QA survey finds 61% of UK workers have had no training on AI-driven cyber threats
QA's survey of 1,000 UK workers found 61% received no training in the past year on AI-driven cyber threats, while 22% said their employer has no policy covering phishing, deepfake voice scams or AI-generated fake invoices.
The same survey found that 22% of respondents said their organisation has no policies in place covering phishing emails, deepfake voice scams or AI-generated fake invoices. QA said the results point to a gap between how prepared businesses are for AI-driven attacks and how confident staff feel about recognising them.
Generative AI has made it easier for attackers to produce convincing phishing messages, undercutting proofreading, long a standard defence. The technology is also being used to build deepfake video and audio, which attackers deploy on video calls and in voice messages. TechRadar cited the case of Paolo Molesini, former chairman of Fideuram - Intesa Sanpaolo Private Banking, who was reported to have fallen for an AI-powered phishing attack and wired more than $100 million overseas.
Confidence levels vary sharply by age and seniority. Workers aged 18 to 24 are now the least confident group, with 39% saying they worry about being caught out, a reversal of the pre-AI pattern in which younger employees were typically the most confident and older people the most heavily targeted. Among non-management workers, 9% said they were very confident they could spot an AI-generated phishing email, compared with 48% of owners and partners and 33% of board directors.
Training content is also thin where it exists. Of the workers who had received any training, 25% described it as dedicated to AI-driven threats, and 30% said AI threats were covered only as part of general cybersecurity training. That leaves 70% who either received no training at all or encountered AI threats only inside broader material.
"It's clear from the survey data that organisations need to build the foundations on basic AI literacy, so that business leaders and workers feel confident in spotting these threats," said Dr Vicky Crockett, Portfolio Director for AI at QA. "When it comes to training, it's imperative that all job roles can positively spot any AI-driven cyber threats, but when it comes to AI training, there's no one size fits all, so combining baseline AI literacy learning with job specific training is usually the best fit."
Jo Bishenden, Chief Learning Officer at QA, said the findings suggest employers face a skills problem alongside a security problem. "AI is changing the way people work, but many employees are not building the skills they need to understand the risks and opportunities that come with these new technologies," she said.
QA's survey did not examine whether employees are themselves using AI tools to help detect AI-generated attacks. Security professionals have used machine-learning models for years to handle advanced threats at speed.
The findings rest on a single survey of 1,000 people conducted by QA, with TechRadar reporting the results.