Image Source: Getty Images
On 25 May 2026, India’s Computer Emergency Response Team (CERT-In) released an advisory, the Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure. CERT-In describes it as guidance rather than a mandate, yet its content is telling. Alongside routine recommendations on patching and monitoring, it devotes a section to deepfake-enabled impersonation, instructing organisations to build verification procedures for video calls, much like they would for firewalls. That a technical agency now writes protocols for spotting a fabricated colleague says where the threat has moved.
AI literacy must now be treated as a national cybersecurity capability, because the effectiveness of technical safeguards increasingly depends on whether people can recognise and resist AI-enabled deception.
A decade ago, impersonating a bank official over the phone took a skilled fraudster and real preparation. However, Generative AI can now clone a voice from a few seconds of audio and produce a passable video likeness within minutes, at falling cost. Traditional phishing relied on clumsy language and implausible claims, weaknesses that alert users could usually spot. AI-generated deception instead exploits fluency, familiarity, and urgency, the very qualities that make communication feel authentic. As synthetic content becomes harder to distinguish from the genuine article, cybersecurity increasingly depends not only on systems and networks but also on protecting human judgment. The core argument is that AI literacy must now be treated as a national cybersecurity capability, because the effectiveness of technical safeguards increasingly depends on whether people can recognise and resist AI-enabled deception.
The Changing Cybersecurity Landscape
Cybersecurity has historically meant defending systems, firewalls against intrusion, and patches against known flaws. Attackers found gaps in code, and defenders closed them. Generative AI does not end that contest, but opens a second, harder one alongside it: deceiving the person operating the system rather than attacking the system itself.
Microsoft’s 2025 Digital Defence Report recorded a 54 percent click-through rate for AI-generated phishing messages against 12 percent for manually written ones. It also recorded a 195 percent global rise in AI-generated identity documents used to defeat banks’ selfie checks and liveness tests. The Stanford AI Index 2026 counted 362 publicly documented AI-related incidents in 2025, up from 233 the year before, including a rise in AI-powered romance scams built on deepfakes. Voice cloning, once a research curiosity, now sustains a genuine fraud economy targeting individuals and call centres alike.
The case at Arup, a British multinational design and engineering company, remains the clearest illustration. In January 2024, an employee at the firm’s Hong Kong office received an email purporting to be from the company’s chief financial officer (CFO), requesting confidential transactions. Suspicious, he asked for a video call to confirm — the very instinct the attackers had planned for. Every other participant, including the CFO, was an AI-generated construction built from footage of past meetings. Reassured, he authorised fifteen transfers totalling roughly US$25.6 million. The fraud surfaced only when the employee contacted headquarters. Nothing was hacked, and no credentials were stolen. The verification step worked exactly as designed. It simply verified something false.
Cognitive Cybersecurity
This calls for a different vocabulary: cognitive cybersecurity, the practice of protecting individuals and institutions against AI-enabled manipulation that targets how people interpret and act on information, rather than exploiting flaws in software. A conventional security audit asks whether a system was breached. A cognitive-security lens asks whether a person was manoeuvred into acting against their own interest — an outcome that, as this case shows, can occur without any breach at all.
The stakes extend beyond fraud. Because financial deception and information manipulation share a common technical base, the same capabilities can just as easily produce a fabricated statement from a public official, or a synthetic clip resembling unrest at a polling station.
For most of the last century, a recorded voice or face was treated as reliable unless proven otherwise. That default no longer holds, and institutions built around it, from courts to finance departments, have yet to adjust.
Generative AI fundamentally changes the economics of deception. Social engineering was once a craft business, requiring a skilled operator and a chosen target. Generative AI turns it into something closer to manufacturing, where a single operator can run hundreds of fluent, personalised attempts at once, each cheap to produce. It also inverts a longstanding default: for most of the last century, a recorded voice or face was treated as reliable unless proven otherwise. That default no longer holds, and institutions built around it, from courts to finance departments, have yet to adjust.
None of this renders firewalls, encryption, or patching obsolete. They remain necessary, but no longer sufficient. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 87 percent of surveyed leaders named AI-related vulnerabilities the fastest-growing cyber risk of the past year, and 73 percent had personally experienced, or knew someone affected by, cyber-enabled fraud in 2025.
Where Technical Fixes Fall Short
A fair objection follows: if watermarking, provenance standards, and detection tools are improving, is a literacy-based response still necessary? The European Union (EU) offers a useful test. Article 50 of the EU AI Act, taking effect in August 2026, requires providers of generative AI systems to mark synthetic content in machine-readable form and obliges deployers of deepfakes to disclose that the content is artificially generated.
That is a meaningful step, but its reach is limited. Labelling rules bind providers within EU jurisdiction, but carry no force against a fraudulent operation run from outside it. Detection tools, meanwhile, chase generation models that improve every few months — a race the defender starts behind. Provenance systems work best where content circulates widely enough to be checked at leisure, such as on social media or in news footage, but fare poorly in a live call demanding an instant answer — exactly the kind of setting seen in the Arup case. That gap is where a trained human response has to carry weight technology cannot yet bear.
Why India is Especially Exposed
India’s vulnerability to AI-enabled deception owes less to any single weakness than to the scale and speed of its digital transformation. The Unified Payments Interface (UPI) processed 185.8 billion transactions in FY 2024-25, up 41.7 percent on the previous year, and now accounts for over four-fifths of the country’s digital payment volume. Every additional transaction widens the opening for fraud: the RBI’s Annual Report for 2024-25 recorded 13,516 digital payment fraud cases, 56.5 percent of all reported banking frauds, with losses of INR 520 crore.
India’s vulnerability to AI-enabled deception owes less to any single weakness than to the scale and speed of its digital transformation.
Much of this growth comes from first-time digital users with little opportunity to learn how to tell genuine communication from a fraudulent copy. India’s linguistic diversity compounds the problem, since generative tools can produce fluent phishing content in regional languages at a scale that manual translation never permitted. CERT-In handled more than 29.44 lakh cyber incidents in 2025, issuing 1,530 alerts and 390 vulnerability notes, and naming AI-driven reconnaissance and deepfake-enabled fraud among the primary risks facing Indian users. This reflects not unusual credulity, but digitalisation outpacing the habits that normally accompany it.
AI Literacy as National Cybersecurity Infrastructure
Closing that gap means treating AI literacy as part of the country’s cybersecurity capability, not an education-sector project running alongside it. The IndiaAI Mission, approved by the Cabinet in March 2024 with an outlay exceeding INR 10,371.92 crore, has begun weaving AI literacy into school curricula for classes six to twelve through the Skilling for AI Readiness (SOAR) programme, which had enrolled 1.34 lakh students and teachers as of December 2025. Alongside this, the government’s “YUVA AI for All” course, launched in November 2025, aims to train 10 million citizens in foundational AI skills. These efforts need to extend to AI-enabled deception, not just the productive use of AI tools.
That extension has to be specific about who it reaches and what it teaches. The people most exposed are rarely those already comfortable online: first-time digital users and older citizens with limited exposure to how convincing a cloned voice or face has become, small traders and gig workers who transact mainly by phone, and speakers of regional languages that mainstream awareness campaigns often bypass. For this audience, useful AI literacy has less to do with understanding how models work and more to do with a small set of practised habits: treating urgency and secrecy as warning signs in themselves, confirming any unusual or high-value request through a second, independently initiated channel rather than the one it arrived on, and reporting a suspected fake through the national 1930 cyber-fraud helpline before money moves rather than after.
Training within banks, telecom operators, and government departments should move beyond generic warnings toward guidance on verifying voice calls and urgent financial requests, an approach CERT-In already recommends. Coordination is necessary, since a scam typically opens with a phone call and closes with a bank transfer elsewhere. The Reserve Bank of India’s (RBI) MuleHunter.AI initiative, and its proposed .bank.in and .fin.in domains, show how verification infrastructure and public awareness can reinforce one another. Any serious programme must also reach beyond metropolitan, English-speaking audiences, since those most exposed are usually least served by existing campaigns.
Governments that treat deception detection as core state capacity, not a line item bolted onto existing budgets, will be better placed for what comes next.
Conclusion
Cybersecurity in the generative AI era cannot remain confined to the defence of servers and networks. It has to extend to the moment a person decides whether a voice, a face, or a request on a screen is what it claims to be. The Arup case shows what that moment looks like inside a boardroom. India’s fraud statistics show it recurring across millions of transactions. Framing AI literacy as a national security capability, rather than an educational add-on, more accurately describes what is needed: institutional defence for a threat that bypasses the technical layer altogether. Governments that treat deception detection as core state capacity, not a line item bolted onto existing budgets, will be better placed for what comes next.
Sairah Zahoor is a Research Intern at the Observer Research Foundation.
The views expressed above belong to the author(s). ORF research and analyses now available on Telegram! Click here to access our curated content — blogs, longforms and interviews.
