13 October 2025 • Cyber security
AI comes with about just as much opportunities as risks. The more it developers, the more it is misused for cyberattacks. That’s why regulators are already responding with strict rules and organizations are turning to AI awareness training for their employees.
In this article, we’ll explain how AI creates new threats, why training is needed, and how you can implement effective training.
AI introduces new risks for organizations
As if we didn’t already have enough threats to deal with, AI technology has transformed the threat landscape as we knew it. Attackers can leverage AI to scale and refine their attacks, while untrained employees may inadvertently expose sensitive data.
As Jeff Crume from IBM says in the video below, it seems like we can’t have nice things like AI.
Here are three key AI-driven risks.
AI-powered social engineering and phishing
Traditional phishing emails were often easy to spot due to poor language or lack of personalization. AI now enables cybercriminals to generate convincing, personalized messages at scale. Think emails or chats that mimic a colleague’s or customer’s tone of voice perfectly.
So how does this work? Think of an AI model scraping all your social media posts to figure out your writing style, personality, hobbies, and so on. With this information, writing an email that looks like it came from you becomes a lot easier.
Finding vulnerabilities with help from ChatGPT
Tasks that previously required skilled hackers, like coding malware or finding vulnerabilities, can now (partially) be handled by AI tools. In 2024, OpenAI confirmed that ChatGPT had been misused to develop malware and evade detection. This means attacks can be executed faster and at greater scale, even by less skilled criminals. No need to spend days or weeks to write malware, when AI can help you do it in a matter of hours.
Deepfakes and AI-generated disinformation
One of the most dangerous AI applications is the deepfake: hyper-realistic audio or video fabrications of someone’s face or voice. Deepfakes can be used to impersonate a CEO or client and commit fraud. In 2024, scammers tried to impersonate the CEO of WPP using a deepfake in a Teams call. The incident showed how convincing deepfake scams can be and the damage they can cause.
These attacks also happen in private settings. Increasingly, cybercriminals are using social media content to create deepfakes of people’s parents or children, tricking victims into sending them money. Just imagine: you get a call, and you hear your daughter’s voice, panicked, asking for help. Would you hesitate? Most people wouldn’t. We’re simply not used to questioning whether a familiar face—or voice—could be fake.
The importance of AI awareness training
Employees often get called the weakest link in a cybersecurity strategy. That’s why many companies train their employees in the more traditional security awareness topics. Such as privacy, passwords, and of course phishing.
But in many of those somewhat outdated training programs, AI is not accounted for.
AI security awareness training zooms in particularly on AI threats, to make sure your employees can recognize and report AI threats once they encounter them. And this is key, because most of us overestimate how well we are able to recognize threats. We don’t think we’re susceptible to phishing until the IT manager decides to launch a phishing campaign and we fill in our bank details.
Most security awareness training solutions offer outdated training content, and it’s key to make sure you’re not offering that same outdated content to your employees. Because cybercriminals are studying new tactics every day.
Why AI compliance training is needed
With all the risks that come with AI, regulators have started to introduce tight AI-related rules. This forces organizations that want to use AI to ensure safe, transparent, and responsible practices. That’s why they turn to AI compliance training.
The most significant driver is the EU AI Act, Europe’s new AI regulation. The Act takes a risk-based approach and imposes various obligations. Article 4 requires providers and users of AI systems to ensure sufficient AI literacy among their staff. In other words: train your employees to understand AI risks, opportunities, and responsibilities. This “AI literacy” requirement comes into effect from February 2025, ahead of the full rollout of the AI Act in 2026. The clock is ticking to build internal AI know-how.
AI compliance training familiarizes staff (and leadership) with essential topics like:
- Risk categories (e.g., identifying if an AI system is “high-risk”)
- Transparency requirements (informing users when they’re interacting with AI)
- Privacy (GDPR) alignment (and how to treat personal data when it comes to AI)
- Safety measures (e.g., human oversight, audit trails)
The AI Act comes with some heavy sanctions if organizations do not comply, up to 7% of global turn over. These fines are higher than current GDPR sanctions, which caused organizations to invest a lot into their privacy infrastructure in the past.
Practical tips for implementing AI awareness and compliance training
- Map AI risks and set clear policies: Identify where and how your organization uses AI and what risks are involved. Define internal rules (e.g., approved AI tools).
- Tailor by role: Customize training for different audiences: deep dives for developers, practical detection tips for general staff, and governance focus for leadership.
- Make it continuous and engaging: Use gamification, simulations, and regular microlearning to keep AI awareness fresh and engaging.
- Test and refine: Run phishing tests with AI elements, collect feedback, and update the training regularly.
- Document everything: Keep records of training completion and policies to demonstrate compliance if audited.
Last but not least, make sure the training program you run includes an AI module. Guardey has this and enables you to do all of the above. With short, weekly challenges, users learn about the latest AI threats, such as deepfakes.
Conclusion
AI is no longer a future concern—it’s today’s reality. Whether through advanced phishing, malware, or deepfakes, AI-driven attacks are here. Regulators are also raising the bar, with the EU AI Act setting new compliance standards.
If you’re looking to combat AI threats and comply with the EU AI Act, consider trying out Guardey. During a 14-day free trial, you can try out the gamified training program together with your colleagues. You can also contact us for an in-depth demo.