AI-Powered Scams & Phishing in the UK: How to Stay Safe in 2026
Adam K

Artificial intelligence is transforming the way people work, communicate and share information. Generative AI can draft emails, analyse documents, summarise complex information and automate tasks in seconds. For businesses and individuals, the opportunities are significant.
The same capabilities, however, are changing the online threat landscape.
For years, one of the most familiar pieces of cyber safety advice was to look for spelling mistakes, poor grammar or awkward language in suspicious emails. Those clues have not disappeared, but they are becoming less reliable. Generative AI can produce fluent, professional and persuasive content at speed, giving criminals another tool for creating convincing phishing messages and impersonation attempts.
The result is a more difficult environment for ordinary internet users. A fraudulent message may look professional, use familiar language and appear to come from a bank, employer, supplier, colleague or other trusted organisation.
This is why modern cyber safety increasingly depends on something more fundamental than recognising a badly written email: knowing when to trust, when to question and when to verify.
For businesses, there is another dimension to the problem. Generative AI is not only changing external cyber threats. Employees are also adopting AI tools in their everyday work, sometimes without fully understanding what information should be shared with them or when an AI-generated answer needs independent verification.
Together, these developments make three areas of digital literacy increasingly important: using AI responsibly, recognising phishing and scams, and protecting information.
How AI Is Changing Phishing and Online Scams
Phishing is fundamentally a form of deception. An attacker attempts to convince someone that a communication is legitimate so that the recipient takes an action they otherwise might not take.
That action could be clicking a link, providing login credentials, sharing confidential information, downloading a file or authorising a payment.
Artificial intelligence does not change that underlying principle. What it can change is the quality and scale of the communication used to deliver the deception.
A phishing message no longer needs to contain obvious spelling mistakes or unnatural phrasing. Generative AI can help produce polished communications in different styles and languages. Publicly available information can also make attempts at impersonation more convincing by giving criminals details about organisations, employees, suppliers and professional relationships.
This makes context increasingly important.
Instead of asking only, “Does this email look genuine?”, people need to ask, “Does this request make sense?”
Was the message expected? Is it normal for this person or organisation to make this type of request? Why is there urgency? Why am I being asked to provide this information? Is there another way to verify what I have been told?
That change in thinking is one of the most important developments in modern phishing awareness.
What Is AI-Powered Phishing?
AI-powered phishing is the use of artificial intelligence to help create, personalise or scale deceptive communications designed to persuade someone to reveal information, click a malicious link, make a payment or take another unsafe action.
Artificial intelligence does not fundamentally change the purpose of phishing. The objective is still to manipulate trust. What AI can change is the speed, quality and potential scale of the communications used to deliver the deception.
Generative AI can produce fluent, professional-looking text and adapt language for different audiences. This means traditional warning signs such as poor spelling, awkward grammar or unnatural phrasing should no longer be relied upon on their own.
The more important question is increasingly not simply “Does this message look genuine?” but “Does this request make sense, and can I verify it independently?”
This complements current UK guidance: the NCSC has warned that generative AI is likely to make aspects of social engineering more effective and make it harder for people to identify phishing attempts. For further reading visit ofcom website.
Why Phishing Is No Longer Just an Email Problem
The word “phishing” is still strongly associated with email, but deceptive communications can reach people through many different channels.
A suspicious request may arrive by text message, social media, messaging applications or other online services. QR codes can also be used to direct people to websites, a technique commonly referred to as “quishing”.
QR codes introduce an interesting challenge because the destination is not immediately visible to the person looking at the code. Someone scans it with their phone and is then taken elsewhere, potentially to a page designed to obtain credentials or other information.
The same principle therefore applies whether a person is clicking a conventional link or scanning a QR code: the apparent legitimacy of the message is not proof that the destination or request is genuine.
Authorised Push Payment fraud presents another example of why human judgement matters. A fraudulent communication may attempt to create urgency around an invoice, bank transfer or other financial request. The objective is often to persuade the victim to act before independently checking whether the request is genuine.
This is why effective phishing awareness is increasingly about behaviour rather than memorising a collection of obvious warning signs.
Certified CPD's Phishing Awareness Essentials course explores these risks in greater detail and is designed to help learners develop practical awareness of suspicious communications and online activity.
The Other Side of AI Risk: How We Use AI at Work
Much of the public discussion around AI and cybersecurity focuses on criminals using artificial intelligence. There is another important risk that begins inside organisations: how employees themselves use generative AI.
Consider an employee who needs to summarise a lengthy customer complaint. Copying the entire customer record into an AI tool may appear to be an efficient way to save time.
Another employee might ask an AI system to analyse a spreadsheet containing financial information. Someone working in HR might use AI to rewrite notes containing confidential employee information. A developer might paste proprietary code into a public AI service to help solve a problem.
In each case, the employee may have a perfectly legitimate objective. The security question is whether the information should have been entered into that particular AI system in the first place.
This is becoming an important aspect of AI literacy.
Before entering information into a generative AI tool, employees need to understand their organisation's policies, the nature of the information they are handling and the implications of sharing it with an external system.
The relevant question is not simply “Can AI help me do this?”
It is also “Should I give this information to AI in order to do it?”
The Generative AI Awareness at Work course is designed around this wider need for AI awareness, helping learners understand the opportunities, limitations and risks associated with using generative AI in a professional environment.
Why AI-Generated Information Still Requires Human Judgement
Information security is not the only concern when employees use generative AI.
AI systems can generate responses that sound authoritative and convincing without guaranteeing that the information is correct. This creates a different type of organisational risk.
An employee may receive an answer that appears sufficiently confident to be copied directly into an email, report, proposal or decision-making process. If that information has not been independently checked, an apparently small mistake can become a business problem.
The consequences depend on the context. Incorrect AI-generated information could potentially affect a customer communication, internal decision, financial analysis or professional recommendation.
Responsible AI use therefore requires more than knowing how to generate a useful response. It requires knowing when that response needs to be checked.
Human oversight remains particularly important when information is consequential, sensitive or relied upon to make important decisions.
What Information Should You Share With Generative AI?
There is no single answer that applies to every organisation and every AI platform. Different organisations have different policies, and different services handle information in different ways.
A more useful principle is to treat information according to its sensitivity and the rules that apply to it.
Before entering customer information, employee records, financial information, confidential business material, intellectual property or other sensitive information into an AI service, users should understand whether they are authorised to do so and how that service handles the information provided.
For employees, organisational policy should be the starting point. Where an organisation has approved AI tools or specific rules governing their use, those requirements should be followed.
Where there is uncertainty, the safest response is not to assume.
Ask before sharing.
That simple behaviour can be considerably more valuable than attempting to memorise every possible AI risk.
Why Information Security Matters to Everyone
Information security can sound like a specialist discipline belonging to IT departments and cybersecurity professionals. In reality, almost everyone now handles information that has value.
Personal email accounts contain years of correspondence. Online banking provides access to financial information. Cloud services store documents and photographs. Businesses hold customer records, employee information, commercial documents and account credentials.
The security of that information therefore depends partly on technology and partly on human behaviour.
A sophisticated security system can provide important protection, but it cannot make every decision for the person using it. Someone still has to decide whether to disclose information, trust a message, approve a request or enter credentials into a website.
This is why information and data security awareness has become an everyday professional skill rather than a purely technical one.
Certified CPD's Information & Data Security course provides learners with a broader understanding of protecting personal and professional information and developing safer digital practices.
The Three Digital Safety Skills Professionals Increasingly Need
The changing digital environment brings AI awareness, phishing awareness and information security much closer together than they once were.
The first requirement is responsible generative AI use. People need to understand what AI can do, where its limitations lie, what information requires additional care and when AI-generated outputs should be independently verified.
The second is phishing and scam awareness. The ability to recognise suspicious communications increasingly depends on understanding context, questioning unexpected requests and verifying unusual activity rather than relying on superficial clues such as spelling mistakes.
The third is information and data security. People need to understand the value of the information they handle and how everyday decisions about accounts, credentials, data sharing and online behaviour can affect its security.
These are not advanced technical cybersecurity skills.
They are human digital-risk skills.
That distinction matters because most employees, freelancers, job seekers and small business owners do not need to become cybersecurity specialists. They need enough practical knowledge to make better decisions when something unexpected happens online.
Can Cyber Awareness Training Help With Cyber Liability Insurance Requirements?
Cyber liability insurance has also increased business interest in employee cyber awareness.
Insurers may ask organisations about the measures they have in place to manage cyber risk, which can include questions relating to employee awareness and security training. The precise requirements vary between insurers, policies and organisations, so no individual training course should be presented as automatically satisfying an insurer's conditions.
Structured employee training can, however, provide documented evidence that an organisation is taking steps to develop staff awareness of relevant cyber risks.
For organisations considering training partly because of cyber liability insurance requirements, the appropriate approach is to confirm the specific requirements with the insurer or broker and then ensure that the chosen training aligns with them.
This distinction is important. Cyber awareness training should form part of a wider approach to risk management rather than being treated as a substitute for appropriate technical controls, organisational policies or professional cybersecurity advice.
Is AI and Cyber Safety Training Only Relevant to Businesses?
No. The underlying risks extend well beyond the workplace.
Someone shopping online may encounter a fraudulent message. A job seeker may receive an impersonation attempt. A freelancer may handle confidential client information. A student may use generative AI without considering what information is being shared. A small business owner may receive an unexpected payment request that appears to come from a supplier.
The circumstances are different, but the underlying decision is often remarkably similar:
Is this genuine, is this information safe to share, and should I act?
That is why AI and cyber safety awareness has relevance across professional and personal life.
For individuals, it can build confidence in navigating an increasingly complex digital environment. For employees, it can contribute to safer workplace behaviour. For organisations, it can support a broader culture in which people understand that cybersecurity is not solely the responsibility of the IT department.
Which AI and Cyber Safety Training Is Right for You?
Someone primarily interested in understanding generative AI and its responsible use at work may want to begin with Generative AI Awareness at Work.
Someone whose main concern is recognising suspicious emails, messages and online activity may find Phishing Awareness Essentials the more appropriate starting point.
For those looking to strengthen their understanding of protecting personal and professional information, Information & Data Security addresses the broader principles of information security.
The three subjects are closely connected, however. AI affects how information is created and shared. Phishing exploits human trust. Information security helps people understand what they are protecting and why.
For learners who want coverage across all three areas, Certified CPD's AI & Cyber Safety Essentials brings the three courses together in one self-paced online bundle.
Building Digital Confidence in an AI-Powered World
The objective of cyber awareness should not be to make people frightened of every email, link or new technology.
Nor should the response to AI risk be to avoid generative AI altogether.
The more useful objective is informed confidence.
People should be able to benefit from AI while understanding its limitations. They should be able to receive an unexpected message without immediately trusting or panicking about it. They should understand that sensitive information has value and that a few moments spent verifying an unusual request can matter.
Technology will continue to change. The specific scams people encounter will change with it.
But some of the most valuable defensive behaviours are remarkably durable: question what is unexpected, verify what matters, protect sensitive information and think before acting.
That is the foundation of modern digital safety.
The AI & Cyber Safety Essentials bundle combines Generative AI Awareness at Work, Phishing Awareness Essentials and Information & Data Security into one online learning package, designed to build practical awareness across these three increasingly connected areas.
FAQs
1. Can AI make phishing emails and online scams harder to spot?
Yes. Generative AI can produce professional, natural-sounding text quickly, which can make some fraudulent messages appear more convincing. This means spelling mistakes and poor grammar should no longer be relied upon as the main indicators of phishing. Unexpected requests, urgency, suspicious links and requests for sensitive information should all be treated carefully.
2. How can I tell if an email or message is a phishing scam?
Look beyond how professional the message appears. Consider whether you expected the communication, whether the sender is asking you to act urgently, click a link, make a payment or provide sensitive information. If something seems unusual, verify the request independently using contact details or a website you already know and trust rather than those provided in the message.
3. What information should I avoid sharing with generative AI?
You should think carefully before sharing personal data, confidential business information, customer records, financial information, passwords, intellectual property or other sensitive information with generative AI tools. Employees should always follow their organisation's AI, data protection and information security policies and use approved AI services where required.
4. Can cyber awareness training help with cyber liability insurance requirements?
Cyber awareness training can support an organisation's wider cyber-risk management and provide evidence that employees have received relevant training. Some cyber insurers may ask about employee security awareness as part of their underwriting or risk-management requirements. However, requirements vary between insurers and policies, so businesses should confirm their specific requirements with their insurer or broker.
5. What training can help employees understand AI, phishing and information security?
Training that combines generative AI awareness, phishing awareness and information security can help employees understand several of today's interconnected digital risks. Certified CPD's AI & Cyber Safety Essentials brings together Generative AI Awareness at Work, Phishing Awareness Essentials and Information & Data Security in one self-paced online training bundle.
Sources & References
This article draws on current guidance, research and fraud statistics from leading UK public bodies and industry organisations.
Office for National Statistics (ONS) — Crime in England and Wales: year ending March 2026. Latest estimates of fraud incidents and victims in England and Wales.
Office for National Statistics – Crime in England and Wales
National Cyber Security Centre (NCSC) — The near-term impact of AI on the cyber threat. Assessment of how artificial intelligence is expected to affect cyber threats, including social engineering and phishing.
NCSC – The near-term impact of AI on the cyber threat
Ofcom — New rules to thwart text message scammers and protect consumers and businesses. Includes 2026 data on suspicious messages received by UK mobile users and the wider scale of fraud.
Ofcom – Protecting consumers and businesses from message scams
UK Finance — Annual Fraud Report 2026. UK fraud data covering 2025, including Authorised Push Payment (APP) fraud and the channels through which cases originated.
UK Finance – Fraud Report 2026
City of London Police / Report Fraud — UK victims lost £2.4 million a day to investment fraud in 2025. Reports £879.8 million in investment fraud losses during 2025.
Report Fraud – UK investment fraud losses in 2025
Information Commissioner's Office (ICO) — Guidance on AI and data protection. UK guidance covering the application of data protection law to artificial intelligence and the processing of personal data.
ICO – Guidance on AI and data protection
Last reviewed: August 2026