Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AI is raising business cybersecurity risk in two directions at once: criminals can use it to make impersonation and fraud more convincing and to speed up parts of cyber operations, while companies that deploy AI systems and agents create additional data, software, and access paths to secure. It amplifies familiar threats; it has not invented cybercrime, and the available evidence does not show that every business attack now uses AI.

What the numbers say—and what they do not

The FBI’s Internet Crime Complaint Center (IC3) reported the following figures for 2025:

Measure Reported figure How to read it
Complaints reporting AI-related information 22,364 IC3 complaint count; not a census of all AI-enabled crime or business exposure.
Adjusted losses associated with those complaints $893,346,472 IC3’s adjusted-loss figure for the AI-related complaints; it is not a complete accounting of AI-caused losses.
Business losses reported for business-email-compromise (BEC) scams involving AI Over $30 million Reported BEC losses involving AI. IC3 notes that not all BEC tactics are AI-enabled.

These are reported complaints and losses, not a measure of every incident or proof that AI caused every loss in the totals. The primary sources reviewed do not establish a reliable share of all business cyberattacks caused by AI or a comparable year-over-year AI-specific business breach rate. Treating either as known would overstate what the figures show.

How AI can make familiar attacks more convincing

Impersonation and targeted messages

Generative AI can help produce text, profile images, audio, and video that support phishing, social engineering, financial fraud, and impersonation of executives or other trusted figures. The FBI’s December 3, 2024 public service announcement describes these as observed uses of synthetic content—not evidence that every unusual message or call is AI-generated. As the FBI puts it, “The creation or distribution of synthetic content is not inherently illegal; however, synthetic content can be used to facilitate crimes, such as fraud and extortion.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
SecuX PUFido USB-C Security Key with PUF Technology, FIDO2/U2F Certified, Hardware-Rooted Unclonable Security for Passwordless Login and 2FA Authentication
  • A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
  • FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
  • Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
  • Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
  • Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.

For a business, the danger is not limited to a generic phishing email. An attacker may use public information to tailor a plausible story, imitate a familiar voice, or create a realistic-looking page or link. NIST’s Cybersecurity Framework Profile for Artificial Intelligence, an initial preliminary draft dated December 2025, discusses these possibilities as risk scenarios, not measured attack rates.

Why visual or grammatical “AI tells” are a weak test

Generated content can be polished and personalized, so awkward wording or obvious image glitches are not dependable ways to decide whether a request is genuine. Verify the identity and the requested action instead. A sudden payment instruction, bank-detail change, request for credentials, or demand for sensitive data should be checked through a separate, trusted channel—even if it appears to come from a known colleague.

How AI may speed up cyber operations

NIST’s December 2025 preliminary draft describes ways AI could help adversaries identify exploitable weaknesses, move through attack paths faster, exfiltrate or tamper with data, and scale activity. It also identifies realistic spear phishing, manipulated audio or video, malicious sites, and malware designed to evade signature-based detection.

Rank #2
SecuX PUFido® Drive Clife Key USB C Security Key with PUF Technology and Built in Flash Drive, FIDO2 U2F Certified Hardware Rooted Unclonable Security for Passwordless Login and 2FA Authentication (1)
  • Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
  • FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
  • Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
  • Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
  • Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.

Those are potential capabilities and risk areas, not a claim that every attacker has advanced AI tools, that attacks are autonomous by default, or that AI reliably defeats modern defenses. The practical concern is that some parts of an attack may become faster or easier to adapt, leaving less room for a business to rely on slow verification or delayed response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AI systems and agents can create new exposure

Protect the system, not just the people using it

AI is also a target. NIST’s Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1, July 26, 2024) identifies prompt injection and data poisoning among security risks. It also calls attention to the code, training data, model weights, availability, and deployment environment associated with AI systems. A business should consider what information can be submitted, where it is processed, who can access related assets, and how the system is maintained.

NIST summarizes the dual risk this way: “GAI-based systems present two primary information security risks: GAI could potentially discover or enable new cybersecurity risks by lowering the barriers for or easing automated exercise of offensive capabilities; simultaneously, it expands the available attack surface, as GAI itself is vulnerable to attacks like prompt injection or data poisoning.”

Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Agents need boundaries around actions and access

An AI agent may be connected to business applications, files, or other tools and may take actions rather than only generate text. For each agent, map the information it can reach, the tools it can call, the actions it is permitted to perform, and the point at which a person must approve a consequential action.

NIST’s May 18, 2026 summary of public comments on AI-agent security reports broad agreement that agents present novel security threats and that baseline practices may need adaptation. It is a summary of stakeholder responses, not a finalized universal technical standard. Use access control, oversight, and risk management as practical starting points while agent-specific guidance continues to evolve.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What businesses can do now

AI does not make established security controls obsolete. The Federal Trade Commission’s Cybersecurity for Small Business guidance points organizations to the voluntary NIST Cybersecurity Framework 2.0 structure: Govern, Identify, Protect, Detect, Respond, and Recover. Adapt the measures below to the organization’s size, sector, systems, and obligations.

Rank #4
Thetis Pro FIDO2 Security Key Passkey with Complex Pin [PinPlex], Hardware Device Supports USB A, Type C &NFC, TOTP/HOTP Authenticator APP, PIV Certificates, FIDO 2.0 Two Factor Authentication 2FA MFA
  • Dual USB-A and USB-C Security Key – Features both USB-A and USB-C connectors for seamless compatibility across desktops, laptops, and tablets. Supports plug-and-stay use or keychain carry.
  • NFC-Enabled for Mobile Access – Built-in NFC allows fast, wireless authentication with Android and iPhone devices. Ideal for mobile logins and on-the-go security.
  • FIDO Certified for Strong Authentication – [CHECK COMPATIBILITY before purchase] Fully compliant with FIDO2 and FIDO U2F standards. Works with major platforms like Google, Microsoft, GitHub, and Dropbox.
  • Passwordless Login with PinPlex – Supports secure passkey login via WebAuthn and CTAP2 with added protection from PinPlex, a complex PIN system that enhances physical security.
  • Multi-Layer Authentication Support – Includes PIV certificates and supports both TOTP and HOTP for strong 2FA/MFA coverage across enterprise and consumer apps.

1. Govern and inventory

  • Keep an inventory of AI tools and services in use, including who owns each one, what data it handles, and which business systems it connects to.
  • Review contractual and legal requirements that apply to the data and services involved.
  • Apply the same inventory discipline to integrations and agents: document permissions and permitted actions, not just the product name.

2. Protect identities, accounts, and money movement

  • Require multifactor authentication (MFA) for business accounts and restrict privileged access and access to sensitive data to people who need it.
  • Verify unusual payment, credential, and bank-detail-change requests through a known, separate channel. Do not use contact details supplied in the suspicious message itself.
  • Set clear approval requirements for consequential transactions and for AI agents that can initiate or alter them.

3. Strengthen email and domain defenses

Configure and monitor SPF, DKIM, and DMARC for company domains. The FTC explains that these complementary email-authentication protocols help receiving servers check whether mail is authorized and how to handle suspicious messages. They can reduce domain spoofing, but they do not prevent every lookalike domain, compromised account, or voice-based scam.

4. Protect systems and data

  • Patch software, encrypt sensitive data in transit and at rest, and maintain regular backups.
  • For AI services, assess what data staff may enter and how inputs, outputs, integrations, and deployment environments are protected.
  • Limit an agent’s permissions to the data and actions needed for its assigned task. Keep human review for actions whose impact warrants it, and retain enough logging to investigate activity.

5. Train staff to verify and report

Use role-specific scenarios involving payment requests, executive impersonation, links, and sensitive-data requests. Teach employees how to report suspicious contact and how to verify an unusual request independently. Measure whether people follow verification and reporting procedures, not only whether they complete a course.

6. Prepare to detect, respond, and recover

Monitor for unauthorized activity and maintain incident-response, disaster-recovery, and business-continuity plans. Test the plans, including how the business will contain compromised accounts or connected AI tools, preserve essential operations, and restore data from backups.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to choose safeguards without chasing an “AI detector”

No single detector is a substitute for controls around identity, access, data, and approvals. When comparing security measures, use criteria that fit the risk rather than assuming one tool solves the problem.

  • Authentication: assess resistance to phishing, rollout and recovery, support across business accounts, management of lost devices, and total cost.
  • AI systems and agents: examine data sensitivity, permission breadth, external connectivity, logging and auditability, human approval for consequential actions, and the ability to contain an incident.
  • Email protection: compare domain-spoofing coverage, monitoring and reporting, handling of legitimate senders, and ongoing maintenance.
  • Training: look for realistic role-based scenarios, regular practice, a clear reporting path, and ways to assess follow-up behavior.

These are decision criteria, not results from a tested vendor comparison. The core business problem is manageable: AI can make some attacks more persuasive or efficient, and AI deployments can add exposure, but disciplined verification, limited access, monitoring, and recovery planning still address the underlying risks.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.