Article Read Time

In April 2026, the FBI released its Internet Crime Report for 2025. For the first time in the report’s nearly 25 years, it carried a section on artificial intelligence. The number attached to it was 22,364 complaints and close to $893 million in losses. That sits inside a much larger total of $20.9 billion lost to internet crime last year, a 26 percent jump over 2024.
The FBI is careful to note that the AI figure is almost certainly low. It only counts cases where the victim knew enough to say AI was involved. Most people who get a convincing phone call never find out what made it convincing.
I bring that up not to alarm you. I bring it up because the federal government just started counting, and that tells you where we are. AI is no longer a topic for conference panels. It is showing up in your inbox, on your phone, and in the software your office already pays for. So it is worth sitting down and being clear-eyed about what it does well and what it does badly.
What AI is genuinely good at
Start with the honest good news, because there is some.
AI is very good at watching. A small city or a 30-person business generates more security events in a day than a person can read in a week. Failed logins, new devices, odd file transfers, a laptop signing in from two states at once. Software that uses AI to sort through that noise can flag the handful of things worth a human look. That is real value, and it is the reason your bank catches a stolen card faster than it did ten years ago.
It is also good at speed. When a piece of malicious software lands on a machine, minutes matter. Tools that can isolate that machine automatically, before anyone opens an email about it, buy you time you would not otherwise have.
And it lowers the floor on expertise. A city clerk can now paste a suspicious email into a tool and get a plain explanation of why it looks wrong. Ten years ago that answer required a consultant. For organizations that have never had a full-time IT person, that is a meaningful change.
What AI is doing for the other side
Now the other half, and it is the half most people underestimate.
The old advice for spotting a scam email was to look for bad grammar and odd phrasing. That advice is dead. Any attacker anywhere in the world can now produce clean, professional English that sounds like it came from your vendor, your insurance carrier, or your county attorney. The tell we taught people for twenty years is gone.
Voice is the bigger worry. Cloning someone’s voice used to take a studio. Now it takes a short clip of them talking, and most elected officials, pastors, and business owners have plenty of those posted publicly. The attack is not exotic. Someone calls your bookkeeper, sounds like you, and says the wire instructions changed. That is it. That is the whole scam, and it works because the voice is right.
AI also lets attackers work at volume. Research that once took an hour per target now takes seconds, so the small organizations that used to be too much trouble are now worth the effort. If you ever told yourself you were too small to be a target, that math has changed.
The part nobody puts in a brochure
There is a third category, and it is the one I see least discussed. It is the risk that comes from your own AI tools.
Every time a staff member pastes something into a chatbot, that information leaves your building. Draft contracts, payroll files, resident complaints, patient names. Ask where that data goes, who can see it, and how long it is kept. If the vendor cannot answer plainly, that is your answer.
The newer worry is AI that acts on its own, sometimes called agentic AI, meaning software that takes actions instead of just answering questions. On May 1, 2026, CISA and its international partners published guidance on this, written specifically with small businesses and local governments in mind. Their advice is refreshingly unglamorous. Do not give these tools broad access. Start with low-risk tasks. Treat them like any other system you have to secure, not like a science project.
What I would actually do
If you run a small business, a city office, or a non-profit, here is where I would put my attention.
Verify money by the voice you called. Not the number in the email. Not the voice that called you. A number you already had, dialed by you. This single habit defeats nearly every version of this attack, including the AI ones.
Turn on a second login step everywhere, especially email, which is the master key to everything else.
Pick a household word with your family and a code phrase with your finance staff. It feels silly right up until the day it saves you $40,000.
And be skeptical of any product sold to you as AI-powered protection. Ask what it actually does, what it costs after year one, and what happens when it is wrong. Some of these tools are good. Some are the same product with a new sticker on the box.
The technology changed. The fundamentals did not. Slow down, verify, and keep the boring habits, because the boring habits are the ones that still work when the voice on the phone sounds exactly like your mayor.
If you are trying to sort out which of these tools are worth your budget and which are a sticker on a box, we are glad to talk it through. No pitch, no obligation. Call Commonwealth Sentinel at 502-234-5554 and ask for a plain answer. If we think you can handle it yourself, we will tell you that.
