Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

AI is changing parts of familiar cyberattack workflows, especially content creation, analysis, personalization and automation. That does not mean cybercrime has become a wholly new or universally autonomous phenomenon: attackers still use conventional tactics and infrastructure, while AI systems themselves have also become targets. The key is to distinguish attacks that use AI from attacks aimed at AI.

What counts as an AI cyberattack?

The phrase can mean two different things. An AI-assisted attack uses an AI system as a tool during an attack—for example, to draft a phishing message or analyze information. An attack on an AI system seeks to manipulate, compromise or extract information from the model or its surrounding application. These categories can overlap, but they are not interchangeable.

Traditional attacks remain useful categories for describing what an attacker is trying to do: steal credentials, exploit a vulnerability, deceive a person or deploy ransomware. AI may change how a step is carried out without replacing the objective, the rest of the attack chain or the infrastructure involved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do AI-assisted attacks differ from traditional attacks?

The distinction is usually about the means, not the goal. A phishing attempt still tries to persuade a person to reveal information or take an action; AI can help produce or personalize the message. An intrusion still involves gaining access and moving through systems; AI may assist with parts of that work. The following comparison describes tendencies, not a claim that every attack fits one column exactly.

What to compare Traditional attack workflow AI-assisted workflow
Attacker’s objective May include stealing credentials, exploiting a vulnerability or deploying ransomware. Can pursue the same objectives; using AI does not, by itself, change the goal.
AI’s role AI is not required for the attack as described. AI may help with content, analysis, personalization or automation at one or more stages.
Infrastructure May rely on conventional tools, websites, accounts and compromised systems. Can still rely on those tools and infrastructure alongside AI; AI does not replace the attack chain.
Scale and personalization Depends on the attacker’s tools and effort. AI can help create personalized or persuasive content at scale, including impersonation material.
Human involvement People may make decisions or carry out steps. Automation may reduce effort in some reported cases, but available evidence does not establish general end-to-end autonomy in real-world attacks.
Defensive focus Protect accounts, systems, people and infrastructure against the relevant tactic. Maintain those protections and account for AI tools, applications and dependencies where they are deployed.

OpenAI’s 2026 account of malicious-use cases describes actors combining AI with tools such as websites and social media accounts, sometimes across different AI models and platforms. That is one reason it is misleading to imagine an AI attack as a single model acting alone.

How can AI help with phishing and social engineering?

Generative and predictive AI can support tasks such as producing content and analyzing large amounts of data. The Canadian Centre for Cyber Security’s National Cyber Threat Assessment 2025–2026 says AI can make social engineering more personalized and persuasive. It can also generate audio or visual content that impersonates a trusted person.

These capabilities can make a message more convincing or help produce more variations. They do not prove that a message is genuine, that an attacker has access to a target’s systems, or that a campaign will succeed. People and organizations should judge requests by their context and verify unusual or consequential instructions through a separate, trusted channel.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The U.S. Government Accountability Office (GAO), in Science & Tech Spotlight: Malicious Use Of Generative AI, summarizes an academic study estimating that AI could reduce malicious users’ phishing costs by more than 95%. This is a study-specific estimate about costs—not a measured reduction for all attackers, nor a statistic about phishing frequency or success.

What does it mean to attack an AI system?

Here, the AI system is the target rather than merely a tool used by an attacker. NIST’s 2025 report, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025), uses different categories for adversarial machine-learning threats. For predictive AI, its taxonomy includes evasion, poisoning and privacy attacks; for generative AI, it also includes misuse attacks.

  • Evasion: An attacker crafts inputs intended to cause an AI system to behave incorrectly or fail to recognize something it should detect.
  • Poisoning: An attacker manipulates data used in training or operation to influence system behavior.
  • Privacy attacks: An attacker seeks information about data or individuals associated with an AI system.
  • Misuse: An attacker manipulates a generative AI system into producing or assisting with harmful outputs, including by bypassing safeguards.

GAO describes approaches to manipulating generative AI safeguards, including role-playing prompts, gradually steering a system through seemingly benign steps and using multiple generative AI systems to refine prompts. These are methods of misuse or safeguard bypass; they are not evidence that a model autonomously completes every subsequent step of a cyberattack.

Can AI launch a cyberattack on its own?

The evidence supports a qualified answer: AI can automate or assist with substantial portions of some activity, but the available reporting does not establish that general-purpose AI systems routinely conduct end-to-end cyberattacks in the real world.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The International AI Safety Report 2026 says one AI developer reported a case in which a threat actor used its models to automate 80–90% of the intrusion effort, while humans remained involved at critical decision points. The report also describes laboratory demonstrations of network probing. It says general-purpose AI systems had not been reported to conduct end-to-end cyberattacks in the real world. The 80–90% figure is therefore a reported case, not a measure of all attacks or proof of fully autonomous operation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What do the available figures actually show?

These figures describe different measures and populations. They should not be added together or read as a direct comparison between AI-assisted and traditional attacks.

Figure What it measures What it does not establish
80–90% of intrusion effort A developer-reported case described in the International AI Safety Report 2026, in which models automated that share of the effort. A general automation rate, or an end-to-end real-world attack without human decision points.
More than 95% reduction in phishing costs A study-specific academic estimate summarized by GAO about malicious users’ phishing costs. A measured cost reduction for every attacker, or an increase in phishing success or frequency.
More than 48,000 new CVE identifiers in 2025, a 22% increase from 2024 ENISA’s 2026 threat-landscape announcement counts newly assigned vulnerability identifiers. The number of successful cyberattacks, or attacks caused by AI.
138 publicly reported generative AI incidents resulting in harm or near harm worldwide for 2024 The Canadian Centre for Cyber Security’s National Cyber Threat Assessment 2025–2026 reports this total, predicted from the first six months of 2024. A count of cyberattacks alone; the figure covers generative AI incidents resulting in harm or near harm.

There is no like-for-like dataset in these sources that establishes whether AI-assisted attacks are more frequent, more successful or more damaging than traditional attacks. Each figure answers a different question.

How should organizations defend against both kinds?

AI does not remove the need for sound cybersecurity fundamentals. Organizations should protect accounts, endpoints, networks and data against familiar threats, while including deployed AI applications and their dependencies in their security planning. ENISA’s 2026 overview describes this dual role: malicious groups can use AI to facilitate activity, and AI integrated into businesses can expand the attack surface.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protect people and conventional systems

  • Use established safeguards for accounts, systems, networks and sensitive data, rather than assuming an AI detector will identify every AI-assisted attempt.
  • Verify unusual payment, access or information requests through a separate trusted channel, particularly when a message appears to come from a known person.
  • Keep track of the AI applications in use and the systems or data they depend on, so security reviews cover the full deployment rather than only the model.

Test AI applications and layer safeguards

GAO describes several mitigation approaches: filtering user instructions, reinforcing safeguards through human feedback and using a separate generative AI system to detect malicious inputs. NIST’s report also discusses mitigations and their limitations. These measures can reduce risk, but they are not guarantees; developers and deployers need to continue testing and monitoring as attackers find new ways to manipulate systems.

NIST put the broader point plainly in its March 24, 2025 announcement: “Despite the significant progress of AI and machine learning (ML) in different application domains, these technologies remain vulnerable to attacks.”

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.