2026 Logo v6
+27 76 521 5042
info@d-finitive.com
LinkedIn Banner Refined
Artificial intelligence is transforming cybercrime—and the fight against it. As criminals weaponize AI to launch faster, smarter attacks, defenders are using the same technology to detect, disrupt, and respond. The battle is increasingly AI versus AI.

Artificial Intelligence vs Artificial Intelligence: How AI Is Fighting Cybercrime

Artificial intelligence is rapidly changing the cybercrime landscape. The same technology that helps organisations automate processes, analyse data, and improve decision-making is also giving cybercriminals new ways to operate faster, smarter, and at greater scale.

 

AI can help criminals craft convincing phishing messages, impersonate trusted individuals, automate attacks, and identify potential vulnerabilities. In Africa, the scale of this shift is already significant: INTERPOL reports that AI is enabling 55% of reported cybercrimes across the continent (INTERPOL, 2026).

 

Yet AI is also becoming one of cybersecurity’s strongest defensive tools—detecting unusual behaviour, identifying threats, and enabling faster responses.

 

For African organisations, this creates a new reality: AI is no longer simply a technology to adopt. It is becoming both a weapon and a defence. The emerging contest is increasingly AI versus AI.

 

How Cybercriminals Are Weaponizing AI

Artificial intelligence has lowered the barriers to sophisticated cybercrime. Tasks that require technical expertise, time and resources can increasingly be automated or enhanced using readily available AI tools.

 

Generative AI can produce convincing phishing emails, imitate writing styles, and create fraudulent content at scale, and speed. AI-generated voices, images, and video are also strengthening impersonation and social-engineering attacks, making legitimate communication increasingly difficult to distinguish from deception.

 

Across Africa, INTERPOL has identified cybercriminals integrating AI-generated text, audio, and video into phishing campaigns, including personalized communications designed to imitate specific individuals or organisations (INTERPOL, 2025).

 

Beyond content creation, criminals can use AI to analyse information, identify potential targets, automate reconnaissance, and adapt attacks more rapidly.

 

The result is not necessarily an entirely new form of cybercrime, but a significant increase in its speed, scale, and sophistication. For organisations, this creates a difficult imbalance: attackers may need only one convincing message or overlooked vulnerability to succeed, while defenders must continuously protect against thousands of potential threats.

 

How AI is Fighting Back

The same capabilities that make AI attractive to cybercriminals are strengthening cyber defence. Traditional security tools often depend on predefined rules and known indicators of compromise. AI-driven systems can go further by analysing vast volumes of activity and identifying patterns that may signal a threat before it becomes obvious.

 

Machine learning can establish normal patterns of user, device and network behaviour and flag anomalies—such as unusual login activity, abnormal transactions, or unexpected access to sensitive information. AI can also support fraud detection, identify insider threats, and reduce the volume of false alerts requiring investigation (National Institute of Standards and Technology (NIST), 2025)

 

The advantage is speed. AI-enabled security systems can analyse threats, prioritise higher-risk incidents and support automated responses, including containment actions and incident-response processes. NIST specifically identifies advanced threat detection and automated incident response among the opportunities for AI-enabled cyber defence (National Institute of Standards and Technology (NIST), 2025).

 

AI does not, however, replace skilled cybersecurity professionals. Its greatest defensive value lies in combining machine speed and analytical capacity with human expertise, oversight, and judgement. The importance of these defensive capabilities becomes particularly clear when viewed against South Africa’s evolving fraud landscape.

 

The South African Context: When AI Meets Social Engineering

South Africa’s elevated levels of digital banking and widespread use of social media and messaging platforms create fertile ground for increasingly sophisticated social-engineering attacks. Criminals no longer need to rely on poorly written phishing emails. Generative AI can help produce convincing messages, replicate voices, and create realistic images or video capable of impersonating trusted individuals and organisations.

 

The scale of the underlying fraud threat is significant. In 2024, SABRIC recorded 97,975 digital banking fraud incidents, an 86% increase from the previous year, while gross losses increased by 74% to approximately R1.9 billion. SABRIC has also identified AI-driven scams, phishing and deepfake-enabled impersonation among the evolving threats facing the banking environment (South African Banking Risk Information Centre (SABRIC), 2025). The risk extends beyond individual consumers. For businesses, an AI-generated voice message or video purporting to come from an executive could reinforce a fraudulent payment instruction, while AI-generated correspondence could imitate suppliers, colleagues, or clients.

 

The South African context illustrates a crucial point: AI does not need to create an entirely new crime to increase risk. Its power lies in making familiar fraud techniques more believable, scalable, and difficult to detect.

 

The AI-versus-AI Arms Race

The emerging cyber landscape is becoming a contest of speed, adaptation, and intelligence. The World Economic Forum reports that 94% of surveyed cyber leaders expect AI to be the most significant driver of change in cybersecurity in 2026 (World Economic Forum, 2026).

 

Attackers can use AI to increase the scale, speed, and sophistication of attacks, while defenders are harnessing it to strengthen detection, accelerate incident response and automate high-volume analytical tasks. The result is an intensifying technological contest in which both sides are continuously adapting.

 

However, AI introduces risks of its own. Poorly implemented systems can create vulnerabilities through misconfiguration, overreliance on automation and susceptibility to adversarial manipulation. Cybercriminals may also deliberately attempt to deceive or exploit AI-based security systems.

 

The advantage will therefore not necessarily belong to the organisation with the most advanced AI. It will belong to those that combine technology with strong governance, quality data, skilled people, and effective human oversight.

 

Building an AI-Ready Cyber Defence

As AI becomes embedded in both attack and defence, organisations need to rethink cybersecurity beyond traditional controls. Investing in AI-enabled security tools is important, but technology alone will not provide resilience.

 

Effective defence requires strong governance over how AI is selected, deployed, and monitored. Organisations should establish clear accountability; understand the data underpinning their systems and regularly evaluate whether controls remain effective as threats evolve. Human oversight must remain integral to AI-driven decision-making (Tabassi, 2023).

 

Employees are equally important. As AI-generated phishing, deepfakes and impersonation become more convincing, verification procedures should be strengthened—particularly for payments, changes to banking details and requests involving sensitive information.

 

Ultimately, AI should strengthen rather than replace existing cybersecurity foundations. Technology, governance, and human judgement must work together if organisations are to remain resilient in an AI-enabled threat environment.

 

D-finitive Insights

Artificial intelligence is changing the balance of cyber risk. The same capabilities that allow criminals to automate, personalise, and scale attacks are giving organisations new ways to detect, analyse, and respond to them.

 

The challenge is therefore not simply adopting AI but using it more effectively and responsibly than those seeking to exploit it.

 

For African organisations, this means strengthening cyber controls, preparing employees for increasingly convincing AI-enabled deception, and embedding governance and human oversight into the use of AI.

 

In the emerging AI-versus-AI environment, resilience will depend not on technology alone, but on how intelligently organisations use it.

 

Delivering Clarity. Protecting Integrity. Driving Accountability.