AI Can Enhance Cyber Threats but Human Training Is Key
AI Can Enhance Cyber Threats but Human Training Is Key
While major technology companies sound the alarm about AI-powered cyberattacks threatening critical infrastructure, the solution may lie less in sophisticated defensive technologies and more in addressing the human vulnerabilities that have plagued cybersecurity for decades.

A coalition of tech giants including OpenAI, Google, Microsoft, and Amazon Web Services recently issued an open letter warning that AI-enabled cyberattacks could become widespread within months, targeting hospitals, water treatment plants, and power systems. The letter, signed by more than 100 organizations, points to an 89% increase in AI-enabled attacks in 2025 compared to the previous year, according to CrowdStrike data. Yet amid the urgent calls for advanced AI defense tools and increased funding, a critical question emerges: Are organizations overlooking the most effective defense mechanism already at their disposal-properly trained employees?
The warning from these technology leaders is not without merit. AI is undeniably transforming the threat landscape, making sophisticated attack capabilities faster, cheaper, and more accessible to adversaries. However, the rush to deploy AI-powered defense systems may be diverting attention and resources from addressing the fundamental human and organizational weaknesses that have consistently proven to be the weakest links in cybersecurity chains.
The Human Element Behind Most Breaches
Despite the growing sophistication of cyber threats, research consistently shows that human error remains the primary entry point for most successful attacks. Social engineering, phishing campaigns, and credential theft-all tactics that exploit human psychology rather than technical vulnerabilities-continue to account for the vast majority of security incidents. AI may make these attacks more convincing and scalable, but it does not fundamentally change the fact that humans are making the critical mistakes that allow breaches to occur.
Catherine Hwang, Product Marketing Director at Proofpoint, notes that “AI simply amplifies existing human vulnerabilities.” This observation is crucial. Voice cloning technology can make vishing attacks nearly undetectable, and AI-generated phishing emails can bypass traditional detection methods by appearing more legitimate. However, these enhanced attacks still rely on the same fundamental weakness: inadequately trained employees who cannot recognize sophisticated social engineering attempts.
The reality is that organizations have spent decades investing in perimeter defenses, intrusion detection systems, and now AI-powered security tools, yet employee security awareness training often receives a fraction of the attention and resources. Many companies treat cybersecurity training as a compliance checkbox-an annual requirement to be completed quickly and forgotten-rather than an ongoing cultural priority.
The Persistent Gap in Basic Security Hygiene
The open letter from tech companies identifies several persistent vulnerabilities that leave organizations exposed: unpatched software, excessive system permissions, weak authentication, misconfigurations, and legacy technology. Notably, most of these vulnerabilities are not technical challenges that require AI solutions to address. They are organizational and process failures that stem from inadequate training, poor security culture, and lack of accountability.
When employees do not understand why timely patching matters, systems remain vulnerable for extended periods. When staff members are not trained to follow least-privilege principles, excessive permissions proliferate throughout networks. When workers lack awareness of authentication best practices, weak passwords and shared credentials become commonplace. These are not problems that AI defense tools can solve-they require human understanding, compliance, and behavioral change.
The emphasis on AI threats may actually be counterproductive if it creates a perception that cybersecurity is becoming too complex for non-technical employees to understand or influence. This mindset can lead to disengagement, with workers assuming that security is entirely the responsibility of IT departments and automated systems. In reality, every employee makes dozens of security-relevant decisions daily, from how they handle sensitive data to whether they click on unexpected email attachments.
The Limits of Technology-Centric Solutions
The voluntary nature of the open letter-lacking binding requirements, deadlines, or specific funding commitments-raises questions about whether the tech industry’s prescription is truly the most effective path forward. The call for organizations to “demand stronger safeguards in the software and AI-generated code they use” places responsibility on purchasing decisions and vendor requirements, rather than on building internal capability and resilience.
This approach has limitations. Even the most secure software and the most advanced AI defense tools cannot protect organizations from employees who fall victim to social engineering, who misconfigure systems due to lack of training, or who fail to follow security protocols because they do not understand their importance. The Five Eyes cyber security agencies’ statement emphasizes that “cyber risk can no longer be treated as a purely technical issue” and that “a whole-of-organization and whole-of-society response is required.”
Yet the focus on AI-powered threats and AI-powered defenses risks framing cybersecurity as an arms race between competing technologies, rather than as a fundamentally human challenge. Organizations that invest millions in AI security tools while neglecting comprehensive employee training programs are building impressive walls while leaving the front door unlocked.
Training as a Force Multiplier
The case for prioritizing human training is not an argument against using technology or AI in cybersecurity defense. Rather, it is a recognition that technology is most effective when deployed in support of a security-aware workforce, not as a substitute for one. AI tools can detect anomalies, automate responses, and analyze vast amounts of data-but they are far more effective when employees understand security principles well enough to recognize suspicious activity, report potential incidents promptly, and follow established protocols consistently.
Research on cybersecurity awareness training demonstrates its tangible impact on organizational security posture. Organizations with robust, ongoing training programs see measurable reductions in successful phishing attempts, faster incident reporting, and better compliance with security policies. These outcomes directly address many of the vulnerabilities identified in the tech coalition’s letter-not through advanced technology, but through informed human decision-making.
Effective security training goes beyond teaching employees to recognize obvious phishing emails. It develops a security mindset that influences behavior across all work activities. Trained employees are more likely to question unusual requests, verify identities before sharing sensitive information, use strong authentication methods, keep software updated, and recognize when something seems wrong-even if they cannot articulate exactly what the technical threat is.
The Challenge of Competing Priorities
One reason that human training may receive less emphasis than AI solutions is that technology investments are more tangible and easier to quantify. Organizations can point to specific security tools they have deployed, contracts they have signed, and systems they have implemented. Employee training is messier-it requires ongoing effort, cultural change, and behavioral modification that cannot be purchased in a single transaction.
Additionally, the cybersecurity industry has strong incentives to emphasize technological solutions. Vendors sell products and services, not cultural transformation. The narrative of AI-powered threats requiring AI-powered defenses naturally leads to increased demand for sophisticated security tools. While these tools have genuine value, the emphasis on technology can crowd out discussions of less profitable but equally important interventions like comprehensive training programs.
The urgency rhetoric around AI threats-with timelines measured in months rather than years-may also work against the long-term commitment required for effective training initiatives. Organizations feeling pressure to respond immediately to emerging threats may opt for technology deployments that can be completed quickly, rather than training programs that require sustained effort to change organizational culture and individual behavior.
Building a Balanced Defense Strategy
The most effective cybersecurity strategies recognize that technology and human capability are complementary, not competing, priorities. AI-powered tools can provide valuable capabilities for threat detection and response, but they achieve maximum effectiveness when deployed within organizations where employees understand security principles and actively participate in defense.
The practical actions outlined by the Five Eyes agencies include several that are fundamentally dependent on human training and organizational culture: reducing attack surface through thoughtful system design, accelerating patching processes, addressing legacy systems, strengthening access controls, and preparing for incidents. These actions require employees at all levels to understand security implications of their decisions and to prioritize security even when it creates inconvenience or slows other work.
Organizations serious about cybersecurity should ensure that investments in training are proportional to investments in technology. This means moving beyond annual compliance training to ongoing programs that evolve with the threat landscape, include realistic simulations of current attack techniques, and are tailored to different roles within the organization. It means measuring training effectiveness through behavioral change and security outcomes, not just completion rates. And it means creating a culture where security awareness is recognized as a core competency for all employees, not just IT staff.
The Risk of Over-Reliance on Automation
As AI tools become more sophisticated on both offense and defense, there is a risk that organizations will become over-reliant on automated systems and lose the human expertise necessary to understand and respond to novel threats. The Harvard Extension School notes that “one important method for mitigating risk is to keep humans involved in the AI loop” because human analysts can help prevent errors and evaluate situations with nuance that AI systems cannot replicate.
This observation applies equally to defensive strategies. Automated systems can process information at speeds and scales that humans cannot match, but they lack the contextual understanding, creative problem-solving, and ethical judgment that human experts bring to security decisions. Organizations that neglect human training in favor of AI automation may find themselves unable to respond effectively when attacks evolve in unexpected ways or when automated systems fail or produce false results.
The threat landscape will continue to evolve, and AI will undoubtedly play an increasing role in both attacks and defenses. However, the fundamental vulnerabilities that enable most successful breaches-human error, inadequate security culture, and organizational failures-are not new problems, and they will not be solved primarily through technology. The tech industry’s warning about AI-powered threats should be taken seriously, but the response must be balanced and comprehensive.
A Call for Holistic Investment
The open letter from major tech companies calls for treating cybersecurity as an urgent priority, and this urgency should extend to investing in human capability as much as in technological tools. Organizations should audit not only their technical defenses but also their training programs, security culture, and employee awareness levels. They should ask whether their workforce could recognize and respond appropriately to the sophisticated social engineering attacks that AI is making more effective.
Governments and industry groups promoting cybersecurity should ensure that guidance and funding opportunities support comprehensive approaches that include human training alongside technology deployment. Security awareness should be integrated into professional development across industries, recognized as a critical skill in the same way that technical competencies are valued and developed.
The stakes identified in the warning-threats to hospitals, utilities, transportation systems, and other critical services-are real and serious. However, defending these systems effectively requires more than advanced AI tools. It requires organizations where every employee understands their role in security, recognizes threats in their various forms, and acts consistently to follow security best practices. Technology can amplify human capability, but it cannot replace it. In the race to deploy AI defenses against AI threats, organizations must not lose sight of the fundamental truth that cybersecurity ultimately depends on people making informed, security-conscious decisions every day.
