Singapore – A majority of organisations in Asia Pacific expect to face an artificial intelligence (AI)-enabled cyberattack within the next 12 months, according to new research from cybersecurity company Mimecast, with many also reporting that they are not fully prepared to address AI-driven threats targeting human vulnerabilities.
The findings come from Mimecast’s State of Human Risk 2026 study, which surveyed 500 IT security and IT decision-makers across Singapore and Australia.
According to the study, 65% of respondents believe an AI-enabled attack against their organisation is inevitable within the next year, while 79% said they are concerned about AI being used as an attack vector.
Despite these concerns, 60% said their organisations were not fully prepared to respond to AI-driven threats that exploit human judgement. This includes 52% who described their organisations as somewhat prepared but still developing AI-specific defence strategies, while 9% said they were aware of the risks but had yet to establish a concrete strategy.
The research also highlighted concerns about employee vulnerability to AI-powered social engineering attacks. Around 66% of respondents said it was very likely that an employee within their organisation could be deceived by a cybercriminal using AI as part of a social engineering campaign.
Mimecast said the findings indicate that AI-enabled cyber risks are increasing the pressure on employees to determine whether communications and requests are legitimate.
“AI is changing the way cybercriminals manipulate trust,” said Nicky Choo, Vice President and General Manager, APAC, Mimecast. “Attackers can now use it to create convincing, tailored messages that appear to come from a colleague, a partner or a senior leader, which means employees are being asked to make difficult decisions in real time. The challenge is no longer just stopping threats before they arrive. It’s helping people recognise when the interactions they rely on may have been manipulated.”
The study also found that AI-specific cybersecurity training remains relatively limited among surveyed organisations. Forty percent of respondents said their organisations provide training on using AI while avoiding exploitation, while 42% conduct simulated AI-driven phishing exercises.
Mimecast noted that the results do not necessarily indicate an absence of broader cybersecurity awareness programmes, but suggest that many organisations have yet to implement training and simulations specifically designed to address AI-enabled threats.
“Employees should not be expected to identify increasingly sophisticated deception on instinct alone,” Choo said. “Yet many organisations have not yet caught up. Fewer than half are training staff on how to avoid AI-driven exploitation or running simulated AI phishing exercises. That leaves many employees making difficult judgement calls without the benefit of AI-specific preparation.”
Mimecast said the findings underscore the need for organisations to strengthen human judgement as part of their cybersecurity strategies, alongside technical controls, as AI continues to make it more difficult to distinguish legitimate communications from malicious ones.

