I've watched AI security stories get more dramatic with every new model, but there is a detail in INTERPOL's latest warning that is easier to miss.
The organization is not saying cybercriminals suddenly discovered some magical new attack method.
The bigger change is that familiar attacks can now become faster, cheaper, more convincing and easier to scale.
INTERPOL global chief information security officer Bjorn R. Watne told CNBC that AI is primarily enhancing established criminal techniques such as scams and fraud.
At the same time, he singled out agentic AI as a different risk because these systems can take actions on behalf of users rather than merely producing information.
That distinction could become one of the most important cybersecurity issues of the next few years.
INTERPOL says AI is increasing the speed and scale of familiar cyber threats while agentic systems introduce additional risks because they can act on a user's behalf.
INTERPOL Says AI Is Not Replacing Cybercrime — It Is Accelerating It
Watne's description is unusually straightforward: AI is an evolution of existing cybercrime rather than a complete revolution.
Scammers can use AI to communicate with more people at the same time, improve translations and create more convincing digital identities.
That matters because cybercrime often depends on scale.
A criminal who can personally contact ten potential victims has a limited ceiling. An automated system that can personalize thousands of interactions changes the economics.
INTERPOL's 2026 Global Financial Fraud Threat Assessment makes the same broader point. It estimates AI-enhanced fraud can be 4.5 times more profitable than non-enhanced tactics and says agentic AI can automate large portions of a fraud campaign.
Why Better Translation Is a Cybersecurity Problem
This sounds like a minor AI improvement until you consider social engineering.
A phishing email that contains awkward language or obvious spelling errors gives a recipient a reason to become suspicious.
Better translation removes one of those clues.
The same applies to customer-support messages, fake job offers, investment pitches and impersonation campaigns.
INTERPOL says improved translation and digital identities are making fraudulent interactions harder to distinguish from legitimate ones.
INTERPOL's Own Data Shows the Shift Is Already Broad
INTERPOL's regional cyber assessments provide useful context for the warning.
Its 2026 African Cyberthreat Assessment says AI was linked to 55% of reported cybercrime across Africa, with AI helping make attacks faster, more scalable and harder to detect.
The assessment also says cybercrime-related losses in the region increased from $192 million to $484 million since 2024, driven largely by AI-facilitated scams, credential harvesting and automated social engineering campaigns.
Those figures describe Africa rather than the United States, so they should not be treated as a direct U.S. measurement.
But they show why INTERPOL is treating AI-enabled cybercrime as an international issue rather than a niche technical problem.
Agentic AI Changes the Risk Equation
A normal chatbot can give you the wrong information.
An agent can potentially take the wrong action.
That is the distinction Watne emphasized to CNBC.
Agentic systems are increasingly designed to interact with tools, applications and external environments on a user's behalf.
That creates a different security problem: the AI now needs authority.
What Changes When AI Gets Permission
- Read access: an agent may retrieve information from email, documents or databases.
- Write access: an agent can create or change data.
- Transaction access: an agent may send money, place orders or trigger business workflows.
- System access: an agent may interact with software, APIs or infrastructure.
- Physical actions: systems connected to vehicles, machines or other devices can potentially convert an AI mistake into a real-world event.
NIST is now specifically working on identity, authentication, authorization, auditing and prompt-injection protections for AI agents because traditional model-level safeguards do not solve the entire authorization problem.
Watch a 2026 Discussion on Agentic AI and Cybersecurity
This discussion with cybersecurity researcher Haya Schulmann examines why autonomous AI systems require stronger guardrails as they gain the ability to perform actions.
2026 discussion on agentic AI, cybersecurity guardrails, privilege limits and the risks created when AI can act in the real world.
The Biggest Mistake Companies Can Make Is Protecting Everything Equally
Watne offered a surprisingly practical recommendation.
Companies should first identify their “crown jewels”: the systems and data that matter most to keeping the business alive.
Then they should identify who would be interested in stealing, changing or disrupting those assets.
From there, threat intelligence can be used to understand the techniques those adversaries actually use.
This is a better starting point than attempting to defend every possible attack scenario simultaneously.
Start With These Five Questions
What data would seriously damage the company if exposed? Which systems keep revenue flowing? Which credentials provide access to those systems? Who is most likely to target them? Which AI systems currently have access to them?
The Agent Identity Problem Is Coming Faster Than Many IT Teams Expect
There is an important security issue hiding underneath the agentic-AI conversation.
Who is the AI?
That sounds philosophical, but for security engineers it is an identity-management question.
If an AI agent can act for an employee, should it use the employee's credentials? Should it have its own identity? Can its permissions change from task to task?
NIST's current agent-identity work explicitly examines these questions, including how to authenticate agents, bind agent actions to human authorization, manage tokens and enforce least privilege.
That means the next wave of enterprise identity management may need to treat AI agents as first-class security principals rather than simply extensions of human accounts.
Bruce Schneier's Old Security Rule Is Suddenly Relevant Again
— Bruce Schneier
Schneier's point was that no individual security product can make an organization permanently secure.
That idea becomes especially relevant with AI agents because the software itself can change how data is accessed, how tools are used and how decisions are made.
A company cannot simply install an AI-security product and declare the problem finished.
It needs continuous authorization review, monitoring, logging, incident response and human oversight for high-impact actions.
The Overlooked Threat: Trust
Perhaps the most interesting part of Watne's comments was not about malware.
It was about human trust.
He argued that people often approach financial services with visible caution, while technology can receive much more automatic trust.
People click through permissions, accept prompts and connect new applications without always asking what authority they are granting.
This is why agent security is partly a traditional cybersecurity problem.
The technology changes, but identity, permissions, social engineering and human behavior remain central.
INTERPOL's Warning for U.S. Companies
For a U.S. business, the practical lesson is not to panic about some hypothetical autonomous super-hacker.
It is to examine where AI is already connected to sensitive systems.
An AI assistant connected to a public knowledge base is one thing.
An agent connected to corporate email, a source-code repository, customer records, financial systems and production infrastructure is another.
The more authority the agent receives, the more important its identity and authorization model becomes.
What Security Teams Should Audit Now
- Agent inventory: Know which AI agents exist and what tools they can access.
- Permissions: Apply least privilege rather than giving agents broad access for convenience.
- Credentials: Keep API keys, tokens and secrets out of prompts, memory and uncontrolled tool responses.
- Human approval: Require explicit authorization for high-impact or irreversible actions.
- Logging: Record what the agent attempted, what tools it used and which human or service identity authorized the action.
- Kill switch: Make it possible to quickly disable an agent without taking down unrelated systems.
INTERPOL Is Also Fighting AI With AI
There is another side of the story that deserves attention.
INTERPOL is not treating AI only as an attacker advantage.
The organization has also been deploying AI and related automation in law-enforcement operations.
In a June 2026 counter-terrorism operation, INTERPOL said AI agents and generated scripts helped automate data collection, deduplication and quality checks across more than 108,000 facial images before analysts reviewed the resulting dataset.
That illustrates the emerging reality.
The same technology that increases attacker efficiency can also increase defender efficiency.
The advantage may increasingly go to the organization that can safely automate more of the right tasks.
AI Cybersecurity Is Becoming an Identity Problem
The most important takeaway from this week's INTERPOL warning is surprisingly simple.
AI does not need to become dramatically more intelligent to make cybercrime more dangerous.
If it can make phishing more convincing, translate messages more naturally, generate identities faster and automate repetitive interactions, attackers can scale existing methods more efficiently.
Agentic AI pushes the problem further because the system itself may be able to act.
That means cybersecurity teams now have to ask two separate questions:
Two Questions Every AI Deployment Needs
What can this AI know? And equally important: what can this AI do?
NIST's current agent-identity work, INTERPOL's cybercrime assessments and Watne's warning all point toward the same practical direction: identity, least privilege, monitoring and human oversight are becoming core parts of secure AI deployment.
That is much less dramatic than the idea of an AI “taking over the internet.”
It is also much more useful.
The Real Threats of AI Misuse
INTERPOL's warning about agentic AI is just one piece of a rapidly expanding puzzle. From autonomous agents exceeding their permissions to hyper-targeted digital manipulation, the cybersecurity landscape is shifting. Read our complete guide to uncover the real AI threats nobody is talking about.
Read the AI Misuse Guide →Sources checked for this article:
CNBC — INTERPOL says AI is increasing the speed and scale of cyber threats
INTERPOL — 2026 Global Financial Fraud Threat Assessment
INTERPOL — African Cyberthreat Assessment 2026
INTERPOL — Asia and South Pacific Cyberthreat Assessment
INTERPOL — Fighting AI With AI
NIST — Identity and Authority of Software Agents
NIST — Why Agentic AI Needs a Strong Identity Foundation
Bruce Schneier — The Process of Security
Bernard Marr — Agentic AI and Cybersecurity: Why Guardrails Matter
Frequently Asked Questions About INTERPOL's AI Cybersecurity Warning
What did INTERPOL warn about AI and cyber threats?
INTERPOL global chief information security officer Bjorn R. Watne told CNBC that AI is making existing cyber threats faster and easier to scale, particularly scams and fraud. He described the change as an evolution of established criminal techniques rather than a completely new form of cybercrime.
Why is agentic AI considered a different cybersecurity risk?
Agentic AI systems can perform actions on behalf of users instead of only generating information. That means a mistake or malicious instruction can potentially affect data, applications, transactions or connected physical systems depending on the permissions the agent has been given.
How are criminals using AI in cybercrime?
INTERPOL reports that AI is being used to improve scams, phishing, social engineering, translation, synthetic identities and other existing criminal techniques. Its African Cyberthreat Assessment says AI was linked to 55% of reported cybercrime across surveyed African countries.
What should companies do about agentic AI security?
Companies should inventory their AI agents, identify the tools and data each agent can access, apply least-privilege permissions, protect credentials and secrets, log agent activity, and require human approval for high-impact or irreversible actions.
What does NIST recommend for AI agent identity?
NIST's current work examines how AI agents should be identified, authenticated and authorized, how permissions should be limited, how agent actions can be audited, and how human authorization can be connected to actions performed by AI agents.
No comments:
Post a Comment