The reconnaissance
Researching a target, its people, suppliers and systems used to take days. AI compresses it to minutes, and the NCSC rates this among the clearest capability gains at every attacker skill level.
Familiar attacks at a new tempo. What AI genuinely changed, what is still hype, and what to do about it.
The headlines say AI attacks; the reality is more specific and more useful. The UK's National Cyber Security Centre assesses that AI will almost certainly increase the volume and impact of cyber attacks, but unevenly. This page separates the real uplift from the science fiction.
An AI cyber attack is a cyber attack in which the attacker uses AI to do the work: researching the target, writing the lure, finding the weakness, adapting the code, or running the campaign at a scale one person could not manage before. Very little about the attack itself is new. The NCSC's near-term assessment describes the threat as "evolution and enhancement" of existing techniques rather than new categories of attack.
That framing matters because it tells you where to look. If the categories are unchanged, the cyber entries already on your risk register are the right place to record what AI has changed, and the question becomes how far likelihood has moved on each one.
Part of our series on the real risks of AI for a business: familiar risks, with the likelihood turned up.
Researching a target, its people, suppliers and systems used to take days. AI compresses it to minutes, and the NCSC rates this among the clearest capability gains at every attacker skill level.
The social engineering built on that research is sharper too: the flawless phishing email and the cloned voice each have their own page in this series.
Capability that needed a specialist team is now available to novices, and the NCSC expects exactly that to increase the volume of successful compromises of devices and accounts.
Faster research, faster drafting and faster iteration shorten every stage of an attack, which shrinks the slack your response processes were built around.
Reading the headlines
"AI cyber attack" spikes in the news a few times a year, and the coverage usually blurs three real patterns into one imaginary one. The real three: AI-polished social engineering doing the breaking in, which is by far the commonest; AI-assisted reconnaissance and vulnerability hunting; and AI used to draft or adapt attack tooling. The imaginary one is the fully autonomous attacker that picks its own targets and needs no human.
The honest picture is the NCSC's uneven one: the biggest gains go to less-skilled attackers running social engineering, while the most sophisticated uses stay with well-resourced groups. For most businesses the question is not whether you are ready for an AI superweapon. It is whether your people-facing safeguards are ready for lures with no tells left.
So when an incident is in the news and someone asks whether it could happen to you, translate the question: which entry on our register does this map to, and does the safeguard on that entry still hold? That version has an owner and an answer.
Fundamentals, less slack
Nothing on this list is new, which is the point. Phishing-resistant sign-in. Passkeys and hardware keys blunt the sharpest uplift, the lure that reads perfectly. Patch cadence. The window between a weakness being published and being tried against you is shorter; your patching rhythm should be too. Tested backups. Tested is the word that matters. Least privilege. Every credential and permission is on the attacker's menu; fewer of them means a smaller menu.
Then the register work: run AI as a driver across your existing cyber entries rather than adding one new entry called AI. Re-score likelihood entry by entry, and check what each safeguard assumes, the way the safeguards page describes. A safeguard built on spotting the fake has aged; one built on process has not.
The NCSC's near-term assessment is the sober reference on where the uplift lands, and the joint Engaging with AI guidance from the Australian, UK and US agencies covers the other half of the story: using AI safely inside your own business.
A cyber attack where AI does part of the attacker's work: researching the target, writing the lures, adapting the code, or running the campaign. The attack categories are the established ones; AI changes the speed, polish and volume, not the goal.
Yes, mostly as AI-enhanced versions of familiar attacks. The NCSC assesses that all types of threat actor, state and criminal, skilled and novice, are already using AI, with the clearest gains in reconnaissance and social engineering. The fully autonomous attack remains speculative.
AI can help write and adapt code, including malicious code, but the NCSC rates that uplift as more limited than the social engineering uplift. The practical near-term change is more attackers producing adequate attacks, not one attacker producing an unstoppable one.
Mostly no. The established fundamentals, phishing-resistant sign-in, patching, tested backups, least privilege, are still the defence; what changed is how little slack you have in applying them. The genuinely new work is on the human layer, where the lures have lost their tells.
As a driver, not a new entry. Re-score likelihood on the cyber entries you already carry, note where response windows have shrunk, and re-check what each safeguard assumes. One new entry labelled AI hides the change; re-scored existing entries show it.
The AI Disruption Index scores the risks AI is driving against your objectives, with a safeguard drafted for each. Free, in about ten minutes.
AI risk series
The real risks of AI for a business
The series hub: what counts as an AI risk, the four families, and where to start.
AI phishing: the email with perfect grammar
Why the spot-the-typo era is over, and the safeguards that work without spotting the fake.
Fraud no longer needs a forger
Deepfakes, voice clones, invoice fraud, and the safeguards that still hold.
AI scams targeting businesses
Old cons, industrialised: the four branches, the tells that remain, and what to do if you're hit.
Prompt injection: the attack your register hasn't heard of
Instructions hidden in ordinary content, and the safeguards that limit the damage.
Guardrails, safeguards, controls: what AI actually needs
Three words untangled, and the four families of AI-era safeguards.
How to run an AI risk assessment
Three ways to do it, compared, and the five steps.
The AI risk register
What every entry carries, with worked examples.
The AI policy your business actually needs
The full template, free on the page, and how to make it yours.
AI in risk management: what it can genuinely do
The four jobs AI does well, and the three things it must never own.
What is AI disruption?
A plain definition: the change is in your risks and plans, not just your tools.
AI hallucinations at work: examples and what they cost
Three documented cases with price tags, and the verification safeguards that catch fabrication before it ships.
See your own AI risk picture
The risks AI is driving against your objectives, scored for your business.