
Mimecast’s State of Human Risk 2026 study finds 65% of surveyed APAC IT see an AI-enabled attack against their organisation as inevitable.
Mimecast has released new research showing that Asia Pacific organisations widely expect artificial intelligence (AI) to be used in attacks against them, while many remain unprepared for threats that exploit human judgement.
The company’s State of Human Risk 2026 study, based on responses from 500 IT security and IT decision-makers across Singapore and Australia, found that 65% believe an AI-enabled attack against their organisation is inevitable within the next 12 months, and 79% said they are worried about AI being used as an attack vector.
Despite that concern, 60% of respondents said their organisation was not fully prepared to handle AI-driven threats that exploit human vulnerabilities, including 52% who described themselves as somewhat prepared but still developing AI-specific defence strategies, and 9% who were aware of the threats but lacked a concrete strategy.
Employees were identified as a particular point of exposure, with 66% of respondents agreeing that an employee at their organisation was very likely to be fooled by a cybercriminal using AI in a social engineering attack.
Preparation gaps extend to training: only 40% of surveyed organisations provide training on using AI while avoiding exploitation, and 42% run simulated AI-driven phishing attacks. Mimecast says this does not necessarily mean other cybersecurity training is absent, but indicates many organisations have yet to introduce measures specifically addressing AI-enabled threats.
It points to a broader need to treat human judgement as a core part of cyber defence alongside technical controls as AI blurs the line between legitimate and malicious communication.
Nicky Choo, Vice President and General Manager, APAC, at Mimecast, said: “Attackers can now use it to create convincing, tailored messages that appear to come from a colleague, a partner or a senior leader, which means employees are being asked to make difficult decisions in real time. The challenge is no longer just stopping threats before they arrive. It’s helping people recognise when the interactions they rely on may have been manipulated.”
Read the report here.
Stay updated on crypto and AI by following our socials.


