Preprint
Concept Paper

This version is not peer-reviewed.

The Human Layer as Primary Cyber Battlefield: Defending Trust, Identity Against Autonomous AI Threats

Submitted:

30 June 2026

Posted:

02 July 2026

You are already at the latest version

Abstract
While traditional cybersecurity has focused on networks, endpoints, applications and data, the rise of autonomous AI systems is shifting adversarial activity toward human cognition, trust and decision-making. The emergence of systems such as Anthropic’s Mythos signals a broader inflection point in which machines can autonomously identify vulnerabilities, generate exploits and accelerate cyber operations with minimal human input. The human layer becomes increasingly vulnerable to AI-enabled manipulation including synthetic identities, deepfake personas, hyper-personalized phishing and real-time social engineering as technical attack timelines compress from weeks to hours. Defending the human layer requires moving beyond passive awareness training and static security controls toward active and edge-computed autonomous defense. Such systems must be capable of detecting suspicious interactions, verifying identity claims, interrupting coercive or deceptive workflows and preserving user agency without becoming opaque or paternalistic. Cybersecurity must defend human agency against rapid threats instead of merely protecting systems and data.
Keywords: 
;  ;  ;  ;  ;  ;  ;  

1. Introduction

The Mythos example provides a useful signal event for understanding the next stage of cybersecurity which will be driven by AI. Claude Mythos represents a technical advance in vulnerability research as well as a broader systemic shift. Frontier AI systems are now capable of the autonomous identification of unknown vulnerabilities with relevant artifacts and accelerating cyber operations beyond the speed of traditional security programs (Campbell, 2026; Goldstein, 2026; Pesoli et al., 2026). This suggests the significance of Mythos is not limited to the discovery of one particular flaw, but rather its importance lies in the operational pattern it represents. AI can currently perform security code review, vulnerability discovery, vulnerability report preparation, and exploit demonstration at machine speed which establishes that cybersecurity is evolving to be less episodic and more continuous. The defender is no longer responding only to periodic vulnerability disclosures or incidents. The defender is now entering a high-velocity contest in which discovery, exploitation, triage, remediation, and manipulation occur within compressed timeframes.

1.1. From Network Defense to Cognitive Defense

This shift challenges a foundational assumption of conventional cybersecurity. Traditional network defense has often depended on time to detect anomalous behavior, investigate alerts, validate vulnerabilities, and perform remediation. However, Mythos-class capabilities challenge that assumption by compressing the interval historically provided to incident management. Pesoli et al. (2026) describe this through the lens of “bugonomics” by emphasizing that the current impact of LLM-assisted vulnerability discovery is a change in the throughput of vulnerability production and remediation rather than only additional zero-days. Their analysis shows that AI can increase candidate vulnerability reports at machine speed while vulnerability management does not automatically scale at the same rate. This infers Mythos is best understood as an inflection point in defender workload and operational tempo which reveals a mismatch between the speed of AI vulnerability generation and the existing speed of remediation and incident management.
A simple interpretation would regard Mythos as a warning about exploits and patch management alone. While those concerns are accurate, they do not represent the actual significance of the shift. AI-enabled vulnerability identification also alters the approach used to make security decisions. Adversarial systems empowered with AI are also becoming more capable of social engineering. The AI ecosystem can industrialize deception, synthesize convincing identities, generate deepfake media, personalize phishing, and adapt social engineering to individual targets. Bailo et al. (2026) describes this as “industrialization of deception” of AI while arguing that generative models can compress attack cycles during targeted social engineering operations. This makes the human layer a core security domain.
The movement from network defense to cognitive defense does not mean that infrastructure and applications are no longer important. Instead, it means that these technical components are increasingly intertwined with human perception. A compromised system may begin with an unpatched vulnerability, but it also can begin with a believable message, deepfake media, a or a forged identity claim that results in a person overriding normal caution. Kelley et al. (2026) finds that generative AI empowers both attackers and defenders while increasing the scale and speed of attacks and lowering the barrier to producing harmful content such as deepfakes. The cyber battlefield expands from the technical environment into the space in which people make decisions including whether a message is authentic or a caller is legitimate.
This is the basis for treating the human layer as a component of the cyber battlefield. The human layer includes trust, identity, attention, emotion, and decision-making. These psychological concerns are now operational attack surfaces. Trust determines whether users accept instructions, or follow links. Identity determines whether a person or system is recognized as legitimate. Attention determines whether warning signs are noticed or ignored. Emotion determines whether urgency, fear, or empathy can be weaponized. Decision-making determines whether a technical control is followed or overridden. The improvement in the ability of AI systems to simulate humans make these human-layer functions increasingly targetable at scale.
Cognitive defense must therefore be understood as a needed expansion of cybersecurity to defend the conditions under which people make security-relevant decisions. Conventional awareness training is not sufficient when adversarial AI can generate persuasive interactions in real time. Periodic education and security processes may help establish baseline caution, but they cannot fully protect users against social engineering empowered with to evolve dynamically as the target responds. A cognitive defense posture must provide the ability to verify identity claims while detecting suspicious interaction patterns, and supporting human judgment before harm occurs.
The defensive implications are substantial. AI is necessary on the defensive side because the threat environment is evolving too fast and too adaptive for manual response alone. Rafi’s (2026) review of generative AI in cybersecurity found that generative models can support automated vulnerability discovery and patch generation through patterns in code and accelerating response workflows. Khurram (2026) also emphasizes that AI can improve adaptive defense and real-time detection while also acknowledging that AI contributes to an arms race involving variations of malware and zero-day exploit capabilities. These findings support the conclusion that defenders must augment human judgment with systems capable of operating at machine speed instead of replacing human judgment with AI.
Mythos signals the acceleration of technical exploitation, but it is critical to recognize the important transformation is cognitive. A struggle over whether humans can continue to recognize trustworthy interactions inside a machine-speed threat environment is being introduced to cybersecurity. The next phase of cybersecurity must defend not only systems and data along with the human capacity to judge, verify, consent, refuse, and act with autonomy.

3. Conceptual Framework: The Human Layer as Attack Surface

The human layer is the conceptual center of AI-driven cybersecurity because it is where technical systems, institutional processes, and individual judgment meet. The “user” is often treated as a point of failure in conventional cybersecurity. The human layer must be understood as an attack surface in its own right in an AI-enabled threat environment. It includes attention, trust, emotion, decision-making, authority response, fatigue and overload, and interface behavior. These are operational surfaces that adversaries can exploit.
Attention is the first exposed surface with attackers exploiting the fact that users often make decisions while multitasking across platforms and devices. AI increases the ability of attackers to craft messages that appear relevant. Personalization allows malicious content to blend into the normal user environment. Daoud et al. (2026) describe phishing as an adaptive and damaging cybersecurity threat that increasingly exploits human behavior as well as technical vulnerabilities. Attention is not just a condition of security awareness in this sense.
Trust is the second and most important surface. Social engineering has always depended on trust, but generative AI changes how trust can be manufactured. Gonzaga et al. (2026) identify realism and personalization as core AI-enabled capabilities that amplify social engineering. Realism increases message plausibility and emotional resonance while personalization improves target selection and persuasion. These capabilities enable what Ashraf (2026) calls Synthetic Trust Attacks which are campaigns in which adversaries deliver trust cues such as identity simulation, contextual plausibility, and authority indicator mimicry. The attack surface in this model is the decision of the victim under conditions of manufactured trust.
Emotion is the third surface. Traditional social engineering exploits fear, urgency, obligation, empathy, shame, and opportunity. AI makes these emotional triggers easier to calibrate as AI-generated messages can be tuned to the role of the recipient and contextual circumstances such as relationships and recent activity. Gonzaga et al. (2026) note that AI-powered social engineering builds on emotional manipulation by combining realism and automation. Ashraf (2026) similarly emphasizes that decision-making can shift under time pressure and emotional manipulation increasing susceptibility to authority and social-proof cues. The emotional dimension of the human layer therefore becomes a security domain.
Identity recognition is the fourth surface. People rely on familiar markers of identity including names, voice, face, organizational title, phone number, and image. Jadala (2026) explains that attackers can now create realistic fake identities with cloned voices and manipulated videos that imitate trusted individuals. Ferrara (2026) expands this concern by arguing that generative AI enables synthetic realities in which identity and interaction are jointly manufactured. Users can no longer rely on recognition alone as verification when identity cues are easy to synthesize.
Decision-making is the fifth surface. The decisive moment in AI-enabled social engineering is the moment the target acts. Ashraf (2026) argues that the real attack surface is the decision of the victim while existing defenses often focus on detecting synthetic media. A user may know that deepfakes and phishing exist but still comply if the specific situation appears credible. The Synthetic Trust Attack Model by Ashraf (2026) describes “decision compression” as the reduction of the effective verification window of the victim through urgency and authority framing. The goal of the attacker is to prevent reflective judgment long enough to induce a target action.
Authority response is the sixth surface. Organizations depend on authority structures to function with employees expected to respond to managers, executives, and other personnel based on context. AI-enabled attackers can exploit that structure by simulating authority and placing the target inside a plausible chain of command. Deepfake impersonation with fraudulent requests, and synthetic pressure all can use authority as a compliance mechanism. Ashraf (2026) identifies authority, urgency, secrecy, fear, and social proof as key triggers in synthetic trust attacks. The human vulnerability here is the habit of responding to legitimate authority within institutional workflows.
Social habit is the seventh surface. People develop routine patterns for handling digital requests such as approving calendar invitations and replying to supervisors. These habits reduce cognitive burden and help organizations operate efficiently, but create predictable behavioral pathways. Generative AI can exploit these pathways by imitating the routine as malicious requests become more persuasive when they do not feel exceptional. Ali et al. (2026) emphasize that social engineering attacks exploit human behavior to bypass technical controls and gain unauthorized access. Adaptive identity and access management responds to this problem by continuously evaluating behavior and access patterns rather than assuming that a login or request is trustworthy because it fits a static rule.
Fatigue and overload form the eighth surface. Security decisions are rarely made in ideal conditions as users are often distracted and overloaded. Beg (2026) argues that AI-driven risks extend beyond discrete software vulnerabilities into cognitive and behavioral domains such as cognitive hacking and manipulation. Fatigue matters because it lowers the practical threshold for manipulation. Even well-trained users may fail when verification requires effort during stress or information overload. The problem is the mismatch between human cognitive capacity and adversarial optimized interaction rather than simply lack of awareness.
Interface behavior is the ninth surface. Login screens, chat windows, email clients, browsers, and many other interfaces shape what the user sees and notices. Fan et al. (2026) show that the human-AI interface itself can become an exploitable attack surface. Their work on adversarial attacks demonstrates that attackers may manipulate the framing of AI-generated explanations to preserve user trust. Interface-level cues such as tone and presentation can influence whether users trust or comply.

4. AI-Enabled Threat Model

A conceptual understanding of the human layer becomes actionable when examining how AI-enabled adversaries operationalize these vulnerabilities. Modern attacks increasingly manipulate trust, identity, authority and human judgment rather than targeting software alone. The following sections examine the primary categories of AI-enabled threats that exploit the human layer.

4.1. Synthetic Personas and Cognitive Capture

Synthetic personas mark a major escalation in AI-enabled cyber risk because they move deception from isolated content into sustained interaction. A deepfake video or cloned voice is a credibility mechanism that allows the attacker to appear as someone the target recognizes and trusts. Synthetic personas enable cognitive capture in which the perception and decision-making of the target become shaped by an artificial identity that appears real. The attacker occupies the interpretive environment of the user and makes the fraudulent interaction feel authentic.

4.2. Hyper-Personalized Phishing

AI-enhanced attackers actively exploit human-computer interaction vulnerabilities. A phishing email can become an adaptive and personalized attack against the judgment of the user. Generative AI enables attackers to be more realistic by producing fluent language that imitates organizational tone across contexts with personalized messages containing persuasive content (Jadala, 2026; Gonzaga et al., 2026). This changes the phishing problem from message detection to interaction defense.

4.3. Adaptive Voice Phishing and Real-Time Social Engineering

The rise of adaptive voice phishing illustrates the convergence of these surfaces. Yang et al. (2026) introduce VishBox as an AI-agent-based framework for simulating voice phishing interactions with an emphasis that real attacks are psychologically adaptive and unfold through attacker-victim interaction. Voice phishing is especially important because it combines identity recognition with emotional pressure and authority response. A written phishing email can be paused and inspected while a live voice interaction pressures the user to respond in sequence.
Static awareness training is insufficient if attackers can imitate identity while simulating authority. Technical controls must be paired with safeguards that protect decision-making under pressure. Behavioral analytics, adaptive access control, identity verification, and escalation protocols all matter because they shift defense from the message layer to the interaction and decision layers. Hussain and Akhtar (2026) argue that AI-based behavioral analysis can strengthen phishing detection and secure access control by continuously monitoring login patterns and interaction behavior. Ali et al. (2026) similarly argue that adaptive identity and access management can dynamically adjust authentication and access privileges based on real-time risk.
The core argument of this section is that AI-enhanced cyberattacks increasingly target the conditions under which humans decide. The path to compromise for an attacker may run through attention, trust, emotion, identity recognition, decision-making, authority response, social habit, fatigue, overload, and interface behavior. A social engineering attack such as a phishing email or deepfake call is a designed interaction that seeks to shape perception. The human layer is the battlefield because it is where technical access and human interaction converge.

4.4. Romance and Investment Scams

These types of scams demonstrate cognitive capture over a longer timeline. Han and Button (2026) describe “pig butchering scams” as hybrid romance-investment fraud in which scammers create relationships while building trust to escalate toward financial exploitation. AI can intensify this model by helping criminals generate convincing profiles and maintain long-term conversations with tailored scripts to invoke emotional responses from the victim. The result is a sustained relationship simulation that captures the affections and financial judgment of the target.
Investment fraud often us deepfake advertisements and cloned celebrity endorsements to make fraudulent schemes appear legitimate. Adegoke and Adegoke (2026) examine AI-enabled fraudulent schemes in digital finance with voice cloning and deepfake impersonation to connect these threats to consumer trust in digital financial adoption. Lui and Miglionico (2026) also warn that deepfakes can distort information used in financial decision-making and may make romance scams more convincing by manipulating images or videos of trusted people. The core harm is that the false content is embedded in a trust-building process designed to make financial risk feel socially validated.

4.5. Financial Fraud and Authentication Bypass

Cognitive capture occurs when these synthetic signals align. A target may see a familiar face or hear a trusted voice which triggers urgent emotional pressure within a familiar interface. Each cue reinforces the others. The goal of the attacker (Figure 1) is to close the space for doubt by making the interaction feel authentic enough that verification seems unnecessary or even inappropriate. This is why deepfake personas are especially dangerous in organizations. A well-designed synthetic interaction makes compliance feel like the correct decision.

4.5.1. Deepfake Video Authentication Bypass

Rahat et al. (2026) argue that deepfake-enabled identity abuse has become an operational threat in U.S. banking targeting risky activities such as contact-center authentication and high-risk payment authorization. They describe blended attacks that combine forged identity documents, face or voice cloning, and social-engineering pressure across channels. This is why appearance cannot function as proof. Njuguna (2026) notes that deepfake technologies can convincingly replicate human appearance and speech which creates opportunities for identity impersonation and financial fraud through social engineering. Yogatama and Rimbawa (2026) similarly argue that deepfake content challenges authenticity and security by enabling fraud and identity manipulation. The implication is that authentication must move from recognition to corroboration. Defenders must evaluate whether identity signals corroborate one another across devices and behavior.

4.5.2. AI-Generated Executive Impersonation

Deepfake-enabled fraud can simulate the voice and face of senior leaders. Bociga and Lord (2026) describe the widely reported Arup case in which a finance employee joined an online meeting that appeared to include the chief financial officer of the company and other staff to later discover that the participants were synthetic and the payment instruction fraudulent. Lui and Miglionico (2026) similarly note that deepfakes are increasingly used in video calls to impersonate senior corporate staff and persuade employees to process fraudulent payments. These cases show that executive impersonation no longer depends only on forged email headers or urgent text requests.
A deceptive message can be followed by a cloned voice call or a synthetic video confirmation that mirrors the tone and urgency of a real executive. Akram et al. (2026) argue that deepfake social engineering attacks exploit human trust using synthetic audio and video to impersonate trusted individuals. The vulnerability lies not only in email security or payment controls, but in the credibility of interaction. The employee is placed inside a simulated authority relationship.

4.5.3. Fake Customer Support Agents

This represents a related form of synthetic persona risk. A fake support agent may guide a target through credential disclosure, remote-access installation, or other social engineering paths under the appearance of assistance. Erickson (2026) describes the “Fake Friend Dilemma,” in which users place trust in conversational agents that appear supportive while potentially serving interests misaligned with the interests of the user. Humanlike and helpful the interfaces make it the easier to weaponize trust.

4.5.4. Cloned Family-Member Voices

Cloned family-member voices show how synthetic personas can exploit intimate trust rather than institutional authority. Voice cloning allows attackers to imitate a relative in distress which creates a strong emotional demand for immediate action. The experimental study of Canyakan (2026) found that participants correctly identified cloned voices only 60% of the time with real voices being identified with 70% accuracy. This suggests that auditory recognition alone is not a reliable defense. Oh et al. (2026) similarly emphasize that deepfake scams often involve impersonating family members in distress to coerce urgent financial transfers and that awareness alone may not be enough when scams exploit emotional urgency and social trust. These findings show that family-voice scams trigger care and panic.

4.5.5. AI-Generated Writing-Style Mimicry

This creates another synthetic-persona pathway. Attackers can imitate the tone of leadership and other figures making fraudulent communication appear ordinary and familiar. Gonzaga et al. (2026) explain that AI-generated messages can display contextual awareness and persuasive language which enables attackers to compose targeted messages tailored to the victim and recent activity. Abdulhamed et al. (2026) show that distinguishing human-generated from AI-generated text has become an important research problem because modern language models produce increasingly humanlike writing. Luttrell et al. (2026) similarly find that humans struggle to detect synthetic text which underscores the difficulty of relying on unaided judgment to evaluate the authenticity of text.
The defensive implication is that cybersecurity must shift from identity as a static credential to authenticity as an interactional condition. A secure device and authorized login do not prove that the person using them is acting accurately or without manipulation. A video meeting does not prove that the participants are genuine. Security must ask whether the interaction itself is trustworthy and whether the human decision-maker is being coerced in the AI era.
This requires layered defenses. Technical detection remains necessary but must be paired with workflow redesign. High-risk actions should require additional verification including out-of-band confirmation, delayed execution, multi-person approval, verified callback procedures, and escalation paths for emotionally charged requests. Rahat et al. (2026) argue that effective defense against deepfake identity abuse requires fusion across identity proofing, authentication, and behavioral analysis rather than reliance on a single biometric or score. The future of human-layer cyber defense depends on corroboration rather than appearance alone.
Synthetic personas reveal why the human layer is now a primary battlefield. The attacker no longer needs to defeat every technical control if the attacker can manufacture the relationship or authority structure that causes a legitimate user to act. Cognitive capture is the moment when the attention of the target is redirected through a believable artificial identity. Defending against this threat requires a new security posture that protects the authenticity of interactions and the integrity of human judgment.
Table 1. The Defense Matrix.
Table 1. The Defense Matrix.
Dimension The Flawed Paradigm: Recognition The Resilient Paradigm: Corroboration
Core Focus Static appearance and speech evaluating holistic cross-channel alignment
Vulnerability Bypassed by synthetic audio or video cloning Screens for behavioral anomalies and device spoofing
Identity Proof Face, voice and ID verification Multi-factor behavior and network data synergy
Primary Risk High-risk payment authorization exploitation Operational threat containment at contact centers

5. Proposed Defense Architecture

Edge-Computed Autonomous Defense for the Human Layer

The defense must move closer to the human as the AI-enabled offense increasingly targets the human layer. Centralized security tools are not sufficient for attacks that unfold inside ordinary interactions such as a browser session or a video call. Human-layer attacks often occur before a conventional security system can classify them as malicious. The next stage of personal cybersecurity should include edge-computed autonomous defense agents embedded directly into the digital environments where people make decisions.
An edge-computed defense model places protective intelligence on or near the device of the user in browsers, phones, laptops, and other devices and applications. The goal is to create a local protective layer capable of noticing human-layer risk at the moment of interaction. A local agent can detect unusual behavioral patterns such as a user receiving unusual payment pressure or that a video call contains synthetic-media indicators.

5.1. Browser-Based Defense

The browser is one of the most important locations for this architecture because it is where many human-layer cyberattacks converge. Web-use agents and browser-based automation can act on behalf of users as they navigate sites. Shapira et al. (2026) show that browsers contain serious attack surface when malicious instructions are embedded in web content including advertisements. Their work demonstrates that browsers can be redirected through injection where malicious guidance appears helpful rather than hostile. A browser-based personal defense agent should check URLs and block known phishing domains while also evaluating whether the interaction itself is being steered. This could include redirecting the user to an unrelated payment flow or encouraging a user to perform an action inconsistent with the original task.

5.2. Device-Level Defense

Phones and laptops should become the second layer of edge defense because they contain the behavioral context needed to detect manipulation. Local defense agents can observe cross-application patterns that centralized point solutions may miss. Xu and Li (2026) argue that users experience privacy and digital risk across fragmented contexts and that agentic AI may help bridge those fragments through cross-boundary privacy management. A user-centered defense agent should be able to connect the dots across apps while still respecting privacy constraints.

5.3. Messaging Platform Defense

Messaging platforms are another crucial site for edge-computed defense. Many attacks occur conversationally including AI-enabled phishing, romance fraud, family-member impersonation, and fake customer-support attacks. A local defense agent embedded in messaging could detect markers of coercion or manipulation including escalating urgency and payment pressure. The role of the agent would be to perform local pattern recognition and intervene only when risk thresholds are met. Possible interventions include warnings, delays, and suggested verification steps.

5.4. Banking Application Defense

Banking applications are a particularly important deployment point because many AI-enabled scams seek financial action. A banking-edge defense agent could evaluate whether a payment request matches normal user behavior and other behavioral indicators such as unusual communication patterns and suspicious urgency. Odeyinka et al. (2026) show that behavioral authentication and continuous risk monitoring can improve real-time detection and trust evaluation in zero-trust environments. This suggests a defense model in which a payment is evaluated by whether the user successfully logged in as well as whether the transaction context remains trustworthy.

5.5. Password Manager Defense

Password managers could become another form of local defense. They already help prevent credential reuse and reduce exposure to phishing by matching credentials to legitimate domains. A password manager could detect when a login page resembles a trusted service but appears in an unusual workflow such as when the use of a password follows suspicious messaging. Yang (2026) proposes a safety-interception framework that sits between an AI agent and its tools to produce a structured verdict of allow, warn, block or review before actions are executed. A human-layer password manager could operate similarly to evaluate whether credential use should be allowed.

5.6. Edge-Based Autonomous Agents

Edge defense also supports proportional intervention. Not every suspicious interaction should be blocked. Some should be allowed with logging, some should require out-of-band confirmation, and some should be stopped. The allow-warn-block-review model of Agent Trust provides a useful vocabulary for this kind of graded response (Yang, 2026). A personal defense agent should be able to distinguish between low-risk uncertainty and high-risk manipulation. A new contact asking for a meeting may only require a reminder. A new contact asking for identity documents may require verification. A known contact asking for a wire transfer through an unusual channel may require a hard stop until confirmed through a trusted path.
This framework should be autonomous but not paternalistic. The purpose of edge defense is to preserve user agency instead of overriding it. The user should remain able to review, contest, and learn from these interventions. The best model is not silent control but explainable friction to protect judgment under pressure without making the system unusable or coercive.
The architecture should combine local intelligence with selective escalation with local agents that can detect and act on immediate context. Centralized systems can provide threat intelligence including known scam patterns. Digital identity ecosystems can provide verifiable credentials. Financial institutions can provide transaction-risk signals. Messaging platforms can support verified contact channels. The key design principle is that raw personal context should remain local whenever possible.
Edge-computed autonomous defense also fits the broader shift toward zero trust. Zero trust assumes that no device, identity, or network location should be trusted by default. Odeyinka et al. (2026) extend this logic to AI-governed infrastructures through continuous authentication and conditional access with dynamic trust evaluation and real-time risk monitoring. The human-layer version of zero trust means continuously verifying interaction authenticity. The question is “Does this request make sense, from this person, in this channel, at this moment, for this action?”
The resulting model is a distributed human-layer defense fabric. Browsers detect deceptive workflows. Phones and laptops correlate suspicious cross-app patterns. Messaging platforms identify manipulation signals. Smart home routers monitor anomalous local device behavior. Banking apps apply behavioral and transaction context before high-risk payments. Password managers evaluate credential-use context. Each component contributes a local judgment. These local agents make it harder for synthetic personas and AI-generated social engineering to capture the decision-making environment of users.
The core claim of this section is that defending human agency in the AI-offense era requires moving defense to the edge. Edge agents can detect urgency and inconsistency along with anomalous behavior at the moment those signals matter. Edge located autonomous defense is a strategy for defending human judgment inside everyday digital interaction where cyber conflict increasingly occurs.

6. Connected Cyber Insurance and Human-Layer Risk

Cyber insurance is likely to become an important part of human-layer cybersecurity because AI-enabled threats are not only technical events. These threats are also financial and recovery events. A person who is deceived by an AI-generated social engineering attack such as a cloned voice or deepfake video call may suffer financial loss and prolonged recovery costs. Traditional personal cybersecurity products often focus on protection before harm occurs while insurance focuses on loss transfer and recovery after harm occurs. These two functions should no longer be treated as separate in the AI-offense era. Personal cyber insurance will increasingly need to become connected to active defensive signals.

6.1. From Static Coverage to Dynamic Risk

The traditional cyber-insurance model is largely static. Underwriting often asks whether the policyholder has basic security controls in place such as antivirus software and incident response plans. This approach makes sense for conventional cyber risk, but it is too limited for human-layer attacks. The more important question now is whether the person is protected against manipulation. An insured user may have MFA enabled and still be deceived into approving a fraudulent transaction. A person may use antivirus software and still be cognitively captured by a synthetic persona.
This suggests a shift from static cyber policies to adaptive risk systems. Insurers may increasingly evaluate whether the insured has active protections against human-layer attacks rather than evaluating personal cyber risk once at enrollment or renewal. These protections could include some of the controls we previously discussed including autonomous fraud detection, device posture, suspicious transaction blocking, identity-verification tools, deepfake detection tools, and a resilience score based on local telemetry. The goal would be to price and reduce residual risk in a threat environment where the judgment of the user is continuously targeted.
The logic for this evolution is already visible in the cyber insurance literature. Liu and Zhu (2023) describe cyber insurance as a complementary mechanism for cyber resilience that helps mitigate residual losses when attacks or failures cannot be fully prevented. Their framework emphasizes residual risk and the relationship between insurance design and defensive behavior. The insurer needs some way to understand whether the insured is maintaining reasonable defenses before harm occurs if insurance is meant to support resilience after harm. This means measuring the presence of protective systems around identity, transactions, communication, and recovery in human related risk.
Dynamic insurance becomes necessary because AI-enabled threats evolve too quickly for annual questionnaires. Liu and Zhu (2023) explicitly argue that coverage should be able to change according to the security state of the environment and the type of threat. Zraqou et al. (2026) similarly argue that AI risks create dynamic risk profiles because AI systems learn and face novel threat vectors over time which render static pricing models inadequate. The risk profile of a user changes over time such as when they enable MFA or install fraud blocking. A connected policy could reflect those changes more accurately than a static application form.

6.2. Human-Layer Risk Signals

A connected personal cyber-insurance model would treat protective signals as underwriting inputs and resilience indicators. The first signal would be autonomous fraud detection. If a browser or payment platform of a user can locally flag suspicious payment pressure or transaction anomalies, then the probability of loss may decrease. The second signal would be secure backup status. Insurers may evaluate whether the user has recent recoverable backups since security events can create recovery costs. The third signal would be device posture. This includes whether devices and key accounts are updated and protected against known compromise. Connected insurance would translate these signals into personal resilience metrics.
The fourth signal would be multi-factor authentication adoption. The fifth signal would be suspicious transaction blocking. A banking or payment platform that can pause anomalous transfers before completion provides a stronger risk-reduction signal than a platform that only alerts after loss. The sixth signal would be identity-verification tools such as digital wallets and out-of-band confirmation workflows. Paparis et al. (2026) show how verifiable credentials and self-sovereign identity along with selective disclosure can support a cyber-insurance ecosystem.
The seventh signal would be deepfake detection or synthetic-media warning tools. A user who has access to local deepfake-risk indicators in video calls or voice messages may be better protected against impersonation-based fraud. The eighth signal would be a history of risky interactions. It could be represented through privacy-preserving risk events such as the number of blocked scam attempts or verified fraud alerts. The ninth signal would be recovery readiness, including whether the user has account recovery plans with emergency contact procedures and documented steps for freezing accounts or restoring access. The tenth signal would be a resilience score based on local telemetry where sensitive behavioral data is processed on the user’s device.

6.3. Privacy-Preserving Insurance

The privacy problem is central. Human-layer cyber insurance requires information about behavior and transactions, but those are the signals that should not be indiscriminately centralized. A connected insurance model that uploads all user behavior to insurers would create a new surveillance and breach risk. PINSA provides a useful direction because it is explicitly designed as a privacy-preserving cyber-insurance framework. Paparis et al. (2026) emphasize data minimization and selective disclosure with smart-contract-based claims handling as ways to support cyber-insurance operations without excessive disclosure of policyholder data.
Explainability is also essential. Users must understand how risk scores are generated and how they affect premiums and coverage if insurance becomes adaptive. Papastergiou et al. (2026) propose an explainable AI-based dynamic cybersecurity risk management approach for cyber insurability making use of real-time contextualized risk assessment to justify control selection and residual-risk decisions. This is important because opaque insurance scoring could create distrust or unfair denial of coverage. A connected insurance system should explain which protections improved the score of the user and which risks remain.
The real challenge is that cyber risk is difficult to price because cyber incidents are interdependent and shaped by incomplete data. He (2026) argues for data-driven actuarial modeling that links loss frequency and severity with insurance decision-making under realistic information availability constraints. The thesis also emphasizes that cyber risk can propagate in ways that resemble epidemic processes and that predictive outputs can inform contract design. This points toward a more dynamic actuarial model for human-layer insurance. A resilience score based on local protections could help insurers distinguish between users who face similar exposure but have different defensive capacity.

6.4. Insurance as Active Resilience

Connected cyber insurance could also reduce moral hazard. A traditional policy may create a concern that insured users will take fewer precautions because losses are covered. Adaptive insurance can counter this by tying coverage incentives to ongoing resilience. Liu and Zhu (2023) discuss moral hazard in cyber-insurance design and the importance of insurer observations of insured actions. A user who keeps backups active and uses identity-verification tools could receive better terms. Insurance would then become a mechanism for encouraging safer behavior rather than merely reimbursing failure.
Legal and regulatory considerations will also shape this model. Atila Yörük (2026) emphasizes that insurer liability and claim outcomes can depend on whether the insured fulfilled administrative and technical duties. Concerns such as unclear coverage and lack of actuarial data will become even more important for human-layer coverage. Policies will need clear definitions of covered losses from AI-enabled fraud including deepfake impersonation and romance-investment scams. They will also need clear standards for what counts as reasonable protective behavior as ambiguous exclusions would undermine trust in the market.
Connected cyber insurance should therefore be designed as a resilience partnership. The insurer would not simply collect premiums and adjudicate claims after loss. The insurer could help maintain protective readiness by offering risk dashboards with privacy-preserving telemetry and identity-recovery services. This is consistent with the broader argument that cyber risk must be elevated to a strategic level. Zraqou et al. (2026) argue that AI changes risk assessment, coverage determination, and claims processing.
Connected insurance also creates an opportunity to align edge defense with financial resilience. Edge-computed defense was framed as a way to detect manipulation locally in Chapter 6. Cyber insurance can extend that architecture by converting local protective signals into coverage and recovery support. The insurer would not need to see the messages or transactions belonging to the user. It would need to know whether protective controls are active, whether recent high-risk events were blocked, and whether recovery capacity exists. This aligns insurance with the principle of defending human agency without centralizing the user’s entire digital life.
The key argument of this section is that AI-era personal cyber insurance should not be limited to reimbursing losses after deception succeeds. It should become part of a connected resilience system that helps incentivize and strengthen defenses against human-layer attacks. Human-layer underwriting must ask whether the user has protection against manipulation with coercive transaction workflows. The future policy is not merely a static contract. It is an adaptive risk relationship among the user, edge defenses, and insurers.
This shift must be governed by three principles. The first principle is that cyber insurance should support resilience rather than replace security. The second principle is that risk assessment should become dynamic and be tied to residual risk. The third principle is that personal telemetry must be handled through data minimization and local processing wherever possible. If these principles are followed, connected cyber insurance can become a constructive part of human-layer defense that provides a privacy-preserving financial safety net which rewards active protection and helps preserve agency in the face of AI-enabled manipulation.

7. Governance and Ethical Considerations

Autonomous defense creates a difficult governance problem because the system designed to protect the user must sometimes interfere with the user. It may warn, block, or require additional verification before a person completes an action. These interventions may be necessary when AI-enabled attackers exploit urgency or emotion using synthetic identity. Yet each intervention also raises the ethical risk that the defense system may protect the user from manipulation, but it may also become a new mechanism for controlling the decisions of the user. The governance challenge is how to ensure that autonomous defense protects agency without overriding it.
This problem is central to the human-layer cybersecurity argument. Judgement itself becomes something to defend if the human layer is now an attack surface. Judgment cannot be defended by replacing it with machine authority. A system that automatically blocks every suspicious message and suppresses every risky interaction may reduce some cyber losses, but it may also produce false disrupt legitimate activity. The aim should not be to remove risk from human decision-making altogether. The aim should be to preserve the conditions under which human decision-making remains meaningful.

7.1. Explainable Intervention

  • The first governance question is when a system should interrupt the user. The threshold for interruption should depend on the risk and the confidence of the detection. The concept of AIoT-driven Health Behavioral Security is useful here because it treats autonomy as something that can be supported through context-aware sensing that is real-time, but it also warns that systems must balance sensitivity to avoid false alarms and intervention fatigue (Nakamura, 2026). This means a defense agent should interrupt when the behavioral stakes are significant and not when a signal is only unusual.
A warning should therefore be used when risk is plausible but not decisive such as when a payment request is unusual but not clearly fraudulent. The system should provide an explanation including a short notice that identifies the risk and gives the user a reasonable path forward. The purpose is to restore deliberation where the attacker is attempting to compress it rather than to frighten the user.
  • When should it block an action entirely? The second governance question is when the system should delay an action. Delays are appropriate when the action is high-impact but still plausibly legitimate. A bank transfer or password reset may not be malicious in itself. When the action occurs after a synthetic voice call or an unusual transaction pattern a delay can create the time necessary for verification. This aligns with runtime-security models that treat action execution as the critical boundary. Autonomous Action Runtime Management framework argues that AI-driven actions should be intercepted before execution for evaluation against policy, and then allowed, denied, or escalated through step-up authorization (Errico, 2026). Delay is the governance mechanism that transforms a manipulated impulse into a reviewable decision for human-layer defense.

7.2. Liability and Accountability

  • Who is liable if it fails? The third governance question is when the system should block an action entirely. Blocking should be reserved for cases where the system has high confidence that the action is dangerous. A known phishing link or malware attachment may justify a hard block. The classification framework of AARM is helpful because it distinguishes forbidden actions from context-dependent actions. Some actions are always prohibited while others are allowed or denied depending on accumulated context (Errico, 2026). This distinction is essential for human-layer governance. Blocking should not be treated as the default response to uncertainty. It should be used when the action falls into a clearly prohibited category or when contextual evidence indicates that allowing it would likely cause irreversible harm.
  • Who is liable if it wrongly blocks a legitimate action? The fourth governance question is how to manage false positives. Wrongly blocking a legitimate action is not a minor inconvenience. False positives can prevent lawful payments and disrupt access to funds while damaging trust in protective systems. Bulla et al. (2026) emphasize that even a small false-positive rate in high-volume payment environments can produce thousands of legitimate transaction failures which results in increasing call-center workload and customer dissatisfaction. A suspicious action should not always be blocked as it may be better to route it through additional evidence gathering or step-up verification.
  • Can insurers require these systems? The fifth governance question is who is liable if the system fails. Responsibility cannot be placed only on the victim when an autonomous defense tool misses a deepfake scam or fails to detect a fraudulent transaction. Shi (2026) argues that AI-related crimes complicate liability because autonomous decision-making and multiple participants make it difficult to determine responsibility. That point applies equally to defensive failure. A governance model must distinguish between a user who ignored clear guidance and a provider whose system was negligently designed.

7.3. Privacy and Surveillance

  • Could autonomous defense become surveillance? The sixth governance question is who is liable if the system wrongly blocks a legitimate action. The user may suffer real harm if an autonomous system prevents a legitimate payment or blocks access to an account. Governance therefore requires audit records and clear allocation of responsibility. The emphasis of AARM on tamper-evident receipts is useful because every action and outcome should be recorded for later review (Errico, 2026). This means a user should be able to ask questions such as “Why was this blocked?” or “What evidence was used?” Autonomous defense becomes opaque authority rather than accountable assistance without these answers.

7.4. User Override and Human Agency

  • How can users understand and override defensive decisions? The seventh governance question is whether insurers can require these systems. Connected cyber insurance may legitimately require some protective measures, but requiring autonomous human-layer defense raises special concerns. Insurance may become a pathway to surveillance if insurers demand invasive monitoring of messages or behavioral activity. A better model is privacy-preserving attestation. A user should be able to prove that protective controls are active without handing over raw communications or behavioral histories. Privacy-preserving cyber-insurance frameworks based on verifiable credentials and selective disclosure point toward this governance model (Paparis et al., 2026).
  • What elements are necessary for autonomy-preserving intervention? The eighth governance question is whether autonomous defense itself could become surveillance. Human-layer defense depends on sensitive signals SUCH AS identity cues and behavioral changes. These signals can protect users, but they can also expose intimate details about their lives. Nakamura (2026) specifically argues that autonomy-preserving intervention requires transparency, dynamic consent, and explainable AI. The defense system should process as much as possible locally and let users understand and control intervention intensity.
  • What categories in the tiered governance model for defensive actions? The ninth governance question is how users can understand and override defensive decisions. A useful governance model can distinguish between three categories. Advisory warnings should be easy to override because the system is offering guidance rather than enforcing a hard boundary. High-risk actions should require step-up verification before override. Forbidden or unlawful actions may be non-overridable because the system has a duty to prevent policy violation. This tiered approach protects intervention while recognizing that some actions are too dangerous or legally constrained to leave entirely to momentary user choice.
Explainability is what makes override meaningful. A user needs a reason from the system when an activity is intercepted. Adebayo (2026) argues that reliable autonomous cybersecurity requires human-in-the-loop explainable AI, where systems know their limits and articulate their reasoning during escalations to human judgment at critical points. Explainability is the medium through which human oversight becomes possible in this model.
This also means that autonomous defense should be auditable. Every significant intervention should leave a record that can support later dispute resolution and liability analysis. Adebayo (2026) emphasizes that HITL-XAI systems create audit trails that show not only what action was taken, why the system acted, and whether a human validated or corrected it. This kind of record helps prevent a dangerous asymmetry in which users are accountable for decisions without making systems accountable for how they shaped those decisions.
Governance must also account for model error and adversarial manipulation. Attackers will adapt to defensive systems and attempt to exploit their approval workflows. Adepu (2026) notes that autonomous cyber defense systems face challenges including false positives, adversarial attacks, model poisoning, privacy concerns, bias, and the need for human oversight in high-risk actions. These are governance problems because they determine when intervention is legitimate and when it is excessive.
Responsible governance should include clear design commitments. Interventions should be proportional to risk. High-impact blocks should be explainable and appealable. Users should be able to configure preferences where safety permits. Data processing should be local and minimized wherever possible. Insurers and platforms should rely on attestations rather than raw surveillance data. High-risk autonomous decisions should require human-in-the-loop review or step-up verification. Systems should generate audit trails that support accountability. Models should be tested for fairness, robustness, and drift. Governance should remain adaptive because the threat landscape will continue to change.
This framework also helps answer the core concern that autonomous defense may become authoritarian. Authoritarianism occurs when the system treats the user as incapable of judgment and substitutes its own decision without explanation or consent. Protective governance should instead treat the user as the protected decision-maker. The role of the system is to restore the decision conditions that attackers seek to destroy. The system provides time if an attacker uses urgency. The system provides verification if an attacker uses synthetic identity. The system provides distance if an attacker uses emotional pressure. The system provides explanation if an attacker uses complexity. The goal is to make the decision of the user less vulnerable to coercion and deception.
The ethical center of this section is therefore agency. Agency does not mean leaving users alone against machine-speed manipulation. Nor does it mean allowing autonomous systems to silently control user behavior. Agency means that people retain meaningful capacity to understand and provide consent or refusal. Autonomous defense should protect that capacity. It should intervene with transparency and accountability when the environment of the user is being distorted. The legitimacy of autonomous defense will depend on how accurately it detects threats and how respectfully it treats the person it protects. The goal is not to replace human judgment. The goal is to defend the conditions under which human judgment remains meaningful.

8. Design Principles for Human-Layer Autonomous Defense

The previous sections argued that the human layer has become a primary cyber battlefield because AI-enabled adversaries increasingly target trust, emotion, and authority response. The practical question is how to design autonomous defenses that protect people without turning protection into control. Human-layer autonomous defense should be designed as a sociotechnical architecture that combines edge computing, identity verification, behavioral context, explainable intervention, insurance incentives, and shared governance.
This section proposes seven design principles for human-layer autonomous defense (Figure 2) which include human agency first, edge-first privacy, explainable intervention, friction at the right moment, continuous authentication of interaction rather than identity alone, insurance-aligned resilience, and shared governance. These principles provide a framework for designing defensive systems that can operate at AI speed while preserving human judgment and accountability.

8.1. Human-Agency First

The first principle is human agency first. Defensive systems should assist risky decisions without unnecessarily removing user control. Human-layer attacks work by narrowing the decision space of the user by creating urgency and exploiting trust. A well-designed defense should reverse that process. It should expand the user’s ability to verify and refuse if necessary. Kovačić and Bilić (2026) support this point through their Human-Centric Social Engineering Shield model which emphasizes real-time risk scoring and adaptive micro-training at decision points rather than relying only on general awareness training or blunt blocking. The design lesson is that human-layer defense should not simply classify people as safe or unsafe. It should support better decisions at the moment those decisions are being manipulated.
Kincl et al. (2026) argue that AI in cybersecurity incident management should augment rather than replace human expertise. Their analysis emphasizes that effective AI integration depends on task alignment with human oversight that is managed by governance. This means autonomous defense should not silently make consequential decisions on behalf of users whenever uncertainty arises. It should intervene proportionately while preserving meaningful override where appropriate and the ability of the user to understand what is happening.

8.2. Edge-First Privacy

The second principle is edge-first privacy. Human-layer defense requires highly sensitive signals including behavioral patterns and identity cues along with relationship history. Autonomous defense risks becoming surveillance if they are centralized without constraint. Edge-first privacy requires that sensitive cognitive and behavioral data be processed locally whenever possible. Only minimal and preferably anonymized risk indicators should leave the device.
This principle is consistent with the broader direction of dynamic insurance. Kumar and Malgaonkar (2026) argue that real-time cyber insurance models can incorporate metrics such as update frequency, access logs, and abnormal device behavior. Yet their study also identifies trust and alert fatigue as barriers to adoption. Adaptive security and insurance models for human-layer defense are valuable but must be built on privacy-first design. Local processing with data minimization and user consent should be treated as foundational design requirements rather than optional safeguards.

8.3. Explainable Intervention

The third principle is explainable intervention. Users should understand why a message or transaction is being flagged. A defensive system that says only generic messages may reduce some harms, but it does not build informed intervention. The intervention should identify the risk pattern in terms the user can understand. The goal is to restore interpretive context instead of merely notifying the user.
Explainability should be understood practically rather than absolutely. Kincl et al. (2026) argue that explainability in cybersecurity can include confidence indicators with decision traceability even when full model transparency is not technically feasible. AI Systems Cyber Doctrine by Upadrasta (2026) similarly emphasizes decision lineage with logging and incident forensics to obtain explainability and accountability. The user should be able to know what evidence triggered the intervention and what options are available.

8.4. Friction at the Right Moment

The fourth principle is friction at the right moment. Security should not constantly interrupt users as this creates fatigue. Although high-risk decisions should not remain frictionless. The design challenge is to create friction when the user is most vulnerable to manipulation and when the action is most consequential. This can include actions such as sending money, approving an MFA prompt, or transferring sensitive data.
The HC-SES model by Kovačić and Bilić (2026) supports this principle by placing adaptive micro-training at decision-making points instead of relying on generic training prior to the moment of risk. Kumar and Malgaonkar (2026) also warn that frequent notifications can generate alert fatigue, while adaptive alerting and critical-issue alerts with customizable preferences can help maintain user responsiveness. The design implication is that human-layer defense should be selective. It should allow low-risk routine activity to proceed smoothly while creating explainable friction during high-risk decisions where urgency, authority and unusual transaction context is present.

8.5. Continuous Authentication of Interaction

The fifth principle is continuous authentication of interaction. Human-layer defense must ask if the entire interaction make sense? A valid login may still be part of an account takeover. A familiar voice may be cloned. A known sender may be compromised. A verified device may be controlled by a deceived user. A signed transaction may still be the product of synthetic authority or emotional pressure.
Tashenova et al. (2026) argue for a multi-tier security model that integrates human factors and behavioral analytics with Zero Trust and defense-in-depth. Their framework supports the shift from one-time authentication toward continuous verification across endpoints and applications. Continuous verification should extend beyond the identity of the user to the interaction itself for human-layer autonomous defense. The system should evaluate whether the sender, transaction and behavioral pattern form a coherent and trustworthy interaction.

8.6. Insurance-Aligned Resilience

The sixth principle is insurance-aligned resilience. Connected cyber insurance should reward protective behavior and autonomous defense adoption without creating unfair surveillance or exclusion. Insurance can support human-layer defense by incentivizing controls such as fraud detection, suspicious transaction blocking, and deepfake detection. Insurance incentives can also create unfair penalties or intrusive monitoring if poorly designed.
Yautsiukhin and Kavalionak (2026) show that cyber insurance can reduce self-protection investment when insured parties rely on coverage rather than maintaining cybersecurity practices. Their bonus penalty mechanism is intended to counteract this by increasing investment incentives while requiring relatively limited verified information. Kumar and Malgaonkar (2026) similarly find that real-time premium adjustment can encourage better cybersecurity behavior if systems are transparent and supported by regulation. These findings support an insurance-aligned design principle which is to reward active resilience while not making insurance a justification for invasive behavioral surveillance.
An insurance-aligned resilience model should be built around privacy-preserving attestations and positive incentives. A user should be able to prove that controls such as fraud blocking and deepfake detection are enabled without exposing private communications. Premium incentives should be framed around protective adoption and recovery readiness rather than punishment for victimization. A person who has experienced fraud should not become uninsurable, but the system should help them improve resilience.

8.7. Shared Governance

The seventh principle is shared governance. Human-layer autonomous defense cannot be governed by vendors alone. Several groups such as users, insurers, and regulators have legitimate interests in defining acceptable autonomous defense. De Gómez (2026) argues that AI regulation can create service value when producers, regulators, and users cooperate around safe and responsible AI deployment.
Shared governance also requires clear responsibility. Chen (2026) argues for user-centric AI governance in which AI is treated as an instrument whose deployment remains attributable to human operators and organizations with recognized obligations across the broader ecosystem. This distributed yet centered approach is useful for human-layer autonomous defense. Responsibility should not disappear into the complexity of vendors, insurers, and users. Identifiable accountability must be made when a defensive system blocks a legitimate action or misses a scam.
These seven principles can be translated into operational design requirements. First, systems should define levels of intervention which can include inform, warn, delay, verify, block, quarantine, escalate, and recover. Second, they should define risk thresholds for each intervention type. Third, they should process sensitive signals locally wherever possible. Fourth, they should provide user explanations in plain language. Fifth, they should support trusted override or escalation pathways when appropriate. Sixth, they should maintain auditable decision traces without creating unnecessary surveillance records. Seventh, they should align insurance incentives with protective behavior through minimal and verifiable evidence. Eighth, they should be monitored after deployment for bias and false positives.
These principles also clarify that human-layer autonomous defense should not become constant warning noise or invisible behavioral scoring. It also should not make users dependent on opaque machine decisions or permit insurers to demand unrestricted access to private interactions. It should not treat past victimization as evidence of moral failure or give vendors unilateral authority to define acceptable digital behavior. And it should not collapse all uncertainty into hard blocking.
The design goal is to protect the human capacity to make security-relevant decisions under adversarial conditions. Human agency first protects choice. Edge-first privacy protects dignity and informational self-control. Explainable intervention protects understanding. Friction at the right moment protects deliberation. Continuous authentication of interaction protects contextual trust. Insurance-aligned resilience protects recovery and incentives. Shared governance protects legitimacy.
These principles define a human-layer defense architecture for the AI-offense era. The system should be fast enough to respond to machine-speed manipulation with enough restraint to preserve autonomy. It should be intelligent enough to detect synthetic identity and anomalous behavior while being transparent enough for users to understand and contest its decisions. It should be connected enough to support resilience and insurance with enough privacy preservation characteristics to avoid becoming surveillance. The ultimate objective is not to automate trust away. It is to defend the conditions under which trust, identity, and human judgment can remain meaningful.

9. Discussion

The rise of autonomous AI cyber capabilities marks a fundamental shift in the practice of cybersecurity. This article has argued that networks, endpoints, applications, and data remain essential security domains, but they no longer define the complete cyber battlefield. Systems such as Mythos illustrate the acceleration of vulnerability discovery and exploit generation beyond traditional human-paced response cycles (Campbell, 2026; Goldstein, 2026; Pesoli et al., 2026, Rao et al., 2026). Cybersecurity can no longer depend solely on periodic assessment and delayed patching as the timeline between discovery and exploitation compresses. The problem is not merely that attackers may become faster. It is that the human and institutional processes on which defense has historically relied are increasingly mismatched with machine-speed offense.
The deeper transformation is cognitive. AI-enabled adversaries have shifted to not only exploit software defects, but also exploit the conditions under which people decide what is authentic and trustworthy. Attention, trust, emotion, and authority response now function as operational attack surfaces. Synthetic personas, romance-investment scams, and adaptive phishing campaigns are all examples of attacks demonstrate that the target is often not the device itself but instead the perception of the user (Ashraf, 2026; Bailo et al., 2026; Gonzaga et al., 2026; Jadala, 2026). A phishing email in this environment is not simply a deceptive message. It is a personalized attempt to capture the decision-making process of the user.
This shift exposes the limits of awareness training as a primary defense. Traditional training assumes that users have enough time and context to detect deception. AI-enabled attacks undermine these assumptions by producing social engineering attacks with plausible requests through trusted channels. Users cannot reasonably be expected to manually authenticate every interaction in an environment where adversaries can automate personalization and synthesize authority in real time. Awareness remains necessary and additionally must be embedded within a broader architecture of decision support and autonomous protection (Haider & Abbas, 2026; Kovačić & Bilić, 2026; Pokorny, 2026).
This chapter proposed edge layered autonomous defense as a response to human-layer risk. Personal defense agents embedded in browsers, devices, and banking applications can detect suspicious interaction patterns at the point of decision. These systems can identify urgency cues with payment pressure paired with synthetic media markers before harm becomes irreversible. Edge-based processing is especially important because human-layer defense requires sensitive behavioral and communication signals. Processing such signals locally wherever possible can reduce the privacy risks that would arise from purely centralized monitoring (Shapira et al., 2026; Xu & Li, 2026; Yang, 2026).
Connected cyber insurance may also become part of the human-layer defense ecosystem. Insurance models are likely to evolve from static policies toward adaptive resilience systems as personal cyber risk becomes more dynamic. Insurers may increasingly evaluate whether the user has active protection against human-layer attacks such as autonomous fraud detection and deepfake detection rather than asking only whether a user has antivirus software or multi-factor authentication. Insurance should reward protective behavior and recovery readiness without becoming a mechanism for surveillance, or exclusion (Liu & Zhu, 2023; Paparis et al., 2026; Papastergiou et al., 2026).

10. Conclusions

The central ethical challenge is that autonomous defense systems will sometimes need to intervene in human decisions. They may warn users, block messages or require additional verification. These interventions can protect agency when adversaries are attempting to manipulate it, but they can also threaten agency if they become excessive. The legitimacy of autonomous defense will therefore depend on governance principles such as proportionality, explainability, auditability, and human oversight. The goal is not to replace human judgment with machine judgment but to defend the conditions under which human judgment remains meaningful.
The cyber battlefield is expanding from systems and data into the human layer, where trust, attention, and emotion are now targetable at scale. The defense of that layer must not become a new form of coercion. Human-layer cybersecurity should strengthen the capacity of the user to pause and provide consent and refusal. The most important security objective in a machine-speed threat environment is not preventing unauthorized access. It is preserving the integrity of human agency amid synthetic identities and adaptive manipulation. Future cybersecurity will succeed only if it protects both the systems people use and the human judgment through which those systems are trusted.

Key Terms and Definitions

  • Human Layer: The intersection of technical systems, institutional processes and individual judgment where attention, trust, emotion and decision-making have become operational attack surfaces.
  • Cognitive Defense: Cybersecurity practice that protects the psychological and decision-making conditions under which people interact with technology rather than focusing solely on infrastructure.
  • Synthetic Personas: Artificial identities created through deepfakes, voice cloning and AI-generated writing that allow attackers to impersonate trusted individuals in sustained and believable interactions.
  • Cognitive Capture: The moment when a target’s attention and decision-making become controlled by an artificial identity that appears authentic making compliance feel correct rather than manipulated.
  • Decision Compression: The deliberate reduction of time available for reflection through manufactured urgency and authority framing, preventing victims from pausing to verify or deliberate.
  • The Mythos Moment: The inflection point when AI systems demonstrated autonomous vulnerability discovery and exploit generation at machine speed collapsing the traditional time buffer cybersecurity depended upon.
  • Edge-Computed Autonomous Defense: Protective intelligence deployed directly on user devices and applications to detect manipulation patterns locally while processing sensitive data on-device to preserve privacy.
  • Connected Cyber Insurance: An adaptive insurance model that treats protective measures as underwriting inputs and makes coverage responsive to the insured’s ongoing defensive posture and recovery readiness.
  • Synthetic Trust Attacks: Coordinated campaigns delivering identity simulation, contextual plausibility and authority cues to manufacture believable conditions under which victims lower their caution.
  • Zero-Trust Human Layer: The principle of continuous verification that no interaction or request should be assumed trustworthy by default requiring constant assessment of whether requests make sense from the source, channel, timing and action involved.

References

  1. Abdulhamed, A.; Ranjan, P.; Xiong, S. A novel approach for distinguishing human and AI-generated texts. ACM Transactions on Asian and Low-Resource Language Information Processing., 2026. [Google Scholar]
  2. Adebayo, H. Human-in-the-loop explainable AI for reliable autonomous cybersecurity infrastructure. Preprints.org. 2026. [Google Scholar] [CrossRef]
  3. Adegoke, K. R.; Adegoke, T. B. AI-enabled fraudulent schemes and their effects on consumer trust and digital financial adoption in Nigeria. SSR J. Multidiscip. 2026, 3(1), 20–36. [Google Scholar]
  4. Adepu, R. Autonomous cyber defense systems powered by AI for enterprise cloud environments. Int. J. Comput. Eng. Technol. 2026, 17(2), 23–41. [Google Scholar] [CrossRef]
  5. Akram, M.; Khan, W.; Ahmad, N.; Imran, M.; Iqbal, M. W.; Rasheed, M. D.; Delshadi, A. M. Deepfake social engineering attacks: Detection and prevention framework.; 2026. [Google Scholar]
  6. Ali, U.; Mustafa, F.; Akhtar, S. Mitigating social engineering attacks using adaptive identity and access management solutions. 2026. [CrossRef]
  7. Ashraf, M. T. Synthetic trust attacks: Modeling how generative AI manipulates human decisions in social engineering fraud  . arXiv 2026, arXiv:2604.04951. [Google Scholar]
  8. Atila Yörük, P. A comparative analysis of insurance protection strategies against cyber threats in Türkiye and the European Union. Can. J. Educ. Soc. Stud. 2026, 6(1), 144–160. [Google Scholar] [CrossRef]
  9. Bailo, P.; Sirignano, A.; Nittari, G.; Visconti, G.; Pesel, G.; Spasari, T.; Ricci, G. A review of crime at machine speed: Criminological aspects of artificial intelligence’s industrialisation of deception. Sci 2026, 8(3), 54. [Google Scholar] [CrossRef]
  10. Beg, S. The human firewall: Modeling AI-driven influence and human vulnerability in hybrid ecosystems. AI Soc. 2026, 1–25. [Google Scholar]
  11. Bhatnagar, P. AI-Based Pentesting of AI Systems Recursive Security Failures  . In Technical Disclosure Commons; Defensive Publications Series, 2026. [Google Scholar]
  12. Bociga, D.; Lord, N. Artificial intelligence and the organisation and control of fraud. In The Research Handbook on Fraud and Society; Edward Elgar, 2026. [Google Scholar]
  13. Bulla, C.; Gupta, S.; Kori, A.; Panda, M. R.; Kadakal, S.; Wali, G. A comprehensive review of financial fraud detection techniques and the emerging role of adaptive agentic AI. 2026. [Google Scholar] [CrossRef] [PubMed]
  14. Campbell, R. Detection and mitigation of Mythos-class frontier model capabilities: A layered reference architecture. Computers 2026, 15(6), 331. [Google Scholar] [CrossRef]
  15. Canyakan, S. Exploring perceptual boundaries: Assessing human ability to differentiate AI-cloned from real voices. J. Interdiscip. Art. Educ. 2026, 7(1), 1–21. [Google Scholar]
  16. Chen, Z. Operational responsibility in AI governance: A user-centric liability framework. AI Ethics 2026, 6, 306. [Google Scholar] [CrossRef]
  17. Chimamiwa, G. Managing cyber risks in the face of AI- and ML-driven adversarial attacks. SBS J. Appl. Bus. Res. 2026, 71–79. [Google Scholar]
  18. Daoud, E.; Garcia-Blas, J.; Alawadi, S.; Carretero, J. Phishing in the age of distributed intelligence: Taxonomies, detection strategies, and the emerging role of federated learning. Prog. Artif. Intell. 2026, 1–32. [Google Scholar]
  19. De Gómez, W. Artificial intelligence regulation as service value in public and private sectors. In Canadian Public Policy / Analyse de politiques; 2026. [Google Scholar] [CrossRef]
  20. Erickson, J. The fake friend dilemma: Trust and the political economy of conversational AI  . arXiv 2026, arXiv:2601.03222. [Google Scholar]
  21. Errico, H. Autonomous Action Runtime Management (AARM): A system specification for securing AI-driven actions at runtime. 2026. [Google Scholar] [CrossRef] [PubMed]
  22. Fan, S.; Zhang, L.; Yuan, X. When AI persuades: Adversarial explanation attacks on human trust in AI-assisted decision making. arXiv 2026, arXiv:2602.04003. [Google Scholar]
  23. Ferrara, E. The generative AI paradox: GenAI and the erosion of trust, the corrosion of information verification, and the demise of truth. Future Internet 2026, 18(2), 73. [Google Scholar] [CrossRef]
  24. Goldstein, G. M. Six reasons Claude Mythos is an inflection point for AI—and global security  . Council on Foreign Relations. 2026. Available online: https://www.cfr.org/articles/six-reasons-claude-mythos-is-an-inflection-point-for-ai-and-global-security.
  25. Gonzaga, K.; Serra, S.; Gomes, M.; Malta, S. AI-powered social engineering: Emerging attack vectors, vulnerabilities, and multi-layered defense strategies. Computers 2026, 15(2), 128. [Google Scholar]
  26. Haider, B.; Abbas, A. Combating phishing threats through AI-enabled identity and access management frameworks. 2026. [CrossRef]
  27. Han, B.; Button, M. An anatomy of “pig butchering scams”: Chinese victims’ and police officers’ perspectives. Deviant Behav. 2026, 47(4), 635–653. [Google Scholar]
  28. Hathaway, H. M. Responsible Disclosure in the Age of AI: A Call for Urgent Action. 2026. [Google Scholar] [PubMed]
  29. He, P.; Fox, A.; Miculicich, L.; Friedli, S.; Fabian, D.; Gokturk, B.; Le, L. T. Co-RedTeam: Orchestrated Security Discovery and Exploitation with LLM Agents. arXiv 2026, arXiv:2602.02164. [Google Scholar]
  30. He, R. Data-driven actuarial modelling of cyber risk: Frequency, severity, and insurance pricing  . Doctoral dissertation, University of Melbourne, 2026. [Google Scholar]
  31. Hussain, A.; Akhtar, S. AI-Based Behav. Anal. Phishing Detect. Secur. Access control. 2026. [CrossRef]
  32. Jadala, S. K. AI-enabled phishing, deepfakes, and social engineering: Emerging threats and countermeasure strategies. Int. J. AI BigData Comput. Manag. Stud. 2026, 7(2), 202–220. [Google Scholar] [CrossRef]
  33. Kelley, P. G.; Rousso-Schindler, S.; Shelby, R.; Thomas, K.; Woodruff, A. How generative AI empowers attackers and defenders across the Trust & Safety landscape. In Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems, 2026, April; pp. 1–21. [Google Scholar]
  34. Khera, V.; Sunil, R.; Mer, P.; Kointarangkul, N.; Diwan, A. Towards adaptive and continuous offensive security: A comprehensive survey of AI driven threat validation techniques. Array 2026, 100843. [Google Scholar]
  35. Khurram, M. S. Artificial intelligence for cybersecurity: Fundamentals, benefits and challenges.; 2026. [Google Scholar]
  36. Kincl, J.; Adam, M. T. P.; Pavleska, T. Human-AI integration in cybersecurity: An industry-aligned perspective on incident management. Int. J. Inf. Secur. 2026, 25, 103. [Google Scholar] [CrossRef]
  37. Kovačić, S.; Bilić, I. AI-enhanced social engineering: Emerging threats and human-centric countermeasures. Romanian J. Inf. Technol. Autom. Control 2026, 36(1), 63–76. [Google Scholar] [CrossRef]
  38. Kumar, M.; Malgaonkar, G.; P. Real-time premium adjustment models for cyber insurance using IoT device security metrics. In Proceedings of the Global Innovation and Technology Summit “AAROHAN 3.0” Engineering Track Advances in Engineering Research; Agarwal, V., et al., Eds.; 2026; Vol. 295. [Google Scholar] [CrossRef] [PubMed]
  39. Lazer, S. J.; Aryal, K.; Gupta, M.; Bertino, E. A Survey of Agentic AI and Cybersecurity: Challenges, Opportunities and Use-case Prototypes. arXiv 2026, arXiv:2601.05293. [Google Scholar]
  40. Liu, S.; Zhu, Q. Cyber insurance for cyber resilience. arXiv 2023, arXiv:2312.02921. [Google Scholar]
  41. Lui, A.; Miglionico, A. AI generated deepfake financial scams: A missing liability regime for consumer protection frameworks. Asian J. Comp. Law. 2026. [Google Scholar]
  42. Luttrell, R.; Davis, J.; Welch, C. Detecting synthetic text profiles: Human discernment versus AI analytics.; 2026. [Google Scholar]
  43. Malkawi, M.; Alhajj, R. AI-Powered Vulnerability Detection and Patch Management in Cybersecurity: A Systematic Review of Techniques, Challenges, and Emerging Trends. Mach. Learn. Knowl. Extr. 2026, 8(1), 19. [Google Scholar] [CrossRef]
  44. Nakamura, Y. AIoT-driven health behavioral security: Vision and challenges. ACM Trans. Comput. Healthc. 2026, 7(1), Article 7. [Google Scholar] [CrossRef]
  45. Njuguna, L. W. Deepfake cybersecurity threats: Detection and mitigation strategies. Int. J. Artif. Intell. Eng. Res. 2026, 2(01). [Google Scholar]
  46. Odeyinka, T. E.; Ejoh, C. I.; Abdulmalik, A. A.; Salami, I. A.; Ogunmolu, A. M. Bridging AI-automated governance, adaptive certification, behavioral authentication, and AI-agent risk monitoring in zero-trust digital infrastructures. J. Eng. Res. Rep. 2026, 28(1), 371–387. [Google Scholar]
  47. Oh, H.; Lee, E.; Shin, S.; Lee, K.; Pyun, M.; Lim, H. DeepAware: Using experiential deepfake simulations to enhance cybersecurity awareness in older adults. In Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems, 2026, April; pp. 1–23. [Google Scholar]
  48. Paparis, G.; Zarras, A.; Farao, A.; Xenakis, C. PINSA: Privacy-preserving cyber insurance framework. Clust. Comput. 29 2026, 172. [Google Scholar] [CrossRef]
  49. Papastergiou, S.; Basheer, N.; Lampropoulos, K.; Verrios, P.; Islam, S. Explainable AI based dynamic cybersecurity risk management for cyber insurability. Int. J. Inf. Secur. 25 2026, 36. [Google Scholar] [CrossRef]
  50. Pesoli, A.; Errico, H.; Cavallaro, L. Demystifying the Mythos or disrupting bugonomics? From zero-day asymmetry to defender remediation throughput. 2026. [CrossRef]
  51. Pokorny, L. Characterizing AI-enabled social engineering threats to U.S. national security: A mixed-methods analysis for developing defensive policy and technical countermeasures. 2026. [CrossRef]
  52. Rafi, M. S. Generative AI in cybersecurity: A systematic review of automated vulnerability discovery and patch generation. 2026. [CrossRef]
  53. Rahat, Y. O.; Islam, M. K.; Rabbani, S. F. Machine learning for identifying deepfake-driven identity abuse, authentication evasion, and customer impersonation in U.S. banking. Front. Comput. Sci. Artif. Intell. 2026, 5(4), 54–67. [Google Scholar]
  54. Rao, A. K.; Keller, A. J.; Kalra, N.; Steed, R.; Kwegyir-Aggrey, K.; Klyman, K.; Staheli, D.; Bergman, A. S. Challenges to the monitoring of deployed AI systems (NIST Trustworthy and Responsible AI, NIST AI 800-4); National Institute of Standards and Technology, 2026. [Google Scholar] [CrossRef]
  55. Shapira, A.; Gandhi, P. A.; Habler, E.; Shabtai, A. Mind the web: The security of web-use agents. In Proceedings of the ACM Asia Conference on Computer and Communications Security, 2026, June; pp. 835–851. [Google Scholar]
  56. Shi, J. Criminal regulation of AI crimes: The application dilemma and path optimization of the crime of assisting information network criminal activities. In Proceedings of the 1st International Conference on Politics, Law, and Social Science, 2026; pp. 27–32. [Google Scholar]
  57. Tashenova, Z.; Alim, A.; Gabdullin, A.; Abdikhaimov, Y.; Raiskanov, R.; Al-Tarazi, O.; Abdugulova, Z.; Amanzholova, S. Design of a multi-tier security model encompassing human factors, identification processes, and secure networking. Information 2026, 17, 537. [Google Scholar] [CrossRef]
  58. Upadrasta, K. AI systems cyber doctrine: Governance and operational control of algorithmic risk (Version 7.0). 2026. [Google Scholar]
  59. Wang, Z.; Schiller, N.; Li, H.; Narayana, S. S.; Nasr, M.; Carlini, N.; Song, D. ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks? arXiv 2026, arXiv:2605.11086. [Google Scholar]
  60. Xu, E.; Li, T. From fragmentation to integration: Exploring the design space of AI agents for human-as-the-unit privacy management. In Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems, 2026; pp. 1–24. [Google Scholar]
  61. Yang, C. AgentTrust: Runtime safety evaluation and interception for AI agent tool use. arXiv 2026, arXiv:2605.04785. [Google Scholar]
  62. Yang, Y.; Choi, D.; Hong, Y.; Park, J. W.; Yu, J. Y.; Kim, H. D.; Park, S. VishBox: An AI-agent-based adaptive voice phishing simulation framework for cybersecurity education. In IEEE Access.; 2026. [Google Scholar]
  63. Yaşar, İ. H.; Uluç, M. Cybersecurity Communication in the Age of Digital Transformation: Zero Trust, Security Culture, and Resilience. Digit. Secur. Media 2026, 3(1), 31–48. [Google Scholar]
  64. Yautsiukhin, A.; Kavalionak, N. A bonus and penalty mechanism as an incentive for cybersecurity investments. Int. J. Inf. Secur. 2026, 25, 47. [Google Scholar] [CrossRef]
  65. Yogatama, B. A.; Rimbawa, H. D. Digital watermarking and the fight against deepfake content. JATI (Jurnal Mahasiswa Teknik Informatika) 2026, 10(1), 691–698. [Google Scholar] [CrossRef]
  66. Zraqou, J.; Omar, K.; Alkhatib, J. Evol. Cyber Insur. Response To Artif. Intell. Risks. 2026, 66.

Additional Reading

Abdulrazaq, M. H., Koçak, C., Oyucu, S., & Asal, B. (2026). Cybersecurity risk mitigation and network anomaly detection in smart homes using machine learning and data mining. PeerJ Computer Science, 12, e3612.
Biswas, B., & Sarkar, S. (2026). Responsible agentic artificial intelligence governance: Risk, safety, and ethical challenges in autonomous systems. International Journal of Applied Resilience and Sustainability, 2(2), 142–167.
Chhabra, A., Datta, S., Nahin, S. K., & Mohapatra, P. (2026). Agentic AI security: Threats, defenses, evaluation, and open challenges. IEEE Access.
Niskanen, A. (2026). Strategic alignment and ecosystem innovation: Integrating the European Digital Identity Wallet into the financial sector.
Parsons, Z. S. (2026). Cryptographic operator authentication for AI agents: Verifying the human in the loop.
Sarkar, A., Goswami, S. S., & Sahoo, S. K. (2026). Dual-use artificial intelligence: Theoretical perspectives on AI risks, cybersecurity, governance, and ethical safeguards. Applied Research Advances, 2(1), 51–73.
Simon, J. (2026). Generative AI, quadruple deception & trust. Social Epistemology, 40(1), 101–115.
Wang, H., & Blok, V. (2026). ELSA Labs as method to study AI-based systems at the micro, meso, and macro level. In S. S. Gouveia (Ed.), The Palgrave Handbook on the Ethics of Artificial Intelligence (pp. 17–33). Palgrave Macmillan. https://doi.org/10.1007/978-3-032-15112-4_2
Figure 1. Financial Fraud Attack flowchart. A sequential model of a blended, multichannel deepfake attack.
Figure 1. Financial Fraud Attack flowchart. A sequential model of a blended, multichannel deepfake attack.
Preprints 221018 g001
Figure 2. Human-Layer Autonomous Defense Architecture for AI Autonomous Threats. Note. This architecture diagram shows how autonomous AI threat pressure is parsed into human-layer risk fields evaluated through seven design principles and translated into proportionate interventions.
Figure 2. Human-Layer Autonomous Defense Architecture for AI Autonomous Threats. Note. This architecture diagram shows how autonomous AI threat pressure is parsed into human-layer risk fields evaluated through seven design principles and translated into proportionate interventions.
Preprints 221018 g002
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.
Prerpints.org logo

Preprints.org is a free preprint server supported by MDPI in Basel, Switzerland.

Subscribe

© 2026 MDPI (Basel, Switzerland) unless otherwise stated

Accessibility

Disclaimer

Terms of Use

Privacy Policy

Privacy Settings