Artificial intelligence (AI) is no longer just a futuristic concept in the world of cybersecurity; it has become an active and defining factor in the daily practice of IT security. While defenders deploy AI to protect complex corporate networks against invisible threats, malicious actors use the exact same technology to bypass traditional security mechanisms. This article provides an in-depth and factual analysis of this dynamic, specifically focusing on the implications for the Dutch digital infrastructure.
The landscape is changing at an unprecedented pace. The rise of Large Language Models (LLMs) and generative AI has drastically lowered the barrier to advanced cyberattacks, while simultaneously providing Security Operations Centers (SOCs) with powerful new analytical tools. The question is no longer whether AI is being used in cyberattacks, but how quickly organizations can adapt to this new reality.
The Sword: How Attackers Deploy AI (Offensive AI)
Cybercriminals have traditionally been early adopters of new technologies. The implementation of AI by malicious actors primarily focuses on scalability, speed, and deception. Manual processes that previously took hours or days can now be executed within seconds with unprecedented precision.
Hyper-personalized Phishing and Social Engineering
For years, phishing was relatively easy to recognize by poor grammar, strange sentence structures, and generic greetings. LLMs have made this detection method virtually obsolete. Today, attackers use advanced language models to generate flawless, highly convincing texts in any desired language, including perfect Dutch.
Even more concerning is the rise of automated spear-phishing. By linking AI to public data sources (OSINT) such as LinkedIn, corporate websites, and social media, attackers can create personalized messages at scale. For example, the model reads that an employee has just started a new project and automatically generates a seemingly legitimate email on behalf of the IT helpdesk, asking them to log in to a 'new project portal'. The scalability of these targeted attacks, made possible by AI, represents one of the greatest current threats.
Deepfake Fraud and CEO Fraud
While phishing focuses on text, deepfakes target image and sound. With just a few seconds of source material (such as a public speech, podcast, or corporate video), AI can now clone a person's voice highly accurately. This technology is deployed for so-called vishing (voice phishing) attacks, where employees are instructed over the phone to transfer large sums of money or share login credentials by a voice that sounds like their manager or CEO.
The threat is not limited to audio. Real-time video deepfakes are making their entry into video meetings. Although the technology for live video manipulation is still more complex than audio, there are already known cases in the market where financial employees have been deceived by a digitally created meeting. For more background on how such media are manipulated and the broader societal impact, you can consult our article on deepfakes and disinformation.
Automated Code Attacks and Vulnerability Discovery
The code-generating capabilities of modern AI models are not only praised by software developers. Attackers use AI to scan for vulnerabilities in massive amounts of source code (for example, in open-source libraries).
Furthermore, AI helps in writing so-called polymorphic malware: malicious code that slightly rewrites itself with each execution. Because the structure of the code changes constantly (even though the function remains the same), it is extremely difficult for traditional, signature-based antivirus software to detect this malware.
In addition, AI tools lower the barrier for so-called 'script kiddies' – attackers with little to no programming experience. By simply entering prompts, they can generate malicious scripts that previously required in-depth technical knowledge. The deployment of advanced reasoning models by attackers enables them to map complex network topologies faster and optimize attack paths.
The Shield: How Defenders Use AI (Defensive AI)
Despite the dark clouds of offensive AI, the technology also offers revolutionary defense mechanisms. In fact, to ward off AI-driven attacks, AI-driven defense is necessary. It is a classic arms race.
Anomaly Detection and Behavioral Analysis in Real-Time
Traditional security relies heavily on known 'Indicators of Compromise' (IoCs), such as known malicious IP addresses or file hashes. As mentioned earlier, this method fails with polymorphic malware or so-called zero-day vulnerabilities (security flaws that are still unknown to the software developer).
However, AI and Machine Learning algorithms excel at pattern recognition on a massive scale. An AI defense system studies normal network traffic and user behavior within an organization over a certain period. This creates a baseline.
As soon as a user – or a compromised account – suddenly starts copying hundreds of gigabytes of data to an unknown server abroad, or logs in at unusual times from an unusual location, the AI system immediately recognizes this anomaly, even if the specific malware is unknown.
Automated Response (SOAR) and Alert Fatigue
In modern IT environments, security systems generate thousands of alerts daily. Security analysts become overwhelmed by this, a phenomenon known as 'alert fatigue'. Large numbers of false positives cause real threats to sometimes be overlooked.
AI plays a crucial role in Security Orchestration, Automation, and Response (SOAR). The model acts as a first-line analyst: it filters the noise, clusters related alerts, and assesses the severity of a notification.
In critical incidents, such as a detected ransomware attack, the AI can autonomously decide to isolate an infected device (endpoint) from the network immediately, even before a human analyst has had time to intervene. The shift toward agentic AI in cybersecurity reduces the Mean Time to Respond (MTTR) from hours to seconds, which often means the difference between a minor incident and a catastrophic data breach.
What Does This Mean for Dutch Organizations?
The Dutch economy is highly digitized and heavily dependent on complex supply chains. This makes it an attractive target for both state actors (for espionage and disruption) and financially motivated cybercriminals (such as ransomware gangs). The introduction of AI into this landscape has specific consequences for Dutch companies and institutions.
Assumption vs. Reality
Many SMEs in the Netherlands still live under the assumption that they are "too small" or "too unimportant" for advanced AI attacks. This is a dangerous misconception. Because AI makes attacks highly scalable and cheap, targeted (spear) phishing is no longer reserved for multinationals. SMEs often form the weakest link and are used as a stepping stone to larger supply chain partners.
The Impact on SMEs and Enterprise
For large enterprises and vital infrastructure (such as banks, hospitals, and energy suppliers), the adoption of AI-driven detection systems (such as AI-enhanced XDR and SIEM solutions) is no longer a luxury, but a necessity. However, for small and medium-sized enterprises (SMEs), the costs and complexity of these systems often present a barrier.
The solution for SMEs increasingly lies with Managed Security Service Providers (MSSPs). These external IT security partners centrally use powerful AI tools to monitor the networks of numerous SME clients simultaneously. This democratizes the power of defensive AI.
Laws and Regulations: NIS2 and the EU AI Act
Pressure from the European Union and the Dutch government to increase cyber resilience is rising significantly. The new NIS2 directive (Network and Information Security) obligates a much larger group of Dutch organizations (including many suppliers of essential services) to implement strict security measures, including proactive detection and rapid incident response—areas where AI is crucial.
At the same time, organizations that deploy AI systems themselves for security or other business purposes must take the new European AI legislation into account. How to handle these technologies safely and compliantly requires strategic policy. More insight into this specific regulation can be found in our explanation of the EU AI Act. External expertise is also required for practical implementation; read more about the broader context on leren.llmnet.nl about adopting AI safely and responsibly in business operations.
Practical Steps for Defense
Although AI increases the technical complexity of attacks, the most effective defense mechanisms often remain rooted in fundamental security hygiene and the Zero Trust principle. Organizations should integrate the following steps into their security strategy:
- Continuous Security Awareness Training: Because AI-driven phishing looks increasingly real, employees must be trained to look not only at language but at the context (e.g., urgency, unusual requests). Always verify suspicious financial requests through a second channel (Out-of-Band verification).
- Implementation of AI-Driven Detection: Ensure that Endpoint Detection and Response (EDR) systems do not run purely on signatures, but can detect behavioral anomalies.
- Zero Trust Architecture (ZTA): Assume by default that the network is already compromised. Ensure strict network segmentation and constantly verify the identity and context of devices and users (via multi-factor authentication, MFA).
- Patch Management: AI can exploit vulnerabilities rapidly after discovery. Prompt and automated patching of systems is essential.
Conclusion: A Continuous Arms Race
The integration of AI in cybersecurity is a paradigm shift. Attackers will inevitably continue to innovate with generative models to exploit human weaknesses (social engineering) and technical gaps with unprecedented scale and precision. Conversely, defense without AI is bound to lose the battle; the human capacity to analyze the immense data streams of modern networks is simply insufficient.
For Dutch organizations, this means that waiting is not an option. Awareness of the threat (such as AI phishing and deepfakes) and strategic investments in AI-driven detection and response systems have become prerequisites for continuity in the current digital era.
Frequently Asked Questions (FAQ)
1. Does AI make traditional antivirus software completely useless?
No, traditional signature-based antivirus software is not useless, but it is insufficient as a sole line of defense. It remains effective at cheaply and quickly stopping already known, older malware. However, for modern, polymorphic, or AI-generated attacks, behavioral analysis (often referred to as Next-Gen Antivirus or EDR) is absolutely necessary.
2. How can I recognize an AI-generated phishing email?
Because AI models write flawless text, the old rule of looking for spelling mistakes no longer applies. Focus instead on the intent and urgency of the email. Does the sender ask for login credentials, financial transactions, or are there threats of immediate consequences? Furthermore, always check the actual sender (the email address, not just the display name) and log in to systems manually instead of clicking on links in the email.
3. Are deepfakes really a threat to Dutch SMEs?
Although the most advanced video deepfakes are often still targeted at large companies (CEO fraud), audio deepfake technology is becoming increasingly cheaper and more accessible. This means that financial administrations of SMEs can also become targets of automated, cloned phone calls. A simple internal protocol (for example: 'above €5000 we always double-check via a video call or in person') is often already sufficient to prevent this.
4. Can companies just feed internal data into an AI model for security analyses?
This is a critical point. Companies must be extremely careful about sharing log files and user data with public AI models like ChatGPT, due to privacy risks and GDPR regulations. For cybersecurity purposes, organizations should use shielded, corporate AI models (on-premise or within a secure enterprise cloud) where the data does not leave their own tenant and is not used to train public models.
5. How does AI relate to the mandatory reporting of data breaches?
The deployment of AI does not change legal obligations. Under the GDPR and the upcoming NIS2 directive, it remains mandatory to report serious incidents in a timely manner to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the NCSC. AI can, however, help organizations map out the exact scope and nature of a breach faster, resulting in more accurate and rapid reporting.