Submitted:
30 June 2026
Posted:
02 July 2026
You are already at the latest version
Abstract

Keywords:
1. Introduction
1.1. From Network Defense to Cognitive Defense
2. Background and Related Work
2.1. Autonomous AI and the Collapse of Human-Paced Security
2.2. Limits of Traditional Cybersecurity Awareness Training
Why Awareness Training Is No Longer Enough
3. Conceptual Framework: The Human Layer as Attack Surface
4. AI-Enabled Threat Model
4.1. Synthetic Personas and Cognitive Capture
4.2. Hyper-Personalized Phishing
4.3. Adaptive Voice Phishing and Real-Time Social Engineering
4.4. Romance and Investment Scams
4.5. Financial Fraud and Authentication Bypass
4.5.1. Deepfake Video Authentication Bypass
4.5.2. AI-Generated Executive Impersonation
4.5.3. Fake Customer Support Agents
4.5.4. Cloned Family-Member Voices
4.5.5. AI-Generated Writing-Style Mimicry
| Dimension | The Flawed Paradigm: Recognition | The Resilient Paradigm: Corroboration |
| Core Focus | Static appearance and speech | evaluating holistic cross-channel alignment |
| Vulnerability | Bypassed by synthetic audio or video cloning | Screens for behavioral anomalies and device spoofing |
| Identity Proof | Face, voice and ID verification | Multi-factor behavior and network data synergy |
| Primary Risk | High-risk payment authorization exploitation | Operational threat containment at contact centers |
5. Proposed Defense Architecture
Edge-Computed Autonomous Defense for the Human Layer
5.1. Browser-Based Defense
5.2. Device-Level Defense
5.3. Messaging Platform Defense
5.4. Banking Application Defense
5.5. Password Manager Defense
5.6. Edge-Based Autonomous Agents
6. Connected Cyber Insurance and Human-Layer Risk
6.1. From Static Coverage to Dynamic Risk
6.2. Human-Layer Risk Signals
6.3. Privacy-Preserving Insurance
6.4. Insurance as Active Resilience
7. Governance and Ethical Considerations
7.1. Explainable Intervention
- The first governance question is when a system should interrupt the user. The threshold for interruption should depend on the risk and the confidence of the detection. The concept of AIoT-driven Health Behavioral Security is useful here because it treats autonomy as something that can be supported through context-aware sensing that is real-time, but it also warns that systems must balance sensitivity to avoid false alarms and intervention fatigue (Nakamura, 2026). This means a defense agent should interrupt when the behavioral stakes are significant and not when a signal is only unusual.
- When should it block an action entirely? The second governance question is when the system should delay an action. Delays are appropriate when the action is high-impact but still plausibly legitimate. A bank transfer or password reset may not be malicious in itself. When the action occurs after a synthetic voice call or an unusual transaction pattern a delay can create the time necessary for verification. This aligns with runtime-security models that treat action execution as the critical boundary. Autonomous Action Runtime Management framework argues that AI-driven actions should be intercepted before execution for evaluation against policy, and then allowed, denied, or escalated through step-up authorization (Errico, 2026). Delay is the governance mechanism that transforms a manipulated impulse into a reviewable decision for human-layer defense.
7.2. Liability and Accountability
- Who is liable if it fails? The third governance question is when the system should block an action entirely. Blocking should be reserved for cases where the system has high confidence that the action is dangerous. A known phishing link or malware attachment may justify a hard block. The classification framework of AARM is helpful because it distinguishes forbidden actions from context-dependent actions. Some actions are always prohibited while others are allowed or denied depending on accumulated context (Errico, 2026). This distinction is essential for human-layer governance. Blocking should not be treated as the default response to uncertainty. It should be used when the action falls into a clearly prohibited category or when contextual evidence indicates that allowing it would likely cause irreversible harm.
- Who is liable if it wrongly blocks a legitimate action? The fourth governance question is how to manage false positives. Wrongly blocking a legitimate action is not a minor inconvenience. False positives can prevent lawful payments and disrupt access to funds while damaging trust in protective systems. Bulla et al. (2026) emphasize that even a small false-positive rate in high-volume payment environments can produce thousands of legitimate transaction failures which results in increasing call-center workload and customer dissatisfaction. A suspicious action should not always be blocked as it may be better to route it through additional evidence gathering or step-up verification.
- Can insurers require these systems? The fifth governance question is who is liable if the system fails. Responsibility cannot be placed only on the victim when an autonomous defense tool misses a deepfake scam or fails to detect a fraudulent transaction. Shi (2026) argues that AI-related crimes complicate liability because autonomous decision-making and multiple participants make it difficult to determine responsibility. That point applies equally to defensive failure. A governance model must distinguish between a user who ignored clear guidance and a provider whose system was negligently designed.
7.3. Privacy and Surveillance
- Could autonomous defense become surveillance? The sixth governance question is who is liable if the system wrongly blocks a legitimate action. The user may suffer real harm if an autonomous system prevents a legitimate payment or blocks access to an account. Governance therefore requires audit records and clear allocation of responsibility. The emphasis of AARM on tamper-evident receipts is useful because every action and outcome should be recorded for later review (Errico, 2026). This means a user should be able to ask questions such as “Why was this blocked?” or “What evidence was used?” Autonomous defense becomes opaque authority rather than accountable assistance without these answers.
7.4. User Override and Human Agency
- How can users understand and override defensive decisions? The seventh governance question is whether insurers can require these systems. Connected cyber insurance may legitimately require some protective measures, but requiring autonomous human-layer defense raises special concerns. Insurance may become a pathway to surveillance if insurers demand invasive monitoring of messages or behavioral activity. A better model is privacy-preserving attestation. A user should be able to prove that protective controls are active without handing over raw communications or behavioral histories. Privacy-preserving cyber-insurance frameworks based on verifiable credentials and selective disclosure point toward this governance model (Paparis et al., 2026).
- What elements are necessary for autonomy-preserving intervention? The eighth governance question is whether autonomous defense itself could become surveillance. Human-layer defense depends on sensitive signals SUCH AS identity cues and behavioral changes. These signals can protect users, but they can also expose intimate details about their lives. Nakamura (2026) specifically argues that autonomy-preserving intervention requires transparency, dynamic consent, and explainable AI. The defense system should process as much as possible locally and let users understand and control intervention intensity.
- What categories in the tiered governance model for defensive actions? The ninth governance question is how users can understand and override defensive decisions. A useful governance model can distinguish between three categories. Advisory warnings should be easy to override because the system is offering guidance rather than enforcing a hard boundary. High-risk actions should require step-up verification before override. Forbidden or unlawful actions may be non-overridable because the system has a duty to prevent policy violation. This tiered approach protects intervention while recognizing that some actions are too dangerous or legally constrained to leave entirely to momentary user choice.
8. Design Principles for Human-Layer Autonomous Defense
8.1. Human-Agency First
8.2. Edge-First Privacy
8.3. Explainable Intervention
8.4. Friction at the Right Moment
8.5. Continuous Authentication of Interaction
8.6. Insurance-Aligned Resilience
8.7. Shared Governance
9. Discussion
10. Conclusions
Key Terms and Definitions
- Human Layer: The intersection of technical systems, institutional processes and individual judgment where attention, trust, emotion and decision-making have become operational attack surfaces.
- Cognitive Defense: Cybersecurity practice that protects the psychological and decision-making conditions under which people interact with technology rather than focusing solely on infrastructure.
- Synthetic Personas: Artificial identities created through deepfakes, voice cloning and AI-generated writing that allow attackers to impersonate trusted individuals in sustained and believable interactions.
- Cognitive Capture: The moment when a target’s attention and decision-making become controlled by an artificial identity that appears authentic making compliance feel correct rather than manipulated.
- Decision Compression: The deliberate reduction of time available for reflection through manufactured urgency and authority framing, preventing victims from pausing to verify or deliberate.
- The Mythos Moment: The inflection point when AI systems demonstrated autonomous vulnerability discovery and exploit generation at machine speed collapsing the traditional time buffer cybersecurity depended upon.
- Edge-Computed Autonomous Defense: Protective intelligence deployed directly on user devices and applications to detect manipulation patterns locally while processing sensitive data on-device to preserve privacy.
- Connected Cyber Insurance: An adaptive insurance model that treats protective measures as underwriting inputs and makes coverage responsive to the insured’s ongoing defensive posture and recovery readiness.
- Synthetic Trust Attacks: Coordinated campaigns delivering identity simulation, contextual plausibility and authority cues to manufacture believable conditions under which victims lower their caution.
- Zero-Trust Human Layer: The principle of continuous verification that no interaction or request should be assumed trustworthy by default requiring constant assessment of whether requests make sense from the source, channel, timing and action involved.
References
- Abdulhamed, A.; Ranjan, P.; Xiong, S. A novel approach for distinguishing human and AI-generated texts. ACM Transactions on Asian and Low-Resource Language Information Processing., 2026. [Google Scholar]
- Adebayo, H. Human-in-the-loop explainable AI for reliable autonomous cybersecurity infrastructure. Preprints.org. 2026. [Google Scholar] [CrossRef]
- Adegoke, K. R.; Adegoke, T. B. AI-enabled fraudulent schemes and their effects on consumer trust and digital financial adoption in Nigeria. SSR J. Multidiscip. 2026, 3(1), 20–36. [Google Scholar]
- Adepu, R. Autonomous cyber defense systems powered by AI for enterprise cloud environments. Int. J. Comput. Eng. Technol. 2026, 17(2), 23–41. [Google Scholar] [CrossRef]
- Akram, M.; Khan, W.; Ahmad, N.; Imran, M.; Iqbal, M. W.; Rasheed, M. D.; Delshadi, A. M. Deepfake social engineering attacks: Detection and prevention framework.; 2026. [Google Scholar]
- Ali, U.; Mustafa, F.; Akhtar, S. Mitigating social engineering attacks using adaptive identity and access management solutions. 2026. [CrossRef]
- Ashraf, M. T. Synthetic trust attacks: Modeling how generative AI manipulates human decisions in social engineering fraud . arXiv 2026, arXiv:2604.04951. [Google Scholar]
- Atila Yörük, P. A comparative analysis of insurance protection strategies against cyber threats in Türkiye and the European Union. Can. J. Educ. Soc. Stud. 2026, 6(1), 144–160. [Google Scholar] [CrossRef]
- Bailo, P.; Sirignano, A.; Nittari, G.; Visconti, G.; Pesel, G.; Spasari, T.; Ricci, G. A review of crime at machine speed: Criminological aspects of artificial intelligence’s industrialisation of deception. Sci 2026, 8(3), 54. [Google Scholar] [CrossRef]
- Beg, S. The human firewall: Modeling AI-driven influence and human vulnerability in hybrid ecosystems. AI Soc. 2026, 1–25. [Google Scholar]
- Bhatnagar, P. AI-Based Pentesting of AI Systems Recursive Security Failures . In Technical Disclosure Commons; Defensive Publications Series, 2026. [Google Scholar]
- Bociga, D.; Lord, N. Artificial intelligence and the organisation and control of fraud. In The Research Handbook on Fraud and Society; Edward Elgar, 2026. [Google Scholar]
- Bulla, C.; Gupta, S.; Kori, A.; Panda, M. R.; Kadakal, S.; Wali, G. A comprehensive review of financial fraud detection techniques and the emerging role of adaptive agentic AI. 2026. [Google Scholar] [CrossRef] [PubMed]
- Campbell, R. Detection and mitigation of Mythos-class frontier model capabilities: A layered reference architecture. Computers 2026, 15(6), 331. [Google Scholar] [CrossRef]
- Canyakan, S. Exploring perceptual boundaries: Assessing human ability to differentiate AI-cloned from real voices. J. Interdiscip. Art. Educ. 2026, 7(1), 1–21. [Google Scholar]
- Chen, Z. Operational responsibility in AI governance: A user-centric liability framework. AI Ethics 2026, 6, 306. [Google Scholar] [CrossRef]
- Chimamiwa, G. Managing cyber risks in the face of AI- and ML-driven adversarial attacks. SBS J. Appl. Bus. Res. 2026, 71–79. [Google Scholar]
- Daoud, E.; Garcia-Blas, J.; Alawadi, S.; Carretero, J. Phishing in the age of distributed intelligence: Taxonomies, detection strategies, and the emerging role of federated learning. Prog. Artif. Intell. 2026, 1–32. [Google Scholar]
- De Gómez, W. Artificial intelligence regulation as service value in public and private sectors. In Canadian Public Policy / Analyse de politiques; 2026. [Google Scholar] [CrossRef]
- Erickson, J. The fake friend dilemma: Trust and the political economy of conversational AI . arXiv 2026, arXiv:2601.03222. [Google Scholar]
- Errico, H. Autonomous Action Runtime Management (AARM): A system specification for securing AI-driven actions at runtime. 2026. [Google Scholar] [CrossRef] [PubMed]
- Fan, S.; Zhang, L.; Yuan, X. When AI persuades: Adversarial explanation attacks on human trust in AI-assisted decision making. arXiv 2026, arXiv:2602.04003. [Google Scholar]
- Ferrara, E. The generative AI paradox: GenAI and the erosion of trust, the corrosion of information verification, and the demise of truth. Future Internet 2026, 18(2), 73. [Google Scholar] [CrossRef]
- Goldstein, G. M. Six reasons Claude Mythos is an inflection point for AI—and global security . Council on Foreign Relations. 2026. Available online: https://www.cfr.org/articles/six-reasons-claude-mythos-is-an-inflection-point-for-ai-and-global-security.
- Gonzaga, K.; Serra, S.; Gomes, M.; Malta, S. AI-powered social engineering: Emerging attack vectors, vulnerabilities, and multi-layered defense strategies. Computers 2026, 15(2), 128. [Google Scholar]
- Haider, B.; Abbas, A. Combating phishing threats through AI-enabled identity and access management frameworks. 2026. [CrossRef]
- Han, B.; Button, M. An anatomy of “pig butchering scams”: Chinese victims’ and police officers’ perspectives. Deviant Behav. 2026, 47(4), 635–653. [Google Scholar]
- Hathaway, H. M. Responsible Disclosure in the Age of AI: A Call for Urgent Action. 2026. [Google Scholar] [PubMed]
- He, P.; Fox, A.; Miculicich, L.; Friedli, S.; Fabian, D.; Gokturk, B.; Le, L. T. Co-RedTeam: Orchestrated Security Discovery and Exploitation with LLM Agents. arXiv 2026, arXiv:2602.02164. [Google Scholar]
- He, R. Data-driven actuarial modelling of cyber risk: Frequency, severity, and insurance pricing . Doctoral dissertation, University of Melbourne, 2026. [Google Scholar]
- Hussain, A.; Akhtar, S. AI-Based Behav. Anal. Phishing Detect. Secur. Access control. 2026. [CrossRef]
- Jadala, S. K. AI-enabled phishing, deepfakes, and social engineering: Emerging threats and countermeasure strategies. Int. J. AI BigData Comput. Manag. Stud. 2026, 7(2), 202–220. [Google Scholar] [CrossRef]
- Kelley, P. G.; Rousso-Schindler, S.; Shelby, R.; Thomas, K.; Woodruff, A. How generative AI empowers attackers and defenders across the Trust & Safety landscape. In Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems, 2026, April; pp. 1–21. [Google Scholar]
- Khera, V.; Sunil, R.; Mer, P.; Kointarangkul, N.; Diwan, A. Towards adaptive and continuous offensive security: A comprehensive survey of AI driven threat validation techniques. Array 2026, 100843. [Google Scholar]
- Khurram, M. S. Artificial intelligence for cybersecurity: Fundamentals, benefits and challenges.; 2026. [Google Scholar]
- Kincl, J.; Adam, M. T. P.; Pavleska, T. Human-AI integration in cybersecurity: An industry-aligned perspective on incident management. Int. J. Inf. Secur. 2026, 25, 103. [Google Scholar] [CrossRef]
- Kovačić, S.; Bilić, I. AI-enhanced social engineering: Emerging threats and human-centric countermeasures. Romanian J. Inf. Technol. Autom. Control 2026, 36(1), 63–76. [Google Scholar] [CrossRef]
- Kumar, M.; Malgaonkar, G.; P. Real-time premium adjustment models for cyber insurance using IoT device security metrics. In Proceedings of the Global Innovation and Technology Summit “AAROHAN 3.0” Engineering Track Advances in Engineering Research; Agarwal, V., et al., Eds.; 2026; Vol. 295. [Google Scholar] [CrossRef] [PubMed]
- Lazer, S. J.; Aryal, K.; Gupta, M.; Bertino, E. A Survey of Agentic AI and Cybersecurity: Challenges, Opportunities and Use-case Prototypes. arXiv 2026, arXiv:2601.05293. [Google Scholar]
- Liu, S.; Zhu, Q. Cyber insurance for cyber resilience. arXiv 2023, arXiv:2312.02921. [Google Scholar]
- Lui, A.; Miglionico, A. AI generated deepfake financial scams: A missing liability regime for consumer protection frameworks. Asian J. Comp. Law. 2026. [Google Scholar]
- Luttrell, R.; Davis, J.; Welch, C. Detecting synthetic text profiles: Human discernment versus AI analytics.; 2026. [Google Scholar]
- Malkawi, M.; Alhajj, R. AI-Powered Vulnerability Detection and Patch Management in Cybersecurity: A Systematic Review of Techniques, Challenges, and Emerging Trends. Mach. Learn. Knowl. Extr. 2026, 8(1), 19. [Google Scholar] [CrossRef]
- Nakamura, Y. AIoT-driven health behavioral security: Vision and challenges. ACM Trans. Comput. Healthc. 2026, 7(1), Article 7. [Google Scholar] [CrossRef]
- Njuguna, L. W. Deepfake cybersecurity threats: Detection and mitigation strategies. Int. J. Artif. Intell. Eng. Res. 2026, 2(01). [Google Scholar]
- Odeyinka, T. E.; Ejoh, C. I.; Abdulmalik, A. A.; Salami, I. A.; Ogunmolu, A. M. Bridging AI-automated governance, adaptive certification, behavioral authentication, and AI-agent risk monitoring in zero-trust digital infrastructures. J. Eng. Res. Rep. 2026, 28(1), 371–387. [Google Scholar]
- Oh, H.; Lee, E.; Shin, S.; Lee, K.; Pyun, M.; Lim, H. DeepAware: Using experiential deepfake simulations to enhance cybersecurity awareness in older adults. In Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems, 2026, April; pp. 1–23. [Google Scholar]
- Paparis, G.; Zarras, A.; Farao, A.; Xenakis, C. PINSA: Privacy-preserving cyber insurance framework. Clust. Comput. 29 2026, 172. [Google Scholar] [CrossRef]
- Papastergiou, S.; Basheer, N.; Lampropoulos, K.; Verrios, P.; Islam, S. Explainable AI based dynamic cybersecurity risk management for cyber insurability. Int. J. Inf. Secur. 25 2026, 36. [Google Scholar] [CrossRef]
- Pesoli, A.; Errico, H.; Cavallaro, L. Demystifying the Mythos or disrupting bugonomics? From zero-day asymmetry to defender remediation throughput. 2026. [CrossRef]
- Pokorny, L. Characterizing AI-enabled social engineering threats to U.S. national security: A mixed-methods analysis for developing defensive policy and technical countermeasures. 2026. [CrossRef]
- Rafi, M. S. Generative AI in cybersecurity: A systematic review of automated vulnerability discovery and patch generation. 2026. [CrossRef]
- Rahat, Y. O.; Islam, M. K.; Rabbani, S. F. Machine learning for identifying deepfake-driven identity abuse, authentication evasion, and customer impersonation in U.S. banking. Front. Comput. Sci. Artif. Intell. 2026, 5(4), 54–67. [Google Scholar]
- Rao, A. K.; Keller, A. J.; Kalra, N.; Steed, R.; Kwegyir-Aggrey, K.; Klyman, K.; Staheli, D.; Bergman, A. S. Challenges to the monitoring of deployed AI systems (NIST Trustworthy and Responsible AI, NIST AI 800-4); National Institute of Standards and Technology, 2026. [Google Scholar] [CrossRef]
- Shapira, A.; Gandhi, P. A.; Habler, E.; Shabtai, A. Mind the web: The security of web-use agents. In Proceedings of the ACM Asia Conference on Computer and Communications Security, 2026, June; pp. 835–851. [Google Scholar]
- Shi, J. Criminal regulation of AI crimes: The application dilemma and path optimization of the crime of assisting information network criminal activities. In Proceedings of the 1st International Conference on Politics, Law, and Social Science, 2026; pp. 27–32. [Google Scholar]
- Tashenova, Z.; Alim, A.; Gabdullin, A.; Abdikhaimov, Y.; Raiskanov, R.; Al-Tarazi, O.; Abdugulova, Z.; Amanzholova, S. Design of a multi-tier security model encompassing human factors, identification processes, and secure networking. Information 2026, 17, 537. [Google Scholar] [CrossRef]
- Upadrasta, K. AI systems cyber doctrine: Governance and operational control of algorithmic risk (Version 7.0). 2026. [Google Scholar]
- Wang, Z.; Schiller, N.; Li, H.; Narayana, S. S.; Nasr, M.; Carlini, N.; Song, D. ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks? arXiv 2026, arXiv:2605.11086. [Google Scholar]
- Xu, E.; Li, T. From fragmentation to integration: Exploring the design space of AI agents for human-as-the-unit privacy management. In Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems, 2026; pp. 1–24. [Google Scholar]
- Yang, C. AgentTrust: Runtime safety evaluation and interception for AI agent tool use. arXiv 2026, arXiv:2605.04785. [Google Scholar]
- Yang, Y.; Choi, D.; Hong, Y.; Park, J. W.; Yu, J. Y.; Kim, H. D.; Park, S. VishBox: An AI-agent-based adaptive voice phishing simulation framework for cybersecurity education. In IEEE Access.; 2026. [Google Scholar]
- Yaşar, İ. H.; Uluç, M. Cybersecurity Communication in the Age of Digital Transformation: Zero Trust, Security Culture, and Resilience. Digit. Secur. Media 2026, 3(1), 31–48. [Google Scholar]
- Yautsiukhin, A.; Kavalionak, N. A bonus and penalty mechanism as an incentive for cybersecurity investments. Int. J. Inf. Secur. 2026, 25, 47. [Google Scholar] [CrossRef]
- Yogatama, B. A.; Rimbawa, H. D. Digital watermarking and the fight against deepfake content. JATI (Jurnal Mahasiswa Teknik Informatika) 2026, 10(1), 691–698. [Google Scholar] [CrossRef]
- Zraqou, J.; Omar, K.; Alkhatib, J. Evol. Cyber Insur. Response To Artif. Intell. Risks. 2026, 66.
Additional Reading


Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).