{"id":104968,"date":"2026-07-14T06:32:12","date_gmt":"2026-07-14T06:32:12","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/104968\/"},"modified":"2026-07-14T06:32:12","modified_gmt":"2026-07-14T06:32:12","slug":"the-best-defense-against-ai-attacks-turns-out-to-be-a-skeptical-human","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/104968\/","title":{"rendered":"The best defense against AI attacks turns out to be a skeptical human"},"content":{"rendered":"<p>Analysts across the security industry now run generative AI through their daily work, from log triage to incident write-ups. Active use in cybersecurity strategy reached 78% of practitioners in 2026, up from half the field a year earlier. The 2026 SANS AI Survey, drawn from 536 IT and security professionals, describes what that commitment costs to keep.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/ai_criminal_mastermind.webp\" class=\"aligncenter\" alt=\"AI attacks\" title=\"AI\"\/> <\/p>\n<p>Reliability trailed adoption over the year. Sixty-three percent of practitioners report significant shortcomings when AI detects or responds to threats, well above the share who said so a year earlier. The failures cluster around false positives, trouble spotting new threats, and confident output that turns out wrong. Teams <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/06\/03\/research-ai-agent-security-capability\/\" rel=\"nofollow noopener\" target=\"_blank\">running AI in production<\/a> describe this as the routine experience.<\/p>\n<p>Trust varies by task, and the survey maps where practitioners draw the line. \u201cOur data shows practitioners are comfortable letting AI classify threats or prioritize vulnerabilities, and far less comfortable letting it confirm a true positive or judge behavioral anomalies,\u201d <a href=\"https:\/\/www.linkedin.com\/in\/bromiley\/\" target=\"_blank\" rel=\"nofollow noopener\">Matt Bromiley<\/a>, a SANS certified instructor and incident responder, told Help Net Security. \u201cThese <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/03\/09\/harvard-business-review-ai-workplace-fatigue-report\/\" rel=\"nofollow noopener\" target=\"_blank\">tools<\/a> track that they are good at structured problems and weak at novel, context-dependent calls. You build the instinct by learning a tool\u2019s failure profile and verifying in proportion to what being wrong costs you.\u201d<\/p>\n<p>One survey respondent described treating AI like a digital intern and checking its work. Bromiley put himself in the same camp. \u201cI cannot agree more with this: \u2018measure twice, cut once.\u2019 Unfortunately, most teams aren\u2019t instrumented to build that instinct,\u201d he said.<\/p>\n<p>The instinct can be trained, up to a point. \u201cAs an instructor, I can attest that the classroom does more than people give it credit for,\u201d Bromiley said. \u201cYou can teach failure modes, instrumentation, what to verify before acting, and how to run a system in parallel long enough to see where it drifts. What you can\u2019t lecture into someone is calibration, meaning how much doubt a given output has earned. Good training just compresses those reps into a place where being wrong is cheap.\u201d<\/p>\n<p>The gap he wants to close is measurable. Two-thirds of practitioners have been misdirected by AI guidance at least once in the past year, and 9% more than twenty times.<\/p>\n<p>The offensive side puts a deadline on that judgment. Bromiley described an incident where attacker speed drove the outcome. \u201cI worked at one where the tempo was what caught us off guard,\u201d he said. The intrusion began as a <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/04\/22\/financial-sector-cyber-threats-report\/\" rel=\"nofollow noopener\" target=\"_blank\">supply chain compromise<\/a> through a malicious package, which set the foothold inside a trusted software environment. From there the adversary moved through internal reconnaissance to lateral movement within minutes, deploying scripts in quick succession. \u201cThe pace felt fast \u2013 the adversary was also bringing in scripts that were clearly commented and had good step-through instructions, matching the hallmark traits of a \u2018friendly AI-developed script\u2019,\u201d Bromiley said.<\/p>\n<p>\u201cI\u2019d be careful about the attribution. We assessed those scripts as likely AI-generated based on their structure and the speed of iteration, not because we recovered proof,\u201d he said. His case sits in the suspected column of the survey\u2019s numbers. \u201cOf the 78% of organizations reporting AI-enabled attacks, 45% confirmed it and 33% suspected. My case belongs in the second group,\u201d he said.<\/p>\n<p>The timing math is what he wants defenders to sit with. \u201cWhat changed was cadence. Recon-to-lateral-movement usually buys defenders time because it\u2019s slow and manual. Here, it bought very little time,\u201d Bromiley said. \u201cDetection thresholds and on-call rotations assume some attacker dwell, and that assumption is what is compressed.\u201d Reconnaissance to lateral movement normally runs slow and manual, and the delay is the window a team catches up in. Take it away, and the margin goes with it.<\/p>\n<p>Looking back, Bromiley listed what the team wanted before the first alert fired. \u201cThey wanted an accurate inventory of their software supply chain, egress logging that made the recon stage visible in real time, and service accounts scoped so the foothold couldn\u2019t reach as far as it had, which aligns with survey results,\u201d he said. \u201cPractitioners rank behavioral detection, user awareness training, human analyst review, and zero trust as most effective against AI-enabled threats. AI-specific controls rank last. Behavioral detection works because it watches what an attacker does, not what the script wrote. Speed doesn\u2019t require a novel countermeasure; rather, it removes the slack that lets teams improvise past a missing one.\u201d<\/p>\n<p>The controls he named line up with where the broader survey lands. Defenders point mostly at behavioral and human-centered controls, and the specialized AI tooling ranks at the bottom of the list. A trained, skeptical human sits at the center of the durable defenses, which fits the instinct problem Bromiley keeps returning to.<\/p>\n<p>The next 12 months will test whether organizations can close the readiness gap against the deployment they have already committed to. The survey points to validation that tracks precision and recall, governance moved into the controls analysts touch every day, and workforce development treated as an immediate operational need. Bromiley\u2019s case makes the reason concrete. The tempo of an AI-assisted intrusion consumes the exact time defenders have been building their instincts to use.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/divider.gif\" class=\"aligncenter\"\/><\/p>\n<p>Guide: <a href=\"https:\/\/helpnet.short.gy\/LNVel6\" target=\"_blank\" rel=\"nofollow noopener\">What automated pentesting alone cannot see<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Analysts across the security industry now run generative AI through their daily work, from log triage to incident&hellip;\n","protected":false},"author":2,"featured_media":104969,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,25,313,223,30,50445,21768],"class_list":["post-104968","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-artificial-intelligence","tag-cybersecurity","tag-generative-ai","tag-report","tag-sans","tag-threats"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/104968","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=104968"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/104968\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/104969"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=104968"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=104968"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=104968"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}