For many years, organisations have invested heavily in protecting their people, information, and physical and digital assets. Artificial intelligence is now reshaping one of the oldest security challenges: social engineering.

While deepfakes have attracted significant attention for their ability to generate convincing synthetic images, videos, and voices, they represent only one component of a broader evolution. The more significant development is AI-assisted social engineering—where artificial intelligence enables the systematic exploitation of context and human behaviour with unprecedented precision.

From Deception to Trust Engineering

What AI changes is not the underlying technique of social engineering, but the ability to personalise and scale it with remarkable efficiency.

Rather than relying on generic approaches, publicly available information can be used to tailor communications around an individual's professional role, travel itinerary, recent activities, colleagues, and communication style.

The result is a shift from simply impersonating individuals to recreating the context, familiarity, and relationships that underpin trust, making fraudulent interactions appear increasingly genuine.

Deepfakes as a Force Multiplier

Deepfake technology significantly enhances this threat by adding familiarity and credibility to deception.

Consider a business traveller who receives a voicemail from what appears to be their manager. The voice is immediately recognizable. The message references the conference they are attending and requests that they “quickly approve a payment” or “confirm a verification code” because an urgent issue has arisen at headquarters.

Nothing about the request appears technically suspicious. The influence comes not from the information itself, but from the confidence created by a familiar voice combined with relevant context.

Increasingly, audio or video replicas do not need to be flawless to be effective. Under conditions of fatigue, distraction, or limited time, a convincing voice combined with accurate contextual information may be sufficient to reduce an individual's natural scepticism.

Social engineering often succeeds by exploiting normal human decision-making patterns. Urgency, authority, fear, and familiarity can influence judgement, particularly when individuals believe that delaying action may create negative consequences. A request framed as an urgent matter from a trusted colleague or executive may bypass normal verification processes because the perceived cost of delay appears greater than the need to question the request.

The Scaling of Human Manipulation

Historically, sophisticated social engineering required considerable time and effort. That limitation is changing.

Artificial intelligence can rapidly gather publicly available information, analyse communication patterns, generate convincing messages, and adapt conversations in real time. What was once reserved for carefully selected, high-value targets can now be deployed against hundreds of individuals simultaneously.

Why Travellers Are Particularly Vulnerable

Business travellers represent an attractive target because they often operate outside their normal routines. Long journeys, unfamiliar environments, changing time zones, and constant reliance on digital communication reduce the opportunity to verify unexpected requests.

A message or phone call that would raise concerns in the office may appear entirely reasonable while travelling, particularly if it references current meetings, travel plans, or colleagues.

These situations are effective not because technology has been compromised, but because they exploit the conditions in which people are more likely to make rapid decisions.

Preparing for the Next Generation of Social Engineering

Traditional awareness programmes have focused on recognising suspicious emails and malicious links. While these remain important, future resilience will require organisations to place greater emphasis on verifying trust itself.

This includes establishing independent verification procedures for sensitive requests, encouraging staff to question unexpected urgency regardless of the source, and recognising that familiar voices, faces, or writing styles are not sufficient evidence of authenticity.

The Strategic Challenge

As artificial intelligence continues to reduce the cost of creating convincing, personalised interactions, one of the most valuable security skills will no longer be simply recognising deception, it will be understanding that trust itself can now be engineered.