Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

No—AI has not made traditional cybersecurity defenses obsolete. Strong passwords, multifactor authentication (MFA), software updates, phishing awareness, and incident response still matter. But generative AI can amplify familiar attacks, and AI systems introduce additional risks involving data, model behavior, privacy, and software supply chains. Security needs to cover both.

Why AI changes cybersecurity without making the old defenses useless

There are two related but different problems. Attackers can use AI to support attacks on people and conventional IT systems; meanwhile, AI applications and their data can themselves be attacked. A password or MFA protects an account, for example, but it does not prevent poisoned training data or a prompt injection in an AI application.

NIST’s AI 100-2 E2025, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, published in March 2025, organizes attacks on machine-learning systems by their goals, methods, and place in the system lifecycle. NIST’s security and resilience research page, updated August 14, 2026, says existing frameworks do not comprehensively address several machine-learning attacks or AI’s complex attack surface. It also notes AI’s potential to help defenders. This is a case for extending security practices—not abandoning them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The eight points below are an editorial way to organize the risks, not an official NIST or government list.

Eight ways AI is changing the threat picture

1. Phishing and impersonation can be more persuasive

Generative AI can help produce tailored phishing, scams, fraud, and impersonation attempts. A message that is polished or specific is not necessarily legitimate, and an AI-written message does not automatically bypass filters or fool its recipient. The UK government’s assessment of generative-AI risks through 2025 identified these as risks AI could enhance; it was a forward-looking assessment, not a measurement of how often attacks succeed today.

For users, verify unusual requests through a separate trusted channel, especially requests to share credentials, approve a payment, or disclose sensitive information. Do not treat familiar tone, correct spelling, or apparent personal details as proof of identity.

2. Some attacks may move faster or reach more targets

Automation can help attackers work more quickly or at greater scale on some tasks. The UK government assessment expected generative AI to amplify existing risks in this way, but it also judged fully automated computer hacking unlikely within its stated horizon through 2025. That forecast should not be mistaken for a current 2026 capability measurement, nor does it mean AI can autonomously compromise any target.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For defenders, speed raises the value of routine controls: timely updates, access limits, monitoring, and a practiced response process can reduce the time an attacker has to exploit a foothold.

3. More people may be able to attempt sophisticated-looking attacks

The UK assessment warned that the growing accessibility of generative AI could let less-sophisticated actors attempt attacks that had previously been beyond their reach. That is a concern about lowered barriers, not evidence that every user of AI becomes a capable attacker or that the number of attackers has increased by a particular amount.

Organizations should avoid relying only on assumptions about an attacker’s skill. Secure configuration, least-privilege access, and monitoring are useful whether an attempt is highly sophisticated or assembled with readily available tools.

4. Training data can be poisoned

Data poisoning means manipulating or supplying untrustworthy data so it influences a model’s behavior. It is distinct from stealing a password or infecting an ordinary computer with malware, although a compromised data source or service can create a route into an AI system’s workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NIST’s January 4, 2024 explanation described how adversaries may confuse or poison AI systems. Its later 2025 taxonomy provides the more current terminology. The risk depends on how a system obtains, checks, and uses data; it is not a universal way to compromise every model.

5. Adversarial inputs can manipulate model behavior

In adversarial machine learning, an attacker may craft inputs intended to make a model produce an incorrect or otherwise useful-to-the-attacker result. NIST’s taxonomy includes evasion and other attack methods aimed at influencing system behavior. The consequences depend on the model’s role and deployment: a mistaken classification in a low-impact tool is different from an output used to support a consequential decision.

Testing should reflect the actual use case, inputs, and consequences of failure. A general claim that a model is “secure” does not establish that it will behave safely under every relevant input or operating condition.

6. Prompt injection and privacy attacks affect AI integrations

The UK assessment names prompt injection and model inversion among risks associated with integrating AI. Prompt injection seeks to influence how an AI application follows instructions or handles content. Model inversion concerns attempts to infer sensitive information associated with a model. Neither is a universal method for breaking every AI product, and the exposure depends on the application’s design, data, and permissions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For an AI application, consider what information it can access, what actions it can take, and whether outputs are reviewed before they trigger consequential actions. Restricting access and separating untrusted content from privileged instructions can reduce exposure, but they are not guarantees against every attack.

7. AI systems have more lifecycle and supply-chain components to secure

An AI service depends on more than a model in isolation. NIST’s current security and resilience work identifies training and test data, model weights, and configuration settings as components relevant to AI controls. Development, deployment, and operation can each introduce risks; systems may also depend on external software, data, and services.

Joint guidance announced by CISA and partner agencies on April 15, 2024 focuses on securely deploying externally developed AI systems. It frames the work around protecting confidentiality, integrity, and availability, addressing known vulnerabilities, and providing ways to protect, detect, and respond to malicious activity against AI systems and related data and services.

8. Mitigations do not guarantee complete protection

Security controls reduce risk; they do not promise that every attack will be prevented. NIST’s January 2024 release reported that available AI mitigations lacked robust assurance that they fully mitigated the risks. NIST computer scientist Apostol Vassilev, one of the report’s authors, said: “We also describe current mitigation strategies reported in the literature, but these available defenses currently lack robust assurances that they fully mitigate the risks. We are encouraging the community to come up with better defenses.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That limitation argues for layers: prevent what can be prevented, monitor for suspicious activity, and prepare to respond and recover. It does not show that conventional controls are useless.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Which defenses still matter—and what AI security adds

Different controls address different parts of the problem. Baseline protections for identity and ordinary IT remain important; AI-specific risk management adds attention to model behavior, data, configuration, and integrations. Monitoring and response span both.

Security layer What it addresses Practical focus
Identity and account security Unauthorized access to user and administrator accounts Unique passwords and MFA; limit access to what each account needs
Software and IT security Known vulnerabilities and malicious activity in conventional systems Install updates, maintain secure configurations, monitor activity, and prepare to respond
AI system security Risks involving models, data, settings, and application behavior Assess the system across development, deployment, and operation; protect associated data and services
Detection and response Malicious activity affecting either conventional IT or AI systems Establish how to detect, contain, and recover from incidents

What individuals can do when using AI

CISA’s September 2024 Stay Safe Online When Using AI tip sheet applies its “Core 4” to online safety when using generative AI:

  • Use strong, unique passwords.
  • Turn on MFA for accounts that support it.
  • Install software updates.
  • Stay alert to phishing.

CISA identifies a physical security key as a phishing-resistant MFA option where an account supports it. Check the service’s available methods and recovery process before choosing an option; a key protects account sign-in, not the data or behavior of an AI model. You do not need a physical key to make use of MFA—the suitable method depends on the service and your needs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What organizations and AI developers should add

AI security should be part of the system’s lifecycle rather than a final check after deployment. In practice, organizations can:

  • Identify the AI system’s data, models, configurations, software, and external services, and determine who can change or access them.
  • Assess how the model and its surrounding application could be affected by manipulated inputs, untrustworthy data, or unauthorized access.
  • Test controls against the system’s intended use and likely failure consequences instead of assuming general software controls cover every AI-specific risk.
  • Monitor AI systems and related services, and define how to investigate, contain, and recover from malicious activity.
  • Keep baseline protections—such as updates, access control, and incident response—in place alongside AI-specific safeguards.

CISA and partner agencies’ guidance is specifically about deploying externally developed AI systems; it should not be read as a complete prescription for every AI development context. NIST’s lifecycle and attack-taxonomy work can help organizations identify where their own system needs additional assessment.

So, are traditional cybersecurity defenses obsolete because of AI?

No. AI changes how some threats can be carried out and adds attack surfaces that ordinary account and software controls do not cover on their own. Traditional defenses still reduce risk to people and conventional IT; AI deployments also need controls for data, model behavior, configuration, integrations, and lifecycle operations. Because neither layer guarantees complete prevention, monitoring and a credible response plan matter too.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.