Group Purchasing
Group Purchasing

You Can’t Spot What Looks Real: Rethinking Security Awareness in the Age of AI, Deepfakes, and Autonomous Attackers

You Can’t Spot What Looks Real: Rethinking Security Awareness in the Age of AI, Deepfakes, and Autonomous Attackers (PDF, 3.18MB)Last updated: 27 Aug, 2026
Presented by:

We’ve made real progress in security awareness, helping people recognize and respond to threats more effectively than ever before. But what happens when the threats no longer look like threats at all? AI-generated phishing is now highly personalized and context-aware. Deepfakes can convincingly replicate trusted voices and identities - at the click of a button on widely available platforms that have no technical barrier to entry. And emerging autonomous agentic AI introduces something fundamentally new: systems that can initiate, sustain, and adapt interactions with humans over time. In this environment, detecting social engineering and scams becomes unreliable, even for experienced professionals. This keynote argues that the future of human risk management is not about improving detection, but about supporting better decisions under uncertainty. Drawing on behavioral science, real-world examples, and observed attack patterns, this session introduces a practical shift for awareness and culture leaders: from detection-based training to decision-focused design. Attendees will leave with clear, actionable ways to evolve their programs, including how to redesign phishing simulations to reflect AI-era realism, introduce effective verification behaviors into workflows, and move beyond click-based metrics toward measures of decision quality. This is not a technical deep dive into AI. It is a practical roadmap for those responsible for influencing behavior at scale, designed to help organizations build resilience in a world where attacks are increasingly convincing, persistent, and human-like.

SANS Security Awareness Summit 2026
You Can’t Spot What Looks Real: Rethinking Security Awareness in the Age of AI, Deepfakes, and Autonomous Attackers