AI for Government
Aware · M20 · lesson 20 of 31 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
How AI Changes the Threat Landscape
📖
now learning

How AI Changes the Threat Landscape

10 min

Learning Objectives

After completing this lecture, you will be able to:

  • Understand the key concepts of how ai changes the threat landscape in a government context
  • Apply knowledge of deepfakes, automated phishing, voice cloning, social engineering at scale
  • Apply knowledge of what government workers face
  • Identify next steps for applying these concepts in your role

Key Topics Covered

  • AI-powered attacks: deepfakes, automated phishing, voice cloning, social engineering at scale
  • What government workers face
  • Government context for how ai changes the threat landscape
  • Practical applications and next steps

Why This Matters for Government

Government agencies face unique challenges when it comes to AI adoption. This lecture addresses these challenges head-on by providing all government employees with the knowledge and frameworks needed to navigate AI in the public sector responsibly and effectively.

As part of the L1 (AI Aware) curriculum, this lecture builds on the foundational principle that every AI system in government ultimately serves citizens. Whether you are working with AI tools daily or setting strategy for your agency, understanding how ai changes the threat landscape is essential for responsible, effective government AI adoption.

Lecture URL: https://skill.re/learn/govt/how-ai-changes-the-threat-landscape.php

======================================================================

TRANSCRIPT: How AI Changes the Threat Landscape

======================================================================

What you will learn: AI-powered attacks—deepfakes, automated phishing, voice cloning, social engineering at scale. How the threat landscape has changed.

Cybersecurity threats have always existed. But AI changes the nature of those threats. Attacks that once required significant resources and specialized skills can now be automated. Attacks that were theoretically possible are now practical and scalable.

This lecture is about understanding the new threat landscape. Not to make you paranoid, but to make you aware. Awareness is your first defense.

WHY THIS MATTERS FOR GOVERNMENT

Government agencies manage sensitive information, critical systems, and public trust. Threats to those things have consequences:

  • Breach of personal information affects citizens
  • Compromised systems affect public services
  • Loss of trust affects government legitimacy
  • Attacks on democratic processes affect democracy itself

Understanding AI-powered threats helps you defend against them.

NEW THREATS

A deepfake is synthetic media (audio, video, or images) created or manipulated by AI to appear authentic.

How Deepfakes Are Made:

AI models can now create convincing videos of people saying things they didn't say, doing things they didn't do.

"Here's video of the governor accepting a bribe." (Never happened—it's AI-generated.)

"Here's audio of the agency director admitting to fraud." (Never said it—voice is AI-cloned.)

Government Threats:

  • Eroding trust: If a video of a leader can be faked, how do citizens know which videos are real?
  • Impersonation: Criminals can impersonate officials to trick citizens or steal money
  • Disinformation: Deepfakes used to spread false information about policies, agencies, or decisions
  • Blackmail: Creating embarrassing deepfakes to extort officials

Why This Matters:

Deepfakes are getting better and easier to create. Five years ago, deepfakes were obviously fake. Now, they're harder to detect.

NEW THREATS

Phishing is when attackers trick people into revealing sensitive information or clicking malicious links.

Traditionally, phishing emails are sent by humans or simple scripts. They're generic, obvious, easy to spot.

AI changes this:

Personalized Phishing:

AI analyzes publicly available information about a person (social media, job title, organization, recent news). It generates highly personalized emails that reference specific details about that person's work or interests.

"Hi [name], I noticed your recent work on [project] in [article]. I have similar interests and wanted to share [malicious link]."

This is much more effective than generic phishing because it's targeted and credible.

Spear Phishing at Scale:

AI can generate thousands of personalized phishing emails simultaneously. An attacker could send targeted phishing to every employee at an agency.

Voice and Video Phishing:

AI can clone someone's voice or create deepfake video. Imagine getting a call from someone who sounds exactly like your supervisor asking you to transfer funds or send passwords.

NEW THREATS

Social engineering is manipulating people into revealing information or taking actions.

AI enables social engineering at scale:

Chatbot Impersonation:

An attacker uses an AI chatbot to impersonate a government agency or trusted organization, gradually building trust with a victim, then requesting sensitive information or access.

Sentiment Analysis and Manipulation:

AI analyzes individuals' online behavior and sentiment. It identifies people who are angry, frustrated, or more vulnerable to manipulation. It targets them with messages designed to manipulate their behavior.

Automated Relationship Building:

AI can conduct months-long conversations with a target, building trust gradually, before making a request for sensitive information.

ANTI-PATTERNS / MISUSE RISKS

Anti-Pattern 1: Assuming Official Media Is Authentic

You see a video of a government official. You assume it's real.

Risk: It might be a deepfake. You base decisions or spread information based on fake media.

Anti-Pattern 2: Trusting Links or Attachments from Unexpected Sources

Someone emails you a link from what appears to be a colleague or official.

Risk: It might be AI-generated phishing. You click it and compromise your system.

Anti-Pattern 3: Believing Voice or Video Without Verification

You get a call from someone who sounds like your supervisor. They ask you to do something unusual.

Risk: It might be voice cloning or deepfake. You take action based on false authority.

Anti-Pattern 4: Oversharing on Social Media

You post details about your work, interests, location, and relationships on social media.

Risk: Attackers use this information to craft highly personalized phishing or social engineering attacks.

PRACTICE / REFLECTION PROMPTS

  • Have you noticed an increase in phishing attempts or suspicious communications? What made them suspicious?
  • In your agency, what critical systems or information would be most valuable to an attacker?
  • How would you verify that a communication claiming to be from a senior official was actually authentic?

KEY TAKEAWAYS

  • AI-powered deepfakes are becoming more convincing. You cannot always trust videos or audio at face value.
  • Phishing is now personalized and more convincing. Attackers can craft emails that reference specific details about you.
  • Social engineering is conducted at scale. Attackers can target many people simultaneously with personalized manipulation.
  • Voice cloning is possible. Attackers can impersonate someone's voice.
  • Verification is critical. Verify important communications through independent channels (call the person directly, not using contact information from the suspicious message).

TERMS / GLOSSARY ITEMS

Deepfake: Synthetic media created by AI to appear authentic.

Phishing: Attempting to trick someone into revealing sensitive information by posing as a trustworthy entity.

Spear Phishing: Targeted phishing directed at a specific individual or organization.

Social Engineering: Manipulating people into revealing information or taking actions.

Voice Cloning: Using AI to create synthetic audio that mimics someone's voice.

You're a government employee. You receive an email from what appears to be your agency's IT department:

"Hi [your name], we've detected unusual activity on your account. Please click here to verify your password: [link]"

The email looks official. But is it real?

Check:

  • Call IT directly (using a number you know is correct, not from the email) and ask if they sent this
  • Check if the email address is the official IT email (even slightly misspelled addresses are suspicious)
  • Look for generic greetings ("Hi [your name]" instead of actual name) as a red flag
  • Hover over the link to see the actual URL (might not be the agency's domain)

Odds: This is phishing. Real IT departments don't ask for passwords via email links.

10 minutes.

Think about your current threat landscape:

  • What sensitive information do you have access to?
  • What would happen if that information was stolen?
  • What would happen if an attacker impersonated you or your agency?
  • What's one action you could take to reduce that risk?

The threat landscape has changed because AI has made attacks easier and more effective. But awareness of these threats is your defense. Be skeptical. Verify. Don't assume media or communications are authentic without checking.

Government AI CLUB Certification Program

Level 1: AI Aware | How AI Changes the Threat Landscape | Lecture 4.1

A GOVT.CLUB initiative.

<- 1.3.6 AI Confidence and Hallucination 1.4.2 Recognizing AI-Generated Threats ->

Start Your CLUB Certification

This lecture is part of L1: AI Aware—8 hours of comprehensive government AI training.

Explore CLUB Certification

L1 1.4.2—Recognizing AI-Generated Threats 10 min - Video + Exercises

L1 1.4.3—Data Leakage: When Sensitive Info Enters AI 10 min - Video + Scenarios

L1 1.4.4—Approved vs. Shadow AI 10 min - Video + Policy

Frequently Asked Questions

What will I learn in How AI Changes the Threat Landscape?

In this 10 min video lecture, you will AI-powered attacks: deepfakes, automated phishing, voice cloning, social engineering at scale. What government workers face

What level is How AI Changes the Threat Landscape?

This is a Level 1 (AI Aware) lecture, part of Chapter 1.4 \u2014 Safety and Security. It is designed for all government employees.

How long is lecture 1.4.1?

Lecture 1.4.1 (How AI Changes the Threat Landscape) takes 10 min. It is delivered as a video format.

Do I need prerequisites for How AI Changes the Threat Landscape?

This lecture is part of L1 (AI Aware). Prerequisites: None.

What is the CLUB Certification?

CLUB (Community Leading Unified Benchmarks) is a maturity-based AI certification for government professionals with 5 levels (L1-L5), 215 lectures, and 25 chapters aligned with NIST AI RMF, OMB, and GAO frameworks.