Artificial Intelligence vs Artificial Intelligence: How AI Is Fighting
Cybercrime
Artificial intelligence is rapidly changing the cybercrime
landscape. The same technology that helps organisations automate processes, analyse data, and improve decision-making is also giving cybercriminals new ways to operate faster, smarter, and at greater scale.
AI can help criminals craft convincing phishing messages,
impersonate trusted individuals, automate attacks, and identify potential
vulnerabilities. In Africa, the scale of this shift is already significant:
INTERPOL reports that AI is enabling 55% of reported cybercrimes across the
continent
Yet AI is also becoming one of cybersecurity’s strongest
defensive tools—detecting unusual behaviour, identifying threats, and enabling
faster responses.
For African organisations, this creates a new reality: AI is
no longer simply a technology to adopt. It is becoming both a weapon and a
defence. The emerging contest is increasingly AI versus AI.
How Cybercriminals Are Weaponizing AI
Artificial intelligence has lowered
the barriers to sophisticated cybercrime. Tasks that require technical
expertise, time and resources can increasingly be automated or enhanced using
readily available AI tools.
Generative AI can produce
convincing phishing emails, imitate writing styles, and create fraudulent
content at scale, and speed. AI-generated voices, images, and video are also strengthening
impersonation and social-engineering attacks, making legitimate communication
increasingly difficult to distinguish from deception.
Across Africa, INTERPOL has
identified cybercriminals integrating AI-generated text, audio, and video into
phishing campaigns, including personalized communications designed to imitate
specific individuals or organisations
Beyond content creation, criminals
can use AI to analyse information, identify potential targets, automate reconnaissance,
and adapt attacks more rapidly.
The result is not necessarily an
entirely new form of cybercrime, but a significant increase in its speed, scale,
and sophistication. For organisations, this creates a difficult imbalance:
attackers may need only one convincing message or overlooked vulnerability to
succeed, while defenders must continuously protect against thousands of
potential threats.
How AI is Fighting Back
The same capabilities that make AI
attractive to cybercriminals are strengthening cyber defence. Traditional
security tools often depend on predefined rules and known indicators of
compromise. AI-driven systems can go further by analysing vast volumes of
activity and identifying patterns that may signal a threat before it becomes
obvious.
Machine learning can establish
normal patterns of user, device and network behaviour and flag anomalies—such
as unusual login activity, abnormal transactions, or unexpected access to
sensitive information. AI can also support fraud detection, identify insider threats,
and reduce the volume of false alerts requiring investigation
The advantage is speed. AI-enabled
security systems can analyse threats, prioritise higher-risk incidents and
support automated responses, including containment actions and
incident-response processes. NIST specifically identifies advanced threat
detection and automated incident response among the opportunities for
AI-enabled cyber defence
AI does not, however, replace
skilled cybersecurity professionals. Its greatest defensive value lies in
combining machine speed and analytical capacity with human expertise, oversight,
and judgement. The importance of these defensive capabilities becomes
particularly clear when viewed against South Africa’s evolving fraud landscape.
The South African Context: When AI Meets Social Engineering
South Africa’s elevated levels of
digital banking and widespread use of social media and messaging platforms
create fertile ground for increasingly sophisticated social-engineering
attacks. Criminals no longer need to rely on poorly written phishing emails.
Generative AI can help produce convincing messages, replicate voices, and
create realistic images or video capable of impersonating trusted individuals
and organisations.
The scale of the underlying fraud
threat is significant. In 2024, SABRIC recorded 97,975 digital banking fraud
incidents, an 86% increase from the previous year, while gross losses
increased by 74% to approximately R1.9 billion. SABRIC has also
identified AI-driven scams, phishing and deepfake-enabled impersonation among
the evolving threats facing the banking environment
The South African context
illustrates a crucial point: AI does not need to create an entirely new
crime to increase risk. Its power lies in making familiar fraud techniques more
believable, scalable, and difficult to detect.
The AI-versus-AI Arms Race
The emerging cyber landscape is
becoming a contest of speed, adaptation, and intelligence. The World Economic
Forum reports that 94% of surveyed cyber leaders expect AI to be the most
significant driver of change in cybersecurity in 2026
Attackers can use AI to increase
the scale, speed, and sophistication of attacks, while defenders are harnessing
it to strengthen detection, accelerate incident response and automate
high-volume analytical tasks. The result is an intensifying technological
contest in which both sides are continuously adapting.
However, AI introduces risks of its
own. Poorly implemented systems can create vulnerabilities through
misconfiguration, overreliance on automation and susceptibility to adversarial
manipulation. Cybercriminals may also deliberately attempt to deceive or
exploit AI-based security systems.
The advantage will therefore not
necessarily belong to the organisation with the most advanced AI. It will
belong to those that combine technology with strong governance, quality
data, skilled people, and effective human oversight.
Building an AI-Ready Cyber Defence
As AI becomes embedded in both
attack and defence, organisations need to rethink cybersecurity beyond
traditional controls. Investing in AI-enabled security tools is important, but
technology alone will not provide resilience.
Effective defence requires strong
governance over how AI is selected, deployed, and monitored. Organisations
should establish clear accountability; understand the data underpinning their
systems and regularly evaluate whether controls remain effective as threats
evolve. Human oversight must remain integral to AI-driven decision-making
Employees are equally important. As
AI-generated phishing, deepfakes and impersonation become more convincing,
verification procedures should be strengthened—particularly for payments,
changes to banking details and requests involving sensitive information.
Ultimately, AI should strengthen
rather than replace existing cybersecurity foundations. Technology,
governance, and human judgement must work together if organisations are to
remain resilient in an AI-enabled threat environment.
D-finitive Insights
Artificial intelligence is changing
the balance of cyber risk. The same capabilities that allow criminals to
automate, personalise, and scale attacks are giving organisations new ways to
detect, analyse, and respond to them.
The challenge is therefore not
simply adopting AI but using it more effectively and responsibly than those
seeking to exploit it.
For African organisations, this
means strengthening cyber controls, preparing employees for increasingly
convincing AI-enabled deception, and embedding governance and human oversight
into the use of AI.
In the emerging AI-versus-AI
environment, resilience will depend not on technology alone, but on how
intelligently organisations use it.
Delivering Clarity. Protecting
Integrity. Driving Accountability.
