A new AI model landed this week. Three things it changes for you
Every few months a new frontier model appears and the security industry panics for a fortnight. Here is what actually changes, and what does not.
The honest summary: the models keep getting better at language, at reading documents, and at doing both cheaply. None of that creates a new category of attack. What it does is remove the friction from three existing ones.
First, the writing. The single most reliable tell in a phishing email used to be the English - odd phrasing, wrong register, a comma where a British business would use a full stop. That tell is gone, and it is not coming back. Any advice that still says “look for poor spelling and grammar” is now actively misleading, because it teaches people to trust a well-written fake.
Second, documents. Models are now good enough to read an invoice, a contract or a set of drawings and answer questions about them. That is genuinely useful for you - and equally useful to someone who has got into a mailbox and wants to find the largest pending payment without reading three years of email.
Third, cost. What mattered about this release is not capability but price per token. Attacks that were previously worth running against a bank are now economic against a five-person plumbing firm, because the marginal cost of a tailored, well-written, contextually plausible message has fallen to roughly nothing.
What does not change: the controls. A second factor still defeats a stolen password. A callback still defeats a redirected invoice, however well written. An immutable backup still defeats ransomware. Every control we recommend is indifferent to how good the prose was that got someone to click.
The one thing we would change in your training: stop teaching spelling as a signal, and start teaching process. “Is this asking me to move money, change details, or sign in?” is a question that still works when the message is perfect.
- ✓Remove “look for bad spelling” from any staff briefing you use - it is now harmful advice.
- ✓Teach the process question instead: is this asking me to pay, change details, or sign in?
- ✓Make sure the callback rule for payment changes is written down, not remembered.
- ✓If you use AI tools yourself, check whether this release changed your supplier's training terms.
- Guidance on AI and cyber security NATIONAL CYBER SECURITY CENTRE ↗
- The near-term impact of AI on the cyber threat NCSC ASSESSMENT ↗
- Model release notes and pricing OPENAI ↗
- Phishing gets fluent: what changes for defenders THE REGISTER ↗
Links open each publisher’s live coverage of this topic.