Human layer

What is AI Security Awareness Training?

The business guide to training your people for AI-driven attacks and the safe use of AI tools.

Key takeaways
  • AI security awareness training does two jobs. It teaches staff to spot AI-driven attacks and to use AI tools safely.
  • The UK NCSC judged in January 2024 that AI will almost certainly increase the volume and impact of cyberattacks, mostly through social engineering.
  • Deepfakes work. Engineering firm Arup lost about 25.6 million US dollars after a finance worker joined a video call where the CFO and colleagues were all AI-generated.
  • Shadow AI is the other risk. Samsung banned public AI tools in 2023 after engineers pasted source code and a meeting transcript into a chatbot.
  • In the United States, complaints to the FBI’s Internet Crime Complaint Center that referenced AI reached 22,364 in 2025, with reported losses of about 893 million dollars.
  • The EU AI Act has required a sufficient level of AI literacy among staff since 2 February 2025, under Article 4.
  • Sweden’s Cybersäkerhetslagen and NIS2 require security awareness training and make the board accountable for it.
  • The single most reliable habit is out-of-band verification. Confirm any unusual request for money, credentials or data through a separate known channel.
  • Annual training alone barely helps. A 2025 controlled study of more than 19,500 staff found no significant link between recent annual training and phishing failure rates.
  • What works is continuous, role-based training paired with process and technical controls, rather than a once-a-year course.

AI Security Awareness Training, Defined

AI security awareness training teaches employees to recognise and resist attacks that use artificial intelligence such as deepfake calls and AI-written phishing and to use AI tools at work safely without exposing sensitive data. It is security awareness training updated for AI-driven threats and the everyday use of AI in the workplace.

The change is recent and fast. In its January 2024 assessment, the UK National Cyber Security Centre judged that AI will almost certainly increase the volume and heighten the impact of cyberattacks with its biggest effect on social engineering. The people in your organisation are now the main target and the tools they use every day are part of the risk.

The training therefore has two jobs. The first is defence, helping staff recognise and stop AI-enhanced attacks. The second is safe use, helping staff get value from AI tools without leaking data or acting on an unchecked answer. Older awareness programmes covered neither well.

Why AI Changed the Threat to Your People

The human being has always been the softest target. What AI changed is the cost. A single attacker can now produce fluent, personalised messages in any language, clone a voice from a short recording and generate video of a real person’s face from clips found online.

Why AI Changed the Threat to Your People

The National Cyber Security Centre reached the same conclusion. Its assessment found that AI offers the biggest uplift in social engineering and that generative AI removes the spelling, grammar and translation mistakes that once gave phishing away. The FBI has warned that criminals use generative AI to commit fraud at larger scale and to make each attempt more believable.

There is a second pressure, pointing the other way. The tools that attackers use are the same tools your staff adopt to work faster. When an employee pastes a contract or source code into a public chatbot, sensitive data can leave the company. So the human layer now faces two AI risks at once, better attacks aimed at it and new ways for it to cause harm.

The AI Threats Your Team Must Recognise

Effective training is built around the specific ways AI is used against people and the ways people misuse AI. The main categories are short.

  • AI-written phishing and business email compromise: Fluent, tailored emails and messages with no obvious errors often impersonating a manager or a supplier.
  • Voice cloning: A familiar voice on a call or in a voice note, built from a short clip of recorded speech, used to push an urgent payment or a password reset.
  • Deepfake video: A live or recorded video that impersonates an executive or a colleague as in the Arup fraud below.
  • Fraud at scale: Fake profiles, forged documents and convincing fake websites, generated quickly to support a scam.
  • Shadow AI and data leakage: Staff entering confidential data into public AI tools or using AI apps the organisation has not approved.
  • Over-trust in AI output: Acting on an AI-generated answer, summary or line of code without checking it.

Every item on that list is a decision made by a person. That is why the training focuses on behaviour rather than on the technology itself.

The Business Cost of an Untrained Workforce

The cost lands in four places. The first is direct financial loss. A single deception can move very large sums, as Arup found when one employee authorised transfers worth about 25.6 million US dollars.

The second is data and intellectual property. Confidential material pasted into a public AI tool can pass out of the company’s control and cannot always be recalled. The third is regulatory exposure. A resulting personal-data breach must be reported to Sweden’s data protection authority, IMY, within 72 hours under the GDPR and NIS2 duties apply with the board held accountable.

The fourth is time and trust. Investigation, recovery and reputational repair are slow and expensive and the money is often gone for good. Arup’s funds were not recovered and the case remained under investigation. Against this, the World Economic Forum’s 2025 outlook found that 42 percent of organisations reported a rise in phishing and social engineering in 2024 while most still had no process to check the AI tools their staff were using.

AI Attacks on Real Organisations

Two cases show the two sides of the risk, an attack from outside and a leak from inside.

The Arup Deepfake Video Call

In January 2024 a finance employee in the Hong Kong office of Arup, the London engineering firm, received a message that appeared to come from the group’s UK-based CFO about a confidential transaction. The employee was doubtful at first.

AI Attacks on Real Organisations

A video call removed the doubt. On the call the CFO and several colleagues looked and sounded exactly as expected and the employee then made 15 transfers totalling about 25.6 million US dollars (200 million Hong Kong dollars) to five Hong Kong accounts. Every other person on the call was an AI-generated deepfake, built from public footage. Hong Kong police reported the case in February 2024 and Arup confirmed it in May 2024.

The control that would have stopped it is the same step that eventually exposed it. Before paying, the employee needed to verify the request through a separate, known channel such as a call back to a confirmed number at head office. Arup’s own CIO described the incident as technology-enhanced social engineering, not a systems breach.

The Samsung Data Leak

In March 2023 Samsung’s semiconductor division allowed engineers to use a public AI chatbot to help with their work. Within about twenty days there were three separate leaks.

One engineer pasted proprietary source code into the tool to fix a bug. Another pasted code from an internal test sequence used to spot defective chips. A third recorded a confidential meeting turned it into text and pasted the transcript in to get notes. None of the three meant any harm. All of them sent confidential data to servers the company did not control.

Samsung’s response was to ban public AI tools and build an internal one. The more durable lesson for most companies is different. Give staff an approved AI tool and a plain rule on what must never be entered, because a ban alone tends to push the same behaviour out of sight.

AI Awareness Training and Compliance

For organisations operating in Sweden and the EU, awareness training is no longer only good practice. Several rules make it a duty.

The EU AI Act sets the most direct requirement. Under Article 4, providers and deployers of AI systems must ensure a sufficient level of AI literacy among staff and anyone operating AI on their behalf. This has applied since 2 February 2025 and national authorities are expected to begin enforcement from 2 August 2026. The Act does not prescribe a set course, so a proportionate, role-based programme is the practical way to comply.

Sweden’s Cybersäkerhetslagen (SFS 2025:1506) transposed the EU NIS2 Directive and has been in force since 15 January 2026. NIS2 lists basic cyber hygiene and security awareness training among its required measures in Article 21 and Article 20 makes the management body responsible for security with personal accountability for board members. See our guide to NIS2 compliance in Sweden.

For financial entities, DORA has applied since 17 January 2025. Article 13(6) makes ICT security awareness programmes and resilience training compulsory for all employees and senior management, at a level matched to each role. In Sweden this is supervised by Finansinspektionen. See our guide to DORA compliance.

Two further rules touch this area. Under GDPR, Article 33, a personal-data breach must be reported to IMY within 72 hours which an AI-enabled attack or an AI data leak can trigger. And ISO 27001 treats staff awareness as part of a working information security management system.

How to Spot an AI-Driven Attack

Some signs still give an AI-driven attack away. Watch for a few patterns.

How to Spot an AI-Driven Attack
  • Urgency and secrecy: A push to act fast and to keep the request confidential.
  • A changed detail or channel: A new bank account, a personal messaging app or a request to skip the normal approval.
  • Requests that bypass process: An instruction to move money, reset access or share data outside the usual steps.
  • Video and audio artefacts: Odd lip-sync, a flat or still face, audio that does not match the mouth or a reluctance to take an unscripted action such as turning the head on camera.
  • Perfect writing, abnormal ask: A fluent, well-targeted message that still asks for something unusual. AI has removed the old spelling and grammar tells.

Here is the hard part. You cannot reliably catch a good deepfake by eye and the quality improves every month. Research backs this up. A 2025 controlled study of more than 19,500 employees found that security awareness training as usually delivered, did not meaningfully reduce how often staff fell for simulated phishing. So the reliable move is to verify the request, not to trust your senses.

How to Build AI Security Awareness That Works

A programme that changes behaviour rests on three things working together, the people, the process and the technology. Treat training as one control among several rather than the whole defence.

Make training continuous and specific. The 2025 study found that a single annual course did little and that susceptibility grew over eight months so replace the yearly module with short, frequent and role-based sessions. Include finance, executives and their assistants who are the usual targets of deepfake fraud, and brief the board since NIS2 holds it accountable.

Set one clear rule and make it normal to follow. Verify any unusual or urgent request for money, credentials or data through a separate, known channel before acting. Require a second authoriser and a call back on a confirmed number for large payments and make reporting a suspicious message quick and free of blame.

Support the rule with controls. Turn on multi-factor authentication everywhere. Give staff a sanctioned AI tool with clear guidance on what must never be entered and add data-loss prevention so confidential material is caught before it leaves. Run realistic simulations that include AI voice and video and use each mistake as a lesson.

None of this depends on anyone spotting a perfect fake. It depends on a habit. When your people verify before they act, the most convincing AI attack still has to get past a phone call it cannot fake.

Myths & Facts

Myth

AI attacks are easy to spot.

Only large companies are targeted.

Our spam filter and antivirus deal with it.

One annual training course keeps us covered.

Banning AI tools removes the data risk.

AI literacy is a future problem.

Fact

A good deepfake fools trained people. In the Arup case the finance worker saw and heard the CFO and several colleagues on a video call, and all of them were AI-generated.

AI lowers the cost and skill needed to attack, so smaller organisations are now in range. The NCSC expects the volume of AI-enabled attacks to keep rising.

A deepfake video call and a fluent AI-written email pass technical filters. The target is a person making a decision rather than a file to scan.

A 2025 controlled study of more than 19,500 employees found annual security awareness training had no significant effect on how often people fell for phishing.

Staff route around bans. Samsung banned public AI tools after leaks, but the durable fix is a sanctioned tool plus a clear rule on what must never be pasted in.

It is a current legal duty. The EU AI Act has required providers and deployers to ensure a sufficient level of AI literacy among staff since 2 February 2025.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. You join a video call. Your CFO and two colleagues are on screen and ask you to make an urgent, confidential transfer today.

    What do you do?

    • Make the transfer, you can see and hear them
    • End the call and verify the request on a known, separate channel
    • Ask the people on the call to confirm they are real
    • Reply to the original message to double-check
  2. You are stuck on a bug and want to paste your company's source code into a public AI chatbot to get a fix.

    What is the safe choice?

    • Paste it in, it saves time
    • Paste only part of the code
    • Use the company-approved AI tool and never paste confidential data into public ones
    • Email the code to your personal account first
  3. A well-written email from a regular supplier asks you to update their bank details for the next invoice.

    How do you respond?

    • Update the details, the email looks legitimate
    • Reply to the email to confirm the change
    • Call the supplier on a number you already had on file
    • Approve it if a colleague also received the email
  4. You get a voice note that sounds like your manager, asking you to buy gift cards for a client right away.

    What is the right move?

    • Buy the gift cards, the voice is unmistakable
    • Call your manager back directly to check
    • Reply to the voice note with a question
    • Buy them but keep the receipts

Knowledge Test

  1. What are the two jobs of AI security awareness training?

    • Buying antivirus and setting passwords
    • Recognising AI-driven attacks and using AI tools safely
    • Writing policies and running audits

    The training teaches staff both to resist AI-enhanced attacks and to use AI tools without exposing data.

  2. How much did Arup lose and how?

    • About 25.6 million US dollars, through a deepfake video call
    • About 1 million US dollars, through a phishing email
    • Nothing, the attack was blocked

    A finance worker made 15 transfers totalling about 25.6 million US dollars after a deepfake video call.

  3. What did the 2025 study of more than 19,500 employees find about annual training?

    • It cut phishing failure in half
    • It had no significant effect on phishing failure rates
    • It only worked for senior staff

    The study found no significant link between recent annual training and how often people failed phishing tests.

  4. Which single habit most reliably stops AI-enabled fraud?

    • Spotting deepfake artefacts by eye
    • Verifying unusual requests through a separate known channel
    • Replying to confirm the request

    Out-of-band verification works even when the fake is convincing, because it does not rely on detection.

  5. Since when has the EU AI Act required a sufficient level of AI literacy among staff?

    • 2 February 2025
    • 1 August 2024
    • 15 January 2026

    Article 4 of the EU AI Act has required AI literacy among staff since 2 February 2025.

  6. What is the safest response to shadow AI?

    • Ban all AI tools and rely on the ban
    • Provide a sanctioned tool with clear rules on what data to keep out
    • Let staff use any tool they prefer

    A ban alone pushes the behaviour out of sight. An approved tool plus clear rules reduces the real risk.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

AI has moved the front line of security to your people. The tools that write fluent phishing, clone a voice and generate a live video of a familiar face are cheap and widely available, and the same tools tempt well-meaning staff to paste confidential data into systems the company does not control.

Awareness is now a legal duty as much as a good practice. The EU AI Act requires AI literacy among staff, and NIS2 and Sweden’s Cybersäkerhetslagen require security awareness training with the board held accountable. eBuilder Security runs employee cybersecurity training built around these AI threats, so your team learns to verify before it acts and to use AI tools without exposing data.

Frequently Asked Questions

What is AI security awareness training?

AI security awareness training teaches employees to recognise and resist attacks that use artificial intelligence and to use AI tools safely at work. It covers deepfakes, AI-written phishing, voice cloning and the risk of leaking data into public AI systems. It is the modern form of security awareness training.

Is AI security awareness training a legal requirement?

In effect, yes for most organisations. The EU AI Act has required a sufficient level of AI literacy among staff since 2 February 2025. NIS2 and Sweden's Cybersäkerhetslagen require security awareness training, and DORA makes it compulsory for financial entities and their senior management.

How is it different from traditional security awareness training?

Traditional training focused on spotting clumsy phishing and choosing strong passwords. AI security awareness training adds two things. It teaches staff to recognise convincing AI-generated attacks that carry no obvious errors and to use AI tools safely so they do not expose confidential data. The threats are harder to see and the tools are new.

Can employees really spot a deepfake?

Not reliably, and this is the honest answer. Deepfake quality is improving faster than the human eye can keep up, and a good fake fooled a finance team at Arup. The dependable defence is verification. Confirm the request through a separate, known channel before you act.

What is shadow AI?

Shadow AI is the use of AI tools that the organisation has not approved or does not know about. Staff paste documents, code or customer data into public chatbots to work faster, and that data can leave the company's control, as it did at Samsung in 2023. A sanctioned tool and clear rules reduce the risk.

How often should staff be trained on AI threats?

Continuously, in short and relevant sessions, rather than once a year. A 2025 controlled study of more than 19,500 employees found no significant link between recent annual training and phishing failure, and susceptibility grew over the eight-month study. Regular, role-based reinforcement works better than a single course.

What should AI security awareness training cover?

It should cover the main AI-enabled attacks, from deepfake video and voice to AI-written phishing and fraud at scale. It should also teach safe AI use, meaning what data must never go into public tools, which tools are approved and how to verify unusual requests. Board members need this training too.

Does AI security awareness training actually reduce risk?

It helps, but only as part of a wider system. Training alone, delivered once a year, has been shown to change behaviour very little. It works when it is continuous and role-based and paired with controls such as multi-factor authentication, payment callbacks and data-loss prevention. People and process together reduce the risk.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.