Security expert Fred Heiding reveals the asymmetrical nature of AI-driven social engineering, where AI evolves rapidly while the human brain remains susceptible to ancient psychological triggers.

Loading Video...
  • AI leverages 'mental heuristics' to manipulate human behavior, creating an asymmetrical advantage for attackers.
  • FBI IC3 reports show a staggering jump in fraud from $4 billion in 2020 to $21 billion in 2025.
  • Technical AI threats can be countered by AI defense, but human psychological vulnerability cannot be 'patched'.

At the recent Black Hat USA 2026 conference in Las Vegas, Fred Heiding, Executive Director of Menlo Park Intelligence, delivered a sobering analysis of the current AI landscape. While much of the industry focuses on data breaches and rogue LLMs, Heiding is sounding the alarm on a more insidious threat: the ability of frontier AI models to systematically manipulate human psychology.

The core of the problem lies in what Heiding describes as a fundamental asymmetry. In traditional cybersecurity, when an attacker uses AI to find a vulnerability in a server, defenders can deploy AI-driven patches and monitoring tools to neutralize the threat. It is a symmetrical arms race. However, when AI targets a human through social engineering, the defender is a biological entity with a brain evolved over millions of years.

Why This Matters

BozokMedia analysis shows that we are witnessing the industrialization of trust. AI can now analyze vast amounts of personal data to craft hyper-personalized lures that trigger deep-seated emotional responses—fear, urgency, or longing. Because these attacks target hard-wired human instincts rather than software bugs, the traditional 'security awareness training' is becoming obsolete. The vulnerability isn't in the system; it's in the species.

"You can't just patch me because my brain is old. It's all these old mental heuristics and systems... so we can't really do it in the same way [with people]." - Fred Heiding

The financial fallout is already evident. Citing the FBI's Internet Crime Complaint Center (IC3) report, Heiding noted that fraud costs to US citizens skyrocketed from $4 billion in 2020 to $21 billion in 2025. This exponential growth correlates directly with the proliferation of generative AI, which allows scammers to operate at a scale and level of sophistication previously reserved for nation-state actors.

Moving beyond the constraints of academia, Heiding's new research at Menlo Park Intelligence aims to explore the 'edgy' side of AI-enabled deception. This includes the potential for AI to manipulate electoral outcomes by influencing voter behavior through subtle, AI-driven psychological nudges, posing a systemic risk to democratic stability.

Did You Know?: AI can now perform 'sentiment analysis' in real-time during a phone call, adjusting its tone and vocabulary instantly to mirror the victim and build rapid rapport.
FeatureTechnical AI AttackAI Social Engineering
Defense MechanismAI-based Security SoftwareHuman Critical Thinking (Limited)
Nature of ConflictSymmetrical (AI vs AI)Asymmetrical (AI vs Human)
Primary TargetInfrastructure/CodePsychological Triggers/Trust

Frequently Asked Questions

Q1: Why can't we use AI to stop AI manipulation?
A: While AI can flag suspicious messages, it cannot 'fix' the human instinct to trust a voice that sounds like a loved one or a message that triggers a panic response.

Q2: What is the most dangerous aspect of AI scams?
A: The ability to scale hyper-personalization. AI can target millions of people individually with a unique, convincing lie tailored to their specific life circumstances.