Asia Pacific organisations widely expect artificial intelligence (AI) to be used in attacks against them, while many remain unprepared for threats that exploit human judgement, according to new research from Mimecast.
Mimecast’s State of Human Risk 2026 study, released on 23 July 2026, found that 65 per cent of surveyed IT and security decision-makers believe an AI-enabled attack against their organisation is inevitable within the next 12 months. The findings are based on responses from 500 IT security and IT decision-makers across Singapore and Australia.
Concern outpacing preparedness
Concern about the threat is widespread, with 79 per cent of respondents saying they are worried about AI being used as an attack vector against their organisation. Yet 60 per cent said their organisation was not fully prepared to handle AI-driven threats that exploit human vulnerabilities, including 52 per cent who described themselves as still developing AI-specific defence strategies.
Employees are seen as a particular point of exposure. Two-thirds of respondents (66 per cent) agreed that an employee within their organisation was very likely to be fooled by a cybercriminal using AI as part of a social engineering attack.
‘AI is changing the way cybercriminals manipulate trust,’ said Nicky Choo, Vice President and General Manager, APAC, Mimecast. ‘Attackers can now use it to create convincing, tailored messages that appear to come from a colleague, a partner or a senior leader, which means employees are being asked to make difficult decisions in real time.’
Training has not kept pace
The study found AI-specific employee training remains limited: only 40 per cent of organisations provide training on how to use AI while avoiding exploitation, and 42 per cent conduct simulated AI-driven phishing attacks.
‘Employees should not be expected to identify increasingly sophisticated deception on instinct alone,’ Choo said. ‘Yet many organisations have not yet caught up. Fewer than half are training staff on how to avoid AI-driven exploitation or running simulated AI phishing exercises.’
Mimecast commissioned Vanson Bourne to survey 2,500 IT security and IT decision-makers across nine countries, including Singapore and Australia, in November and December 2025, covering organisations with more than 250 employees each.

