- 442% rise in AI-powered vishing attacks (2024)
- Malicious email attack every 19 seconds (2025)
- Non-Human Identities outnumber human employees by 144-to-1
Experts agree that securing the AI-augmented workforce requires a fundamental shift from traditional cybersecurity models to dynamic, AI-native defenses and comprehensive governance frameworks for both human and non-human identities.
The Ghost in the Machine: Securing the New AI-Augmented Workforce
TAMPA, FL – June 30, 2026 – The definition of a corporate workforce is undergoing a seismic shift. It's no longer just a collection of human employees. It is now a hybrid entity, a dynamic mix of people and the increasingly autonomous AI agents they use. This evolution, while promising unprecedented productivity, has opened a new and perilous front in the cybersecurity war—one that traditional defenses are ill-equipped to handle. Recognizing this paradigm shift, security awareness leader KnowBe4 has announced a Workforce Security Summit, aiming to pull back the curtain on a challenge that extends far beyond phishing emails into the very nature of digital identity and trust.
The New Arms Race: Fighting AI with AI
The threat landscape has been supercharged by generative AI. Cybercriminals are weaponizing artificial intelligence to execute attacks with a speed, scale, and sophistication that is rapidly outpacing human-led defenses. Industry threat reports paint a stark picture: AI-powered vishing (voice phishing) attacks, fueled by voice-cloning technology that can create a realistic replica from a few seconds of audio, have skyrocketed. One recent analysis noted a staggering 442% rise in such attacks in 2024, a trend that has only accelerated.
This isn't theoretical. High-profile breaches, like the one that hit Charter Communications in April 2026, were initiated by vishing scams that secured millions of records. Similarly, AI-generated phishing emails, now flawlessly crafted and hyper-personalized, are flooding inboxes at a blistering pace. Cybersecurity firm Cofense reported a malicious email attack occurring every 19 seconds in 2025, more than doubling the rate from the previous year. The result is a dramatic reduction in "breakout time"—the critical window from initial breach to an attacker's lateral movement within a network. According to CrowdStrike, this window shrank to an average of just 29 minutes in 2025, giving security teams precious little time to react.
In response, the cybersecurity industry is fighting fire with fire. KnowBe4's summit plans to highlight strategies for an "AI-Native Security Defense," using adaptive training and attack simulations that mirror these new threats. The move reflects a broader industry consensus: static, rules-based security is obsolete. The future of defense lies in dynamic, AI-powered systems that can analyze behavior, detect anomalies, and respond at machine speed.
Beyond 'Shadow IT': The Rise of 'Shadow AI'
While external threats are escalating, an equally potent risk is emerging from within enterprise walls: 'Shadow AI.' This term describes the unsanctioned use of AI tools by employees, a modern-day successor to the 'Shadow IT' problem of the last decade. When an employee pastes sensitive strategic data into a public large language model (LLM) to summarize a report or uses an unvetted AI-powered browser extension, they create a blind spot for security teams and a potential vector for catastrophic data leakage.
KnowBe4's CEO, Bryan Palma, acknowledged this fundamental shift in the company's announcement. "The workforce has changed fundamentally, and security strategies must catch up," he stated, pointing to the need to secure a workforce comprised of both human employees and AI agents. This is where the concept of 'AI agent security' comes into focus.
These agents, whether simple scripts or complex LLM-powered bots, create a proliferation of Non-Human Identities (NHIs). Recent research reveals a startling imbalance: in many large enterprises, NHIs now outnumber human employee identities by a ratio of 144-to-1. Each one represents a potential attack surface. Securing them requires a new governance model that can monitor agent behavior, manage their access privileges, and detect anomalies that could signal a compromise. To this end, KnowBe4 plans to demo its 'Agent Risk Manager,' a tool designed to provide visibility into this shadow realm and recommend risk-reduction actions in real time.
Redefining Digital Workforce Security
The emergence of the hybrid human-AI workforce is forcing a re-evaluation of the entire security awareness and training market. For years, the primary goal was to fortify the "human firewall." While that remains critical, it's no longer sufficient. Companies like KnowBe4, traditionally competing with firms such as Proofpoint and Cofense on the quality of their phishing simulations and training content, are now pivoting to address this new, broader challenge.
The differentiation is subtle but profound. While competitors are also integrating AI to create more sophisticated phishing tests and personalized training, KnowBe4 is attempting to frame the problem around the governance of the AI agents themselves. This positions the company not just as a training provider, but as a platform for managing the operational risk of AI adoption.
This strategic pivot aligns with a major investment trend in the cybersecurity sector. Venture capital and M&A activity have shifted decisively towards companies that offer AI-native security. The market is betting that the most valuable solutions will be those that can secure the entire AI-era enterprise—from the cloud and data to the identities of both humans and their digital counterparts. For CISOs and IT leaders, the challenge is no longer just about preventing clicks on malicious links; it's about establishing a comprehensive governance framework for every identity, human or not, operating within their environment.
The Path Forward: From Awareness to AI Governance
As organizations race to harness the power of AI, they must simultaneously build the guardrails to manage its risks. The upcoming summit promises a first look at KnowBe4's roadmap, including AI-driven content advancements and innovations in human and agent risk management. This reflects an industry-wide imperative to move beyond simple awareness and toward integrated AI governance.
For business leaders, this means fostering a culture of AI literacy while implementing technical controls that provide visibility and oversight. It requires asking new questions: What AI tools are our employees using? What data are they accessing? How do we secure the credentials of our AI bots? How do we defend against an AI-generated deepfake of our CFO authorizing a wire transfer?
The solutions will likely involve a combination of advanced, AI-powered threat interception for email and collaboration tools, continuous monitoring of agent behavior, and targeted, in-the-moment coaching for employees. By securing both humans and agents, companies can build the trust and resilience needed to innovate confidently. The era of the hybrid workforce is here, and securing it represents the next great frontier for the global economy.
