisted phishing and social engineering as the dominant initial access method. Reconnaissance at 78 percent reflects the use of AI tools to process publicly available data about targets at a speed and scale that human operators cannot match.

Chart 1: AI adoption by attackers at each stage of the kill chain and threat volume index per stage, US enterprise incidents 2026 (Sources: Moody’s; Deepstrike; Cyble)
The Three AI Threats US Enterprises Are Least Prepared For
The first is adaptive malware. Traditional malware operates on predefined logic that security tools learn to recognise and block. AI-assisted malware rewrites its own code to evade signature-based detection, adapts its behaviour based on the environment it encounters and communicates with command and control infrastructure in patterns that mimic legitimate traffic. NETSCOUT’s 2026 predictions describe botnets capable of generating attacks at 20 terabits per second, a volume that threatens not just individual targets but the subscriber connectivity of entire internet service provider networks.
The second threat is model poisoning. As US enterprises deploy AI systems for security operations, business process automation and customer service, those models become targets themselves. An attacker who can introduce corrupted data into the training pipeline of a security AI system can cause it to misclassify genuine threats as benign or to flag legitimate activity as suspicious, degrading the system’s utility precisely when it is needed most. This attack vector is still emerging but its potential impact is significantly higher than conventional malware.
The third threat is autonomous reconnaissance. AI systems can now conduct open source intelligence gathering on a target organisation continuously, processing social media profiles, job listings, conference presentations, patent filings and news coverage to build a detailed picture of the organisation’s technology stack, key personnel, business relationships and potential pressure points. This reconnaissance happens before any contact with the target’s systems and produces a personalised attack blueprint that makes subsequent social engineering and phishing attacks dramatically more effective.
How US Enterprises Are Responding: Current vs Required Posture
| AI Threat Category | Current US Enterprise Response | What Is Actually Required | Gap |
| AI-generated phishing | Email gateway filtering and periodic user training | AI-assisted detection and continuous deepfake simulation training | Significant |
| Deepfake impersonation | Policy-based verification for financial transfers | Out-of-band verification protocols and executive threat monitoring | Critical |
| Adaptive malware | Signature-based endpoint detection | Behavioural AI detection and continuous endpoint telemetry | Significant |
| Model poisoning | Limited; most organisations have not assessed this risk | AI governance framework; training data provenance verification; model output monitoring | Critical |
| Autonomous AI reconnaissance | Periodic external attack surface scans | Continuous external threat intelligence monitoring; digital footprint management | Significant |
| Shadow AI deployments | Limited visibility; estimated in 20% of 2025 breaches | AI usage governance policy; network visibility tools for unauthorised AI tool connections | Urgent |
Table 1: AI threat categories with current US enterprise response posture versus required response and gap assessment (Sources: IBM 2026 Breach Report; Cyberbase; Moody’s 2026 Outlook)
The Shadow AI Problem
One AI threat that received disproportionately little attention until recently is shadow AI: the use of unauthorised AI tools and models by employees without security team knowledge or oversight. IBM’s Cost of a Data Breach Report identified shadow AI as a contributing factor in 20 percent of data breaches in 2025. These breaches added an average of 670,000 dollars to incident costs. An employee who pastes customer data into a public large language model interface, uses an AI-powered browser extension with access to corporate systems or connects an unauthorised AI tool to their work email account has created a data exposure that most organisations have no visibility into.
Proofpoint’s research found that 59 percent of US CISOs restrict employee use of generative AI tools altogether as their primary response to this problem. This is a reaction rather than a strategy. Blanket restriction creates workarounds. Employees find ways to use the tools they believe improve their productivity and the shadow AI problem becomes harder to manage, not easier. The organisations making genuine progress on this issue are those building governance frameworks that distinguish between acceptable and unacceptable AI tool use, monitoring for policy violations and treating AI tool governance as a security discipline rather than an HR policy question.

Leave a Reply