The exact share of UK workers who have had no training on AI-driven cyber threats is unclear: two accounts of a QA-associated survey give conflicting figures, 61% and 39%. Neither figure can be confirmed from the accessible primary survey material. Separate government figures show that only 19% of businesses and 17% of charities reported running staff cyber security training or awareness activity in 2025/2026, but those figures measure organizations and are not specifically about AI threats.
Why the headline figure is disputed
A report by The Business Investor, published 2 October 2026, says 61% of workers received no training of any kind on AI-driven threats, including AI-generated phishing, during the previous 12 months. A QA search result dated the same day describes a survey finding that 39% of employees received no training on AI-powered cyber threats during the previous 12 months.
The accessible material does not explain why the figures differ. The underlying survey page and question wording were not available to resolve whether the accounts use different definitions, populations, field dates, or methods. It is therefore not sound to state that almost two thirds—or any other precise share—of UK workers went untrained as an independently verified fact.
| Source and measure | Reported figure | What can be concluded |
|---|---|---|
| The Business Investor’s account of a QA-associated worker survey | 61% received no AI-threat training in the previous 12 months | Secondary reporting; the primary survey details were not available to confirm the claim. |
| QA-associated search result | 39% received no AI-powered cyber-threat training in the previous 12 months | The result conflicts with the secondary report and does not disclose enough to reconcile it. |
| Government Cyber Security Breaches Survey 2025/2026 | 19% of businesses and 17% of charities ran staff training or awareness activity | Organization-level activity, not a worker-level measure or a count of AI-threat training. |
What the government figures do—and do not—say
The Department for Science, Innovation and Technology and Home Office survey reports whether organizations ran staff cyber security training or awareness activity. Its 19% business and 17% charity figures do not show how many individual employees attended, how often training happened, or whether it covered AI-enabled attacks. They cannot be directly compared with a worker survey about receiving training on AI threats.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
A separate government report found that 50% of business cyber leads and 48% of charity cyber leads were not confident preparing training materials or sessions. That is a measure of cyber leads’ confidence, not evidence that those shares of employees lacked training; see the Cyber security skills in the UK labour market 2026.
How AI changes familiar cyber threats
The UK National Cyber Security Centre (NCSC) says threat actors are already using AI to improve reconnaissance, vulnerability research and exploit development, social engineering, basic malware generation, and analysis of stolen data. In its assessment, Impact of AI on cyber threat from now to 2027, published 7 May 2025, the NCSC expects much of AI’s near-term effect to be an improvement in existing tactics rather than entirely new kinds of attacks. It says AI will almost certainly make elements of cyber intrusion more effective and efficient.
Rank #2
- Matt-laminated and greaseproof pages ensure glare-free reading and long life
- The outside covers are made from a new rubberized material for better Handling and Grip
- All the Tool Holder Identification Sections now include a full INCH section along with a METRIC section
- Updated and Improved Index Searching
That does not mean every convincing phishing message was written by AI, or that AI-generated messages have a reliable tell. Polished spelling and grammar are not proof that a message is safe. The practical risk is that familiar deception—an urgent request, a believable impersonation, or a tailored lure—can be made more effective.
What to do with a suspicious message or request
There is no dependable visual test for whether a message was written by AI. Treat unexpected requests for money, login details, sensitive information, or urgent action as a reason to pause, regardless of how fluent the message sounds.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →- Verify the request using a known phone number or contact method, not contact details supplied in the message.
- Do not open unexpected links or attachments while you are unsure whether the message is genuine.
- Report the message through your employer’s established security process, especially if it targets a work account or asks for a business action.
These are sensible ways to handle social engineering; they cannot guarantee that an attack will be detected or stopped. Employers should pair awareness training with appropriate security controls. The NCSC’s guidance on AI and cyber security covers organizational considerations for secure AI use.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Where workers and employers can find training
QA lists employee awareness learning, workshops, webinars, certifications, and other training options on its Cyber Security Awareness Month 2026 page and in its cyber security course catalogue. These pages show that training resources are available; a course listing alone does not establish how effective a course is or whether it suits a particular workplace. Employers should choose content that reflects their staff’s roles, the organization’s reporting process, and the kinds of requests employees are expected to verify.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

