AI Lowers Cybercrime Barrier; Security Experts Warn UAE Residents on New Threat Landscape
Dubai Life

AI Lowers Cybercrime Barrier; Security Experts Warn UAE Residents on New Threat Landscape

Cybersecurity teams race to defend against AI-accelerated attacks in the UAE.

Tech expert Yassin Watlal, Senior Director of Systems Engineering for the Middle East, Turkey and Africa at CrowdStrike, puts it plainly: cybercriminals no longer need sophisticated skills to cause serious damage. AI has done the work of lowering the barrier for them.

That operational reality sits at the center of a broader conversation about artificial intelligence risk, one that has shifted noticeably in character. The most forceful cautions no longer come exclusively from outside critics. Anthropic chief executive Dario Amodei has cautioned that frontier AI development may require deceleration, contending that safety systems and independent oversight need adequate time to advance in parallel. Sam Altman of OpenAI, Demis Hassabis of DeepMind, and Elon Musk have similarly endorsed more stringent safeguards for increasingly sophisticated systems. Current and former AI researchers have issued progressively sharper warnings as models gain greater autonomy.

The language can appear extreme. Certain researchers discuss systems capable of self-improvement, operation with reduced human supervision, or resistance to control. Others focus on risks already visible today, spanning AI-assisted cybercrime to agents that can write code, use tools, and execute multi-step tasks. For the general public, these concerns often collapse into a single alarming concept: AI risk.

Some dangers are already present. Others are emerging at the frontier. The most severe scenarios remain theoretical. This distinction carries real weight in the UAE, where artificial intelligence is being adopted rapidly across government operations, business sectors, and daily life.

Cybersecurity offers the clearest picture of what AI risk looks like in practice right now. “AI has dropped the barrier of entry for a lot of the threat actors,” Watlal told Khaleej Times. “The less sophisticated actors now can do things that they were not able to either do, or it would take a lot of time.”

This does not mean criminals are inventing entirely new attack methods. In many cases, AI is accelerating existing techniques and making them more convincing. Phishing messages arrive in polished language, customized for specific individuals or regions. Voice is deployed for impersonation. Malware is generated faster. And the steps following initial system access can now unfold much more quickly.

Attackers increasingly prefer not to force entry when they can simply obtain valid credentials. “They will want to log in, not break in,” Watlal said. CrowdStrike reports that the average time for cybercriminals to move from initial compromise to other parts of an organization decreased to 29 minutes in 2025, with the fastest observed case requiring just 27 seconds.

For security teams, that compression is consequential. An attack can propagate through a network before personnel finish investigating the first suspicious alert. AI is being deployed on both sides of this conflict: attackers automate operational components, while defenders increasingly need AI to investigate alerts and respond at comparable speed.

Meanwhile, the industry is shifting focus toward agents, a more difficult-to-perceive category of concern. Most people first encountered generative AI through a chatbot, where a typed query produced an answer and the interaction ended. The current trajectory involves systems assigned an objective and permitted to take multiple steps toward completing it, potentially writing code, searching information, calling other software, analyzing files, or performing actions using external tools.

This creates a fundamentally different safety problem. A chatbot can produce a wrong answer and the interaction stops there. An agent can transform a wrong decision into an action with real consequences.

That ambition does not mean AI will suddenly make every government decision independently. But it makes questions about permissions, human oversight, and system security considerably less theoretical. What information can the agent access? What actions can it take without requesting human approval? What happens if it misinterprets a task? How quickly can a human intervene?

These are increasingly practical questions for companies. Watlal said businesses need to consider not only defending themselves against criminals using AI, but also securing the AI systems they deploy internally. “What can we ask the AI to do safely and then put guardrails around it?” he said. This becomes more critical as AI systems connect to company data, internal tools, and automated workflows.

Some frontier AI researchers express concern about a future where systems become capable enough to substantially contribute to developing their own successors. AI already assists engineers in writing code, analyzing research, and performing components of work involved in building newer models. The concern centers on what could occur if that assistance became significantly more autonomous, and systems began accelerating development of even more capable systems.

This is where discussions about recursive self-improvement, superintelligence, and loss of human control emerge. There is no scientific consensus that such a process will occur, when it might happen, or whether future AI systems would behave in the catastrophic ways some researchers fear. That uncertainty is precisely what divides the industry.

One perspective argues that potential consequences could be so serious that waiting for proof would mean waiting too long. The other warns against slowing a technology with enormous economic and scientific potential because of scenarios that remain speculative. Even among those who agree stronger safeguards are needed, disagreement exists over how far to go. For more detailed context on these concerns, see https://www.khaleejtimes.com/uae/ai-risk-uae-residents-should-do-industry-concerns.

Calls to slow down AI development generally do not mean deactivating existing systems or asking people to stop using them. Proposals under discussion include stronger independent evaluations, more time between major capability jumps, better testing before release, greater coordination between frontier laboratories, and clearer rules around what highly capable systems should be permitted to do.

For most UAE residents, the immediate response is far less dramatic than warnings about future AI might suggest. Current risks deserve attention precisely because they are less spectacular and already occurring.

AI-assisted fraud, impersonation, and cyberattacks are happening now. Watlal recommends enabling multi-factor authentication on personal accounts, verifying unexpected requests through a separate channel, and pausing before approving a login or clicking a link. “Things go so quickly in life that quite often we respond to something that then we regret, or we approve something that then we regret,” he said.

For businesses, the issue extends further. Companies adopting AI agents need to determine what information those systems can access, what actions they can perform, and where human involvement must remain mandatory. Watlal emphasized that the human role remains critical, particularly for judgment, context, and accountability.

The broader AI debate separates into two distinct questions. The first is already present: how should people protect themselves from criminals and organizations using increasingly capable AI today? The second is considerably harder: how much independence should society eventually grant to AI systems themselves? The people building the technology do not agree on the answer, but what has changed is that some of them increasingly believe society should start asking that question before the most powerful systems arrive.

Q&A

How has AI changed the operational capability of cybercriminals?

AI has lowered the barrier of entry for threat actors, enabling less sophisticated attackers to execute techniques that previously required advanced skills or significant time. Attackers now use AI to generate polished phishing messages, deploy voice impersonation, create malware faster, and accelerate post-compromise lateral movement.

What is the current timeline for attackers to move laterally after initial system compromise?

CrowdStrike reports that the average time for cybercriminals to move from initial compromise to other parts of an organization decreased to 29 minutes in 2025, with the fastest observed case requiring just 27 seconds.

What security measures does Yassin Watlal recommend for individuals?

Watlal recommends enabling multi-factor authentication on personal accounts, verifying unexpected requests through a separate channel, and pausing before approving a login or clicking a link to avoid regrettable decisions made in haste.

What guardrails do businesses need to establish for internal AI systems?

Companies must determine what information AI agents can access, what actions they can perform without human approval, and where human involvement must remain mandatory, particularly for judgment, context, and accountability.