AI is increasingly being used on both sides of the cyber battlefield, helping criminals scale attacks while enabling defenders to detect anomalies, correlate threats, investigate incidents and accelerate response.

Day 2 AI Threat Detection: How AI Is Fighting the AI-Powered Criminal

The420.in Staff
14 Min Read

Centre for Police Technology Launches a 31-Day Cybersecurity Knowledge Series for Police, LEAs, Corporate Investigators, Digital Forensics, Fraud, Cyber Risk and Security Professionals

October 2, 2026: As artificial intelligence becomes increasingly accessible, it is changing both sides of the cybersecurity equation.

Criminals are using AI to automate reconnaissance, create convincing impersonation campaigns, analyse stolen information and scale fraud. At the same time, cybersecurity companies, police agencies and investigators are using AI to detect suspicious behaviour, identify patterns and respond to threats faster.

This creates a new cybersecurity reality:

AI is becoming both a weapon for attackers and a detection tool for defenders.

Following Day 1’s focus on Agentic AI Security, Day 2 of the Centre for Police Technology (CPT) 31-Day Cybersecurity Knowledge Series examines AI Threat Detection — how it works, how criminals are using AI, how defenders can counter these threats and what new technologies are emerging.

What Is AI Threat Detection?

Traditional cybersecurity systems often depend on predefined signatures, rules and known indicators of compromise.

For example, a security system may block a known malicious file, IP address or website.

But modern attacks can change rapidly.

Attackers can modify malware, create new infrastructure, use legitimate services and generate highly convincing social-engineering content.

AI Threat Detection approaches the problem differently.

Instead of asking only:

“Have we seen this attack before?”

AI can also help ask:

“Does this behaviour look unusual, suspicious or inconsistent with what normally happens in this environment?”

Machine Learning (ML), behavioural analytics, anomaly detection, Natural Language Processing (NLP) and AI-assisted security operations can analyse enormous volumes of security information and identify patterns that may require investigation.

Microsoft’s 2026 Digital Defense Report describes AI as changing both the offensive and defensive sides of cybersecurity, with attackers gaining speed and scale while defenders use AI for discovery, analysis, prioritisation and response.

How Are Criminals Using AI?

AI is not limited to helping criminals write phishing emails.

Its potential use extends across multiple stages of the attack chain.

Microsoft recently described EvilTokens, a cybercrime platform that used an AI-style chatbot to analyse compromised email accounts, identify trusted relationships and payment responsibilities, and help criminals develop fraud strategies and impersonation messages.

This illustrates an important change.

AI can potentially help criminals move from:

“Send thousands of fraudulent messages.”

to:

“Identify the most valuable person, understand their relationships and create a more targeted attack.”

AI can also assist criminals with:

  • Generating convincing phishing and social-engineering content
  • Impersonating trusted individuals or organisations
  • Analysing stolen information
  • Automating reconnaissance
  • Scaling fraudulent communications
  • Creating variations of malicious content
  • Identifying potential targets
  • Automating parts of cybercrime workflows

The result is not necessarily a completely new form of cybercrime.

Instead, AI can make existing criminal techniques faster, cheaper, more personalised and easier to scale.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

Why AI Makes Threat Detection More Difficult

The same technology that helps defenders analyse patterns can make attacks harder to distinguish from legitimate activity.

Consider a conventional phishing message.

It may contain obvious spelling mistakes, unusual formatting or suspicious language.

AI can help criminals produce messages that are grammatically polished, personalised and contextually appropriate.

Similarly, a fraudulent communication may use information gathered from public sources or compromised accounts to appear more credible.

This creates a problem for traditional security controls.

The question is no longer simply:

“Does this message look suspicious?”

It becomes:

“Does this communication, identity, behaviour and transaction make sense when considered together?”

That is where behavioural and AI-assisted detection becomes increasingly important.

How Does AI Detect a Cyber Threat?

AI-powered detection can examine multiple signals simultaneously.

For example:

Login → Device → Location → Behaviour → Data Access → Network Activity → Transaction

Imagine an employee normally logs in from Delhi during working hours and accesses a predictable group of applications.

Suddenly, the account:

  • Logs in from an unfamiliar location
  • Uses an unfamiliar device
  • Accesses sensitive files
  • Downloads unusually large amounts of data
  • Attempts privileged actions

None of these events alone necessarily proves malicious activity.

Together, however, they may represent a significant behavioural anomaly.

AI systems can help correlate these signals and assign greater attention to the overall pattern.

This can allow security teams to investigate suspicious activity before it develops into a major incident.

How Can Police and LEAs Use AI Threat Detection?

For police and Law Enforcement Agencies, AI threat detection can have applications beyond protecting government networks.

Investigators increasingly encounter enormous quantities of digital information.

An investigation may involve:

  • Emails
  • Chat records
  • IP addresses
  • Device logs
  • Financial transactions
  • Cloud records
  • Malware
  • Network activity
  • Digital images and documents
  • Cryptocurrency-related information
  • Open-source intelligence

AI can assist investigators in identifying relationships, anomalies and patterns across large datasets.

For example, an investigation involving multiple accounts could reveal common devices, locations, communication patterns or transaction relationships that would be difficult to identify manually.

AI can therefore help with:

  • Cybercrime triage
  • Digital-evidence analysis
  • Threat-intelligence correlation
  • OSINT analysis
  • Fraud-pattern detection
  • Malware analysis
  • Investigative lead generation

However, there is an essential distinction:

An AI-generated alert or anomaly is an investigative lead — not automatically evidence of criminal activity.

Investigators must still establish the facts through lawful collection, verification, preservation and analysis of evidence.

How Can Common People Counter AI-Powered Threats?

AI threat detection is not only a problem for large companies.

Ordinary users are increasingly exposed to AI-assisted phishing, impersonation and fraud.

The defensive approach therefore needs to change as well.

1. Verify Before Trusting

If someone suddenly asks for money, OTPs, passwords, banking information or urgent action, independently verify the request.

Do not rely solely on the appearance, voice or writing style of the person contacting you.

2. Treat Urgency as a Warning Sign

AI can make fraudulent messages highly convincing.

A request that says:

“Act immediately.”

should be independently verified before action is taken.

3. Do Not Trust Voice or Video Alone

AI-generated or manipulated audio and video can make impersonation more convincing.

If someone makes an unusual financial or sensitive request through a call or video, verify their identity through another trusted channel.

4. Protect the Information AI Can Use Against You

Publicly available information can help attackers construct more convincing impersonation attempts.

Review what personal information is publicly visible on social media and other platforms.

5. Use Strong Account Protection

Multi-factor authentication, unique passwords, password managers, software updates and device security remain important even in an AI-driven threat environment.

AI does not make basic cybersecurity obsolete.

It makes basic cybersecurity more important.

How Can Organisations Counter AI-Powered Threats?

Organisations need to defend against both AI-enabled attacks and attacks against their own AI systems.

Important controls include:

  • Identity and access management
  • Multi-factor authentication
  • Least-privilege access
  • Endpoint detection and response
  • Network monitoring
  • Security information and event management
  • Data-loss prevention
  • Threat intelligence
  • Behavioural analytics
  • AI-specific security controls
  • Continuous logging and monitoring
  • Human approval for high-impact actions

The goal should not be to replace every security analyst with AI.

Instead, AI can help analysts process information faster while humans retain responsibility for consequential decisions.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

What New AI Threat Detection Technologies Are Emerging?

The cybersecurity industry is rapidly developing products designed to use AI for threat detection, investigation and response.

Google AI Threat Defense

In May 2026, Google Cloud introduced Google AI Threat Defense, an AI-powered cybersecurity platform designed to identify and prioritise real-world attack paths and accelerate remediation. Google describes it as an always-on autonomous security platform intended to help organisations defend against attacks occurring at machine speed.

CrowdStrike Falcon AI Detection and Response

CrowdStrike expanded Falcon AI Detection and Response (AIDR) in 2026, including integrations with AI gateway partners such as Google Cloud, Microsoft Azure, Databricks, Kong and others. The aim is to provide greater visibility and control over AI interactions, including risks involving prompts, agents and models.

Zscaler Agentic SOC

In September 2026, Zscaler announced Zscaler Agentic SOC, designed to use specialised AI agents to detect, investigate and respond to threats at machine speed.

FortiSOC

Fortinet introduced FortiSOC, a cloud-delivered SOC platform incorporating agentic AI to correlate alerts, investigate threats and recommend or execute response actions under analyst oversight.

Blackpoint AI SOC Agent

Blackpoint Cyber announced an autonomous AI SOC Agent for Identity Threat Detection and Response, designed to identify and contain high-confidence identity-related threats targeting Microsoft 365 and Google Workspace accounts.

Sophos Fusion

Sophos launched Sophos Fusion, an AI-native cybersecurity defence system designed to connect security controls, data sources and analyst workflows, with agentic AI used for investigation and response within defined controls.

These developments show that the market is moving beyond AI as a simple chatbot or assistant.

AI is increasingly being incorporated directly into:

Threat Detection → Investigation → Correlation → Threat Hunting → Response

But Can We Trust AI to Detect Threats?

Not completely.

AI systems can produce false positives.

They can miss genuine threats.

They can be affected by poor-quality data.

Attackers can also attempt to manipulate detection systems.

This means AI-generated conclusions should be treated with appropriate scrutiny.

For police and forensic investigators, this becomes even more important.

If an AI system identifies a device, person, transaction or communication as suspicious, investigators must still determine:

  • What data produced the finding?
  • How reliable was that data?
  • Why did the system flag it?
  • Can the result be independently verified?
  • Was the underlying evidence lawfully obtained and preserved?

AI can accelerate an investigation.

It should not replace the investigative process.

What Happens When AI Meets AI?

The cybersecurity landscape is increasingly becoming a competition between automated systems.

Attackers can use AI to:

Find → Target → Manipulate → Automate

Defenders can use AI to:

Detect → Correlate → Investigate → Respond

This creates an increasingly important principle:

Cybersecurity teams must be able to operate at the speed of the threat.

But speed alone is not enough.

A fast system that produces unreliable conclusions can create new risks.

The objective is therefore not simply to build faster AI.

It is to build reliable, explainable, auditable and appropriately controlled AI-assisted security systems.

From AI Detection to AI Defence

The future of cybersecurity is moving from systems that simply generate alerts toward systems that can understand context, connect events and assist with investigations.

For common users, this means recognising that convincing messages, voices and videos may no longer be reliable indicators of authenticity.

For organisations, it means combining AI-powered detection with strong identity, endpoint, network and data-security controls.

For police and LEAs, it means learning how AI can help analyse increasingly complex digital evidence while preserving investigative and evidentiary standards.

And for cybersecurity professionals, it means preparing for a world where attackers and defenders can both operate at machine speed.

The central question is no longer simply:

“Can AI detect a cyberattack?”

It is:

“Can we build a security system that can detect, explain, investigate and respond to AI-enabled threats without losing human oversight?”

That is the challenge of AI Threat Detection.

Day 2 — AI Threat Detection

31 Days | 31 Key Topics | October 2026

A Cybersecurity Awareness Month Knowledge Initiative

Created by Centre for Police Technology (CPT)

Follow Centre for Police Technology (CPT) for the complete 31-Day Cybersecurity Knowledge Series.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected