Executive Answer
Attackers are already using AI at scale: deepfake video calls that cost less than a Netflix subscription, voice clones generated from 3 seconds of audio, and autonomous phishing agents that achieve 54% click rates. Forty-one percent of organizations faced a deepfake attack in 2026, and the Five Eyes warned that AI capable of overwhelming enterprise defenses is months away. The answer is not to ban AI but to implement five controls - out-of-band verification, an approved tooling list, continuous exposure monitoring, AI-specific training, and an updated incident response plan.
- 41% of organizations experienced an AI deepfake attack on an audio or video call in 2026 (Gartner).
- Months away - the Five Eyes assessment of when AI capable of overwhelming enterprise defenses becomes widely available (June 2026).
- $25M - the amount a finance employee wired after a deepfake video call impersonating the CFO (documented case, Hong Kong, 2024 - now a widespread attack pattern).
- 82% of detections in 2026 were malware-free - attackers logged in with valid credentials rather than deploying malware (CrowdStrike 2026 Global Threat Report).
- 25% of employees are fooled by AI-cloned voices even in controlled simulation scenarios - and that number rises under real-world pressure (Scientific Reports, 2025).
Attackers are already using AI at scale - deepfake video calls, AI-cloned voices, and autonomous phishing agents that run reconnaissance faster than any human team. Forty-one percent of organizations faced an AI deepfake attack on a call in 2026, and the Five Eyes warned that AI capable of overwhelming enterprise defenses is months away. The defensive answer is not to avoid AI but to implement five specific controls - from out-of-band verification to continuous exposure monitoring - and build the governance structure that makes safe AI adoption possible alongside a hardened perimeter.
A finance employee joins a video call with the CFO and three colleagues. The conversation is normal - budget review, wire transfer approval, standard process. He executes the transfer. Every face on that call was a deepfake. The CFO never made the call. The money is gone.
This is not a hypothetical. It has happened, and it is happening at scale. The tools required to run this attack cost less than a monthly Netflix subscription. Any motivated attacker - not just nation-states, not just organized crime - can now impersonate your executives, clone your IT team's voice, and generate phishing emails indistinguishable from internal communications.
Last week, the Five Eyes intelligence alliance - the US, UK, Canada, Australia, and New Zealand - issued a rare joint warning. AI capable of overwhelming enterprise and government defenses is months away, not years. Gartner's 2026 CISO survey found that 41% of organizations have already faced an AI deepfake attack on a call.
Most companies are still debating whether to allow ChatGPT in the office. That is the wrong conversation, and it is happening years too late.
What Has Actually Changed
The threat is not new in kind. Social engineering, phishing, and identity fraud have been in the playbook for decades. What has changed is the cost, the scale, and the speed - and those three changes together cross a threshold that makes previous defenses inadequate.
Cost has collapsed. Running a convincing deepfake video call used to require specialized equipment and expertise. Today it takes a consumer GPU and an afternoon of setup. Voice cloning from a 30-second audio sample is available through public APIs. AI-generated phishing that reads like a native speaker in any language costs fractions of a cent per message.
Scale is now automated. An attacker does not write 10,000 phishing emails. An AI agent does it, personalizing each one with data scraped from LinkedIn, email signatures, and public filings. Reconnaissance that used to take a red team a week now runs in hours. The attack surface is mapped, prioritized, and exploited faster than a human analyst can process the alert.
Speed breaks the response model. The average time from initial phishing click to credential theft to lateral movement has compressed to under an hour in AI-assisted attacks. Security teams built to investigate and respond in 24 to 48 hours are operating on a timeline that no longer matches the threat.
Why Traditional Defenses Are No Longer Enough
Multi-factor authentication does not stop a deepfake call where the employee willingly reads out the code. Security awareness training that teaches people to "be suspicious of unusual requests" does not account for a video call that looks and sounds exactly like the CEO. Perimeter defenses do not catch an attacker who logs in with valid credentials obtained through AI-assisted social engineering.
This is not a failure of those tools. It is a failure to update the threat model. The controls were designed for a world where the attacker had to work harder. AI has changed the work-to-impact ratio on the offensive side. The defensive side has to catch up.
The gap is not technical. It is conceptual. Most organizations have not yet internalized that the human layer - the employee who takes a call, reads a message, approves a transaction - is now the primary attack surface, and that AI makes it much easier to manipulate that layer convincingly.
The 5 Controls Every Organization Needs Now
These are not theoretical. They are the baseline I recommend to every organization that asks me how to start. None of them require a large budget. All of them require a decision to be made.
1. Out-of-band verification for high-risk actions. Any request involving a wire transfer, credential reset, or access grant - regardless of who appears to be asking - must be verified through a separate, pre-established channel. Not a callback to the number provided on the call. A call to a number you already have. This single control would have prevented every deepfake CFO fraud case documented to date.
2. An approved AI tooling list with data classification rules. Shadow AI is the first risk to address. Employees are already using AI tools - for writing, analysis, code, customer communication. The question is whether they are doing it with or without guidance on what data can go in. An approved list with clear rules is not a ban. It is a structure that makes safe use possible.
3. Continuous external exposure monitoring. AI-driven attackers map your external attack surface before they move. A quarterly pen test tells you what was exposed three months ago. Continuous monitoring tells you what is exposed today - unpatched systems, newly exposed credentials, misconfigured cloud assets. The attacker's reconnaissance is continuous; yours has to be too.
4. AI-specific awareness training. Standard phishing awareness training is not enough. Employees need to understand what deepfakes are, how convincing they can be, and what the verification protocol is when something feels off. This is not a one-time module. It is an ongoing conversation that needs to update as the attack techniques evolve.
5. An updated incident response plan. Most incident response plans were written for malware, ransomware, and data exfiltration. They do not cover the scenario where an attacker uses AI to impersonate a vendor and manipulate an employee over three weeks of email correspondence. Add those scenarios. Run a tabletop exercise. Know what the response looks like before it happens.
The Right Goal: Use AI Safely, Not Avoid It
I want to be direct about something. The answer to AI-powered attacks is not to avoid AI. Organizations that refuse to adopt AI will fall behind their competitors who do adopt it, and they will still face AI-powered attacks from the outside. Avoidance is not a security strategy. It is a business strategy that fails on both dimensions.
The organizations that get this right will do two things simultaneously: they will protect themselves from AI-powered attacks, and they will enable their teams to use AI productively within a defined, monitored framework. Those two goals support each other. Understanding AI deeply enough to secure it is the same understanding you need to use it well.
The framework for doing this is not complicated. It is a governance decision - who approves AI tools, who monitors usage, who is accountable, and what happens when something goes wrong. Large companies have solved this. The principles scale down to mid-market and SMB with the same logic and a smaller budget.
Your 30-Day Action Plan
Week 1 - Audit what you have. Survey your teams. What AI tools are in use today? Which were approved by IT, and which were adopted without a formal process? Shadow AI is the starting point, not the exception. You cannot manage what you have not mapped.
Week 2 - Publish the framework. An approved tooling list. Data classification rules for AI inputs (what can go into a public AI tool versus what cannot). A process for requesting exceptions. This does not need to be 40 pages. A clear, enforceable one-pager is better than a comprehensive policy that nobody reads.
Week 3 - Test your human layer. Run a simulated deepfake call or AI-generated phishing campaign against your own team. Not to shame anyone, but to calibrate the actual risk and validate whether your awareness training is working. The results will be uncomfortable. They will also be necessary.
Week 4 - Brief the board. AI risk belongs on the board agenda, not because it is trendy but because the financial and reputational exposure is material. The board needs to understand the threat, approve the resource allocation to address it, and see the framework you are building. This is a governance conversation, not a technical one.
The Bottom Line
AI has changed the economics of attacks. The cost is lower, the scale is larger, and the speed is faster. Your defenses need to account for that shift - not by blocking AI, but by building the controls that make safe adoption possible.
The organizations that will come out ahead are the ones that make this decision deliberately, before an incident forces it. The framework exists. The controls are known. What is usually missing is the organizational will to implement them before the problem arrives.
This is the first article in a five-part series on AI and enterprise security. Next week: why AI is creating a new category of insider threat - and what to do about it.
The $25M Hong Kong deepfake case is not an outlier - it is the new baseline. I tell every executive team I work with: the moment your employee believes they are on a video call with your CFO is the moment your security posture depends on whether you established an out-of-band verification protocol before that call happened. That protocol costs almost nothing to implement. The absence of it costs everything. AI-powered attacks have made out-of-band verification for high-risk transactions a non-negotiable control, not a nice-to-have.
Related Expertise
Related Articles
Shadow AI: The Insider Threat Your Security Stack Can't See
75-85% of employees use unapproved AI tools. Here is why your DLP stack cannot see it and what to do about it.
AI GovernanceAI Governance Without Board Accountability Is Just a Document
The EU AI Act's August 2026 deadline is closer than most boards realize - and most are not ready.
Frequently Asked Questions
How are attackers using AI against enterprises in 2026?
Attackers are using AI in three primary ways: deepfake video and audio calls to impersonate executives and bypass MFA, autonomous AI agents that run reconnaissance and generate custom phishing content at scale, and AI-assisted credential attacks that move far faster than human defenders can respond. The Five Eyes intelligence alliance warned in June 2026 that AI capable of overwhelming enterprise defenses is months, not years, away.
Should companies block AI tools to reduce cybersecurity risk?
Blocking AI tools entirely is neither practical nor necessary. Employees will find workarounds, and the competitive cost of falling behind on AI productivity is real. The right approach is to implement controls rather than bans: an approved tooling list, data handling policies, monitoring, and user education. The goal is to use AI with guardrails, not to pretend AI does not exist.
What are the five security controls every company needs before deploying AI?
The five controls are: (1) an out-of-band identity verification protocol for any request involving money, credentials, or access changes; (2) an approved AI tooling list with data classification rules; (3) continuous external exposure monitoring, not point-in-time scans; (4) AI-specific employee awareness training covering deepfakes, vishing, and AI-generated phishing; and (5) an updated incident response plan that includes AI-driven attack scenarios.
How do I build an AI security policy in 30 days?
Week 1: audit current AI tool usage across the organization - shadow AI is the first risk to address. Week 2: publish an approved tooling list and data classification rules for AI inputs. Week 3: run a simulated deepfake or AI phishing exercise to test your human layer. Week 4: update the incident response plan and brief the board on the AI threat landscape and your response framework.
Is your organization ready for AI-powered threats?
I work with organizations to build AI security frameworks and governance structures that protect against modern threats without blocking productivity.
Let's Talk