Microsoft security boss warns AI insecurity 'unprecedented' as tech goes mainstream
RSA keynote paints a terrifying picture of billion-plus GenAI users facing innovative criminal tactics


The rapid, mainstream adoption of generative AI is increasing security risks, resulting in “one of the most complex threat landscapes ever.”
So claims Microsoft's corporate vice president of security Vasu Jakkal, during her keynote speech at the RSA Conference in San Francisco this week.
"Identity-related attacks have increased by 10x just year over year. Cybercrime is both a nation-state and ransomware is a gig economy. If cybercrime was an economy, [or] a country it would be the third largest GDP in the world," Jakkal said.
Jakkal painted a grim picture of AI being a potent tool for attackers to "proliferate malware rapidly and quickly and create new variants, to password cracking more intelligently with more context."
What’s more, she warned that bad actors could abuse AI to "prey on what makes us human - our curiosity using phishing and new techniques there."
The security boss highlighted voice imitation attacks, noting "just a three-second voice sample can train a GenAI model to sound like anyone." She also flagged emerging threats like AI model poisoning, prompt injection attacks, and risks around AI training data.
Despite the dangers, Jakkal struck an optimistic tone about AI's potential benefits if secured properly, from healthcare breakthroughs to personalized education. "Imagine if we could use AI to reach the millions and billions around the world in rural corners in education," she posited.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
To better protect AI systems, Microsoft recommends a three-pillar strategy, according to Jakkal:
- Discover all AI usages and map risks
- Protect by mitigating risks through measures like zero trust and data controls
- Govern AI through risk-based policies, compliance tracking, and user education
"Governance is about human agency. It’s making sure we put ethics, [and] we put humans at the front and at the heart of technology to understand how we should build this safely, deploy this safely, and use this safely," Jakkal stated. "We need to be really thoughtful about this."
RELATED WHITEPAPER
The security leader issued a call to arms for defenders to rise to the AI security challenge: "You are the heart of trust in the heart of an organization's trust in AI. You're the ones who provide a safe and secure space for exploration. You are the Yes for AI," she said.
"I invite you to join me fearlessly, bravely, keeping security at the heart, and with care together. I invite you to freely dream big, to make our world safer, and to work together because I think it's going to be a beautiful world."
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
'You need your own bots' to wage war against rogue AI, warns Varonis VP
News Infosec pros are urged to get serious about data access control and automation to thwart AI breaches
By Rene Millman Published
-
CrowdStrike CEO: Embrace AI or be crushed by cyber crooks
News Exec urges infosec bods to adopt next-gen SIEM driven by AI – or risk being outpaced by criminals
By Rene Millman Published
-
APIcalypse Now: Akamai CSO warns of surging attacks and backdoored open source components
NEWS Apps and APIs bear the brunt as threat actors pivot to living off the land
By Rene Millman Published
-
AI is changing the game when it comes to cyber security
News With AI becoming more of an everyday reality, innovative strategies are needed to counter increasingly sophisticated threats
By Rene Millman Published
-
RSAC Chairman urges collaboration to ensure collective defense in security
News Chairman emphasizes the critical need for cooperation among cyber security experts
By Rene Millman Published
-
IT Pro Live: The future of encryption
Video AI and quantum ccomputing could be about to change the face of security forever
By IT Pro Published
-
Mobile apps now most common method of fraud
News RSA Security report highlights the rise in burner devices and rogue apps
By Bobby Hellard Published
-
Ransomware in reality: people pay
News In real life, noble intentions give way to business truths
By Jane McCallion Published