AI models breaking out of test labs made headlines this summer. OpenAI, Anthropic and Meta all disclosed cases of their own models breaching outside systems during safety testing. But the attacks doing real damage to UK businesses right now are not rogue AI. They are ordinary criminals using AI tools to run old scams faster and more convincingly. UK Finance’s 2026 Annual Fraud Report puts UK fraud losses at £1.28 billion in 2025, up 4% on the year before, with growth concentrated in scams that manipulate people rather than break into systems.
Criminals are using AI to scale old scams, not invent new ones
Security researchers are consistent on this point. AI has not created new categories of cybercrime. It has made existing techniques – phishing, impersonation, malware – faster to produce and harder to spot. Adam Meyers, head of counter adversary operations at CrowdStrike, has described the change as AI enhancing attack methodology at every stage while a human still runs the operation. That distinction matters for how a business should spend its security budget. The priority is not defending against autonomous AI attackers. It is defending against people who now have AI doing the slow, manual parts of an attack for them.
Four AI-powered attack methods hitting UK businesses right now
Automated reconnaissance on your company and your people
Criminals now use AI to scan a company’s website, social media and public filings in minutes to work out who holds financial authority, who is travelling, and who is likely to approve a payment without checking. This groundwork used to take hours of manual research. AI has made it near instant, which is why targeted scams increasingly reference real projects, real names and real timing.
AI agents running the negotiation in extortion cases
In ransomware and extortion incidents, some criminal groups now use AI agents to handle the back-and-forth negotiation with a victim, mimicking natural conversation while a human oversees the outcome. This lets a small criminal operation run several negotiations at once.
Higher-quality malicious code, produced faster
Attackers used to rely on rough, hand-built scripts. AI now lets less-technical criminals generate working malicious code that would previously have required real development skills and considerably more time.
Cheap, disposable attack infrastructure
Fake login pages and phishing sites used to be costly to rebuild every time one was taken down. AI has made it cheap to regenerate this infrastructure automatically, so takedowns barely slow an active campaign.
Cyber Essentials certification is built around exactly these fundamentals: access control, patching, and malware protection, the basics that blunt AI-enhanced attacks regardless of how convincing they look.
Talk to us about getting your company Cyber Essentials certified.
UK fraud data shows the human factor is the growing risk
Investment fraud losses in the UK rose 40% to £221.5 million in the year covered by UK Finance’s 2026 report, much of it driven by fraudulent adverts and AI-generated content used to make fake schemes look credible. Separately, research from Trustpair and OpinionWay found that 42% of UK companies had experienced at least two successful AI-powered fraud attacks, with 21% of affected businesses reporting average losses of £500,000 per incident.
In Dr Logic’s experience, the businesses hit hardest are not the ones with weak firewalls. They are the ones without a clear, tested process for verifying unusual payment requests.
Invoice and CEO-impersonation scams are the sharpest UK risk right now
AI voice cloning and deepfake video have made business email compromise and CEO-impersonation fraud significantly more convincing than the old badly worded email. A convincing voice note or video call asking for an urgent payment now needs a verification step that does not rely on recognising a voice or a face.
Dr Logic recommends a mandatory callback policy for any payment or credential request that arrives by phone, voice note or video, using a number the business already has on file, never one supplied in the request itself.
What this means for your business
None of this requires a bigger security budget. It requires consistency. Multi-factor authentication across every account, not just the obvious ones. A patching routine that does not lag behind vendor releases. A named, tested process for verifying payment instructions. These are unglamorous controls, but they are what stops an AI-enhanced human attack from working. The businesses currently getting caught out are rarely missing exotic technology. They are missing consistent basics.



















































