Every control in this article comes from authorised engagements, run under contract with permission to test the human layer. We are describing what we do to clients who hired us, so that you can stop the people who did not.

What AI changed

Two things: scale and quality. The tells we used to teach people to spot are gone. Phishing is now fluent in any language, free of the spelling mistakes that gave it away. Pretexts are personalised from data scraped off LinkedIn and the company blog, so the message references a real project and a real colleague. A voice can be cloned from a few seconds of a conference talk. Video calls can carry a real-time face that is not the person's. None of this is exotic anymore. It is cheap, fast, and good enough.

What we get away with now

The engagements land differently than they did two years ago. A cloned voice of a finance lead, left as a voicemail about an urgent payment, gets callbacks. A short deepfake on a "verification" video call gets a contractor to reset an account. AI-written spear-phish, tuned to one person's role and recent work, sails past the smell test that used to catch the generic version. The technique is old. The polish is new, and the polish is what gets people to act.

Awareness training has to change

The old advice has stopped working. "Look for typos" and "check the sender name" assume sloppy attackers, and attackers are not sloppy now. Training has to move from spotting mistakes to a single habit: verify high-stakes requests out of band, no matter how convincing they look or sound. Money, credentials, and access requests get confirmed on a known channel before anyone acts. Teach people that a familiar voice or face is no longer proof of identity, because both can be faked. And make reporting a suspected attempt fast and blameless, so people raise a hand instead of hiding a mistake.

Training is necessary, not sufficient

Here is the part that gets skipped: good people will still be fooled by a good fake, and blaming them does not fix it. The reliable controls are in process, not in vigilance. A callback to a number you already had on file, not the one in the message. Two-person approval for transfers above a threshold. A shared code word for high-stakes verbal requests. The point is to remove single points of human failure, so one convinced employee is not enough to cause the loss.

Make the password not matter

The strongest control against credential phishing is to make a stolen password useless. Phishing-resistant authentication, passkeys and hardware security keys built on FIDO2, does exactly that: the credential is bound to the real site and cannot be replayed to a fake one. Push-approval prompts do not clear the same bar, because a tired person taps approve. Move the high-value accounts, admins, finance, anyone who can move money or access, onto phishing-resistant keys first. After that, the fluent phishing email has nothing to steal that works.

Where AI helps the defender

The same tools cut both ways. Anomaly detection on payment requests flags the out-of-pattern wire. Liveness and deepfake checks add friction to verification calls. AI triage sorts the flood of reported messages so a human looks at the ones that matter. Use it as a layer, not a guarantee. A detector that is right most of the time still misses the one that counts, which is why the process controls come first.

The controls that actually hold

  1. Move admins, finance, and anyone who can move money onto phishing-resistant MFA.
  2. Require out-of-band verification for money, credentials, and access changes.
  3. Rewrite awareness around verifying requests, not spotting typos.
  4. Add two-person approval and a code word for high-stakes requests.
  5. Run a social-engineering test that includes AI-assisted voice and pretext.
  6. Make reporting a suspected attempt a single click, with no blame attached.
You cannot train your way out of a perfect fake. You can build a process where one fooled person is not enough to cause the loss. That is the goal: not people who never get tricked, but a company that survives when they do.

The attackers upgraded their tools this year. The defence is not better instincts. It is verification you do not have to think about and credentials that cannot be replayed.