The median attacker now uses AI across 15 documented techniques, scaling known methods rather than inventing new ones. (AI-Generated Image)
AI is making cyberattacks faster, fraud more convincing and digital identities harder to trust. Major Vineet Kumar, Founder and Global President of CyberPeace, argues that the answer is not to expect flawless behaviour from users, but to build systems that anticipate human error and protect people from it.
As AI gets smarter, are humans becoming the weaker link in cybersecurity?
Humans are not becoming weaker, only more targeted. As we see in Verizon’s 2026 breach report, the human element was present in 62% of breaches, up from 60% the previous year. The median attacker now uses AI across 15 documented techniques, scaling known methods rather than inventing new ones. Ransomware and zero-day exploits remain among the most damaging of these techniques, alongside voice phishing and SMS scams, which are rising too. In my experience, a person becomes the weak link only when systems demand perfect behaviour every day. The WEF’s 2026 survey found 87% of respondents saw AI-related vulnerabilities as the fastest-growing risk. Good design expects human error and limits its damage.
Can cyber peace exist without global rules on cyber warfare?
It cannot last, and, as we see, the gap is enforcement, not rules. States affirmed in 2013 that international law applies to cyberspace, and agreed 11 voluntary norms in 2015 (United Nations Group of Governmental Experts, UN GGE). At the first substantive session of the new UN Global Mechanism in July 2026, states remained split between those who see existing law as sufficient and a smaller bloc seeking binding rules. The Hanoi Cybercrime Convention will enter into force only after 40 states become Parties. Peace needs accountability: attribution, consequences, and clear protection for CII (critical information infrastructure) and elections, because civilians pay when rules stay vague, and digital empowerment cannot take root without that protection. Efforts like the ICRC’s Digital Emblem, extending Geneva Convention protections to hospitals and humanitarian infrastructure in cyberspace, show how international law is beginning to catch up with cyber warfare.

Major Vineet Kumar, Founder and Global President of CyberPeace.

What is the biggest cybersecurity threat people still underestimate?

It is fraud, which we underestimate by calling it a nuisance. As we see, the WEF’s 2026 outlook says fraud has overtaken ransomware, with 73% of respondents directly affected in 2025. Indians reportedly lost ₹22,495 crore to cyber fraud in 2025, with investment scams accounting for about 75%. CSAM is another underestimated threat, often treated as separate from mainstream cybercrime even as offenders use the same platforms and payment rails. CyberPeace’s analysis of MHA data shows that of the ₹8,690 crore frozen or blocked as of January 2026, only about ₹167 crore has been returned to victims. Digital arrest has no legal recognition in India, yet incidents rose from 39,925 in 2022 to 123,672 in 2024, because fear outruns legal awareness.
Has AI changed the meaning of trust in the digital world?
As we see, a familiar voice or face is no longer proof. A meta-analysis of 56 studies puts average human accuracy at spotting deepfakes at about 55%, with a confidence interval crossing 50%. The FBI’s first standalone AI-fraud category logged $893.3 million in adjusted 2025 losses across 22,364 complaints. India’s IT Amendment Rules 2026 cut the takedown deadline for flagged unlawful content to 3 hours and require AI-generated media to carry labels and provenance metadata. Law helps, but trust must now move from how something looks to how it is verified, through call-backs and independent checks.
Can technology be made truly inclusive without compromising security?
It must be, because as we see, exclusion itself creates risk. Inclusion is part of security, not a trade-off against it. The ITU estimates 2.2 billion people remain offline, and newer users with thin digital skills are easy targets. Verizon found engagement rates for mobile phishing simulations were 40% higher than for email ones, and for many Indians the phone is the only computer. Security that demands expertise fails these users first. We should put the friction on the attacker instead: safe defaults, local languages, simple verification, and practical skills training. Community-level initiatives such as the CyberPeace First Responder Programme, which trains local volunteers to deliver first-line cyber-safety support, show how this kind of inclusion can be built at scale.
After nearly three decades in cyber peacebuilding, what still keeps you awake at night?
What keeps me awake is the people inside scam compounds. The UN human rights office says more than 300,000 people are trapped in scam centres, forced to defraud strangers under threat of violence. Government data shows 6,998 Indians rescued since 2022, from Cambodia, Laos and Myanmar. Many were lured by fake job offers, and survivors are often misidentified as criminals. I fear AI will make this model more profitable faster than we build protection. After three decades, every scam still has a human being at both ends. This is not a fight any one institution can win alone. Organisations like ours, working together with government, law enforcement, the UN and industry, are already building the response, from I4C's registry of suspected cybercriminal identifiers, built with banks and the 1930 helpline for reporting fraud to UNODC's #TrappedInScamCrime awareness campaign on fake job offers, and that partnership is our best hope of protecting people before they are trapped.
Tags: