It's no secret that cybersecurity strategy relies on a familiar assumption: humans are the weakest link. If you train your people to spot suspicious emails, use multi-factor authentication, and have endpoint protection, you have your best chance of avoiding a cyber incident. That framework is now obsolete.
We've entered the age of AI vs. AI.
Generative AI can be helpful, but without appropriate controls and tools, it expands the capabilities of bad actors. These actors can now exploit weaknesses at a scale previously impossible. Further, traditional MFA assumes it's possible to reliably authenticate a user. AI-powered attacks change that supposition.
Bad actors using generative AI no longer need to guess how to exploit vulnerabilities. They persuade. AI can perfect impersonation by cloning voices, leveraging synthetic video, and hyper-personalizing phishing attacks. This is real and not theoretical; we see it every day on social media. It is now harder than ever to train human judgment to defeat this enhanced machine-generated deception.
According to the Thales 2026 Data Threat Report, AI-fueled attacks are a prominent threat: 59% of global respondents have seen deepfake attacks, and 48% have experienced reputational damage due to AI-generated misinformation. AI generates convincing pretexts in real time and exploits a vulnerability no software patch can fix: trust.
How does this impact higher education?
Higher education faces an uphill battle, as it is already a top target for cybercriminals due to its decentralized IT environment and open-by-design culture. Now those same characteristics amplify exposure to the threats described above.
Hardware-based authentication is one of the strongest mitigating controls available. FIDO2 protocols anchor identity to a physical device and cryptographic keys that cannot be phished or socially engineered away. However, unlike in the private sector, universities have thousands of students on completely unmanaged personal devices across every operating system. BYOD is one of the major factors complicating FIDO2 adoption. Furthermore, legacy systems may not support FIDO2.
Third-party risk deserves equal attention. Organizations bear the risk of their entire ecosystem, whether or not they have contracted relationships. Institutional leaders need to review vendors more regularly to confirm they are also updating their security standards to prevent AI-related attacks. If a vendor can't speak to those requirements, that's a risk worth acting on.
The path forward requires a new posture.
The threat landscape has shifted, and higher education leaders can no longer treat this as a problem to delegate to IT or risk management without appropriate resources and executive-level understanding.
Begin with these questions:
Can your current architecture withstand a credential attack that bypasses human judgment entirely? If the answer is no, this is a risk worth highlighting and exploring further on your risk register.
Is it possible to accelerate FIDO2 adoption and pair existing MFA with behavioral analytics that don't rely solely on user verification? If the answer is no, that gap needs a clear owner and a timeline.
How are you addressing AI risks with key vendors? If your vendors cannot speak to how they're addressing AI-driven threats, that gap can be your liability. Don’t delay until contract renewal to have this discussion.
Finally, the "spot the phish" message needs an upgrade. Your campus community needs to know that even the best-trained eyes can be fooled, and that resilience comes from better architecture, not just awareness. The institutions that treat AI vs. AI as a present reality and invest accordingly will be better positioned when the next major attack makes the news.