Most AI security incidents involve people. A few key habits go a long way.
Protect Data
- Use only approved AI tools for work.
- Don't paste passwords, customer data, or confidential documents into unapproved tools.
- Check what integrations and extensions can access.
Verify Output
- AI output can be wrong or manipulated. Check facts, code and figures before relying on them.
- Be wary if an AI tool suddenly suggests unusual actions, like visiting a link or sharing data — it may have read malicious content.
Recognise AI-Enabled Scams
- Phishing messages are now fluent and personalised.
- Voices and video can be faked.
- Verify urgent requests for payments, credentials or data through a known, separate channel.
Agents and Automation
- Understand what AI agents you use can do on your behalf.
- Review actions before approving them.
- Report strange behaviour.
Report Incidents
If you've shared sensitive data inappropriately or suspect an AI-related scam, report it quickly. Fast reporting limits damage.