When AI Joins the Org Chart on Both Sides

When AI Joins the Org Chart on Both Sides

Everyone keeps asking, “How will AI change my job?”

Almost nobody is asking, “What happens when AI gets a job attacking my company?”

Over the last year, we quietly crossed that line. AI is no longer a “future problem”—it’s on the org chart, both inside and outside the firewall.

We already have AI agents running the bulk of real-world espionage campaigns, handling 80–90% of the operation with only light human supervision. We have phishing volume exploding as attackers lean on models to write perfect, localized lures at machine scale. And we’ve seen deepfake video streams of “CEOs” pull in more viewers—and more money—than the legitimate keynotes they’re impersonating.

We’re past the demo phase. AI isn’t just another productivity plugin.

It’s in your workflows, and it’s deeply embedded in your threat model.

This isn’t a thought experiment. It’s your next incident ticket.

AI as Your Coworker: Helpful, Over-Privileged, and Logging Everything

On the “legit” side, AI has already joined your staff.

Copilots answer tickets and summarize email. Models are embedded in your help desk, your EDR, your CRM, and your documentation tools. "Agents" can read SharePoint, pull from line-of-business apps, and update records on your behalf.

Most of that is sold—and bought—as efficiency. And a lot of it is.

The problem is how we onboarded these AI coworkers.

No one really did role design for them. They’re often wired straight into production data with almost no concept of least privilege. Very few people can actually answer, in plain language, which models can see which data sets—or where all those prompts and responses are being logged and stored.

If a new human employee walked in and said:

“Hi, I’d like access to everyone’s mailbox, Teams chats, finance dashboards, the ticketing system, and all your file shares so I can ‘help.’”

…there would be a process. HR. Forms. Approvals. Pushback.

For AI systems, we just ticked “Enable,” watched the demo, and moved on.

AI as Your Attacker: 24/7, Tireless, and Always Upgrading

On the other side, attackers did something very simple: they hired the same kind of coworker—but for the red team.

Give an AI agent access to the right tools, and it can already chain together full campaigns: discovery, exploitation, exfiltration. Let it write your phishing emails, and suddenly you’re not dealing with broken English and sketchy logos—you’re dealing with messages that read like your finance director wrote them, in the right language, with the right internal jargon.

Deepfakes take it a step further. We now have employees wiring tens of millions of dollars after sitting on multi-person video calls where every “executive” in the room was synthetic. We have fake keynotes with fake CEOs that look good enough to attract real-time audiences in the tens of thousands and funnel them into scams.

This is the new shape of the threat:

The email looks exactly like your vendor or your CFO. The voice on the phone sounds exactly like your CEO. The “colleague” on the video call is a model, not a human. And the campaign driving all of this doesn’t sleep, doesn’t get bored, and never decides to “try again tomorrow.”

We spent years training people to hunt for typos and off-brand graphics.

Attackers outsourced those problems to a model that writes cleaner English than half the org.

The Mental Model That’s Now Broken

Most companies still think in three simple buckets: Humans inside (employees, vendors, contractors), Humans outside (attackers), and Software (apps, SaaS, infrastructure).

AI doesn’t sit cleanly in any of those. It lives in the overlap.

It’s software that behaves like a junior analyst. It’s a tool you use to defend, and a tool attackers use to break in. It’s increasingly an autonomous actor that can chain steps together without a human watching every move.

If you keep treating AI as “just another app,” you’ll keep giving it access like “just another app”—while it behaves more like an intern with root, a key to the finance system, and absolutely no sense of risk.

The Conversation Starter: Accuracy Over Action

This isn’t the part where I pretend there’s a clean, six-step checklist that fixes all of this. It’s not about a 70-page AI policy or the latest buzzword control.

It’s about getting the picture right.

AI isn’t magic and it isn’t Skynet. It still needs access, infrastructure, and bad assumptions to do real damage. But pretending it’s just a shiny feature in your SaaS stack is exactly how organizations sleepwalk into a breach.

Most orgs are already living in this new world. Inside the firewall, AI is answering tickets, summarizing meetings, drafting code, and touching privileged data. Outside the firewall, AI is generating your phishing, writing your malware, crafting your deepfakes, and in some cases driving the intrusion itself.

The gap isn’t technology. It’s the mental model.

Once you accept that AI is now a weird hybrid of tool, coworker, and adversary, you stop making the easy assumptions. You stop handing it blanket access “because it’s helpful.” You stop pretending an AI-driven attack is a science-fiction edge case instead of a current planning scenario.

And that, for me, is the whole point of After Dark:

to drag the “future problem” into the present tense, before it shows up in your ticket queue with a case number.

The article is now in its strongest form for your intended voice: conversational, high-impact, and focused on challenging assumptions.