Artificial intelligence is transforming the digital world at remarkable speed. It is helping companies automate services, governments process information, researchers analyze data, and citizens access knowledge more easily. However, the same technologies that improve productivity and innovation are also being adapted by malicious actors. The rise of tools such as WormGPT, FraudGPT, and other unrestricted or criminally marketed language models shows how generative AI can be used to strengthen cybercrime, especially phishing, fraud, social engineering, and ransomware operations.

The central danger is not that artificial intelligence creates entirely new forms of crime. Many cyber threats existed long before the arrival of generative AI. Phishing emails, fake invoices, impersonation scams, credential theft, ransomware, and malware campaigns are not new. What AI changes is the speed, quality, scale, and accessibility of these attacks. A criminal who once needed technical skill, strong language ability, or a team of collaborators can now use automated systems to produce convincing messages, imitate professional communication, translate scams into multiple languages, and personalize attacks against victims.

WormGPT became widely known as one of the first examples of a malicious chatbot allegedly promoted on underground forums as a tool for cybercrime. Reports described it as a ChatGPT-like system without the safety restrictions normally built into mainstream AI platforms. Security researchers and journalists connected WormGPT and similar tools to phishing, business email compromise, and fraud campaigns designed to deceive employees, companies, and individuals. The authenticity and sophistication of every criminal AI tool can vary, but the broader trend is clear: cybercriminals are interested in generative AI because it can reduce the cost of deception and increase the effectiveness of social engineering.

The National Cyber Security Centre in the United Kingdom has warned that AI will almost certainly increase the volume and impact of cyberattacks. Its assessment notes that AI is already improving reconnaissance and social engineering, making both more efficient and harder to detect. The same assessment warns that AI lowers the barrier for novice cybercriminals, hackers-for-hire, and hacktivists, particularly in access operations and information gathering.

This matters because social engineering remains one of the most common entry points into digital systems. A company can spend heavily on firewalls, endpoint protection, and cloud security, but one convincing message to an employee can still open the door to compromise. Generative AI makes those messages cleaner, more persuasive, and more difficult to distinguish from legitimate communication. Traditional phishing often contained spelling errors, unnatural phrasing, or obvious formatting mistakes. AI-generated phishing can remove those warning signs. It can imitate the tone of a manager, vendor, public official, nonprofit partner, or financial institution. It can also produce messages in the language, style, and emotional context most likely to influence a target.

The risk is especially serious for small businesses, civil society organizations, local governments, schools, and nonprofits. These institutions often hold sensitive data but lack the budget and staff of large corporations. They may not have full-time cybersecurity teams, advanced threat monitoring, or formal incident response plans. For them, AI-enabled cybercrime represents a force multiplier for attackers. A small organization may face attacks that look professional, personalized, and credible, even if the attacker has limited skill.

Another major threat is business email compromise. In this type of attack, criminals impersonate executives, vendors, employees, or partners to redirect payments, steal credentials, or obtain confidential documents. Generative AI can help attackers create messages that appear more authentic and context-aware. A fake email requesting an urgent wire transfer, a changed bank account, or access to a file may no longer look suspicious. Combined with information gathered from websites, LinkedIn, social media, public records, and previous data breaches, AI can help criminals craft highly believable narratives.

Ransomware may also become more dangerous. AI can help attackers identify targets, summarize stolen data, create more convincing extortion messages, and improve the speed of criminal operations. The NCSC has specifically noted that AI-enabled improvements in reconnaissance, phishing, and coding are likely to contribute to the ransomware threat. This does not mean every ransomware attack will be fully automated or that AI alone can replace skilled cybercriminals. More advanced operations still require technical knowledge. But AI can make existing criminal workflows faster and more scalable.

The policy challenge is therefore complex. Governments should not respond with panic or with unrealistic bans that ignore the legitimate benefits of AI. At the same time, treating malicious AI as only a private-sector security problem is insufficient. Cybersecurity is now a matter of economic stability, public trust, democratic resilience, and national security. A serious policy response must combine regulation, institutional readiness, public-private cooperation, digital literacy, and international coordination.

First, governments should promote secure-by-design obligations for AI developers and software providers. AI systems that can generate code, automate workflows, or interact with external tools should be designed with abuse prevention in mind from the beginning. This includes red-team testing, misuse monitoring, access controls, reporting channels, and safeguards against generating harmful cyber content. The goal is not to eliminate every possible misuse, which is impossible, but to raise the cost of abuse and reduce negligent deployment.

Second, organizations should adopt risk-management frameworks that treat AI-enabled cybercrime as part of their normal security planning. The NIST Cybersecurity Framework 2.0 is useful because it organizes cybersecurity around governance, identification, protection, detection, response, and recovery. NIST describes the framework as a tool to help organizations better understand and improve cybersecurity risk management, with CSF 2.0 designed for industry, government, and organizations seeking to reduce cybersecurity risks. For AI specifically, the NIST AI Risk Management Framework provides voluntary guidance for managing risks to individuals, organizations, and society, and NIST has also released a generative AI profile to help organizations identify unique risks posed by generative AI.

Third, policy should require stronger identity verification in high-risk transactions. Since AI makes digital impersonation easier, organizations should not rely on email alone for financial approvals, password resets, vendor changes, or access to sensitive systems. Policies should require multi-factor authentication, out-of-band verification, call-back procedures using known numbers, dual approval for payments, and strict controls over privileged accounts. These are not glamorous reforms, but they directly reduce the success of AI-enhanced scams.

Fourth, governments and industry should expand cyber education beyond technical teams. Every employee, public servant, school administrator, and nonprofit worker is now part of the cybersecurity perimeter. Training should focus less on spotting bad grammar and more on verifying requests, recognizing pressure tactics, protecting credentials, and reporting suspicious activity quickly. In the AI era, the old advice to “look for spelling mistakes” is no longer enough. People must learn that a message can be perfectly written and still be fraudulent.

Fifth, cyber incident reporting should be simplified and encouraged. Many organizations hide attacks because they fear reputational damage, legal consequences, or embarrassment. This weakens collective defense. Policymakers should create safe, practical reporting channels that allow victims to share indicators of compromise, suspicious domains, phishing patterns, and fraud attempts. Faster reporting helps law enforcement, cybersecurity agencies, and private companies identify criminal campaigns before they spread.

Sixth, public policy should address the criminal market around malicious AI tools. Platforms, hosting providers, payment processors, and communication services should cooperate with lawful investigations into tools openly marketed for fraud, credential theft, malware assistance, or ransomware activity. Enforcement should focus on criminal use and commercial facilitation of cybercrime, not on legitimate cybersecurity research or responsible AI development. This distinction is important because defenders also need AI tools to detect threats, analyze malware, and protect networks.

Finally, international cooperation is essential. Cybercrime crosses borders. A phishing campaign can be written in one country, hosted in another, paid for through a third, and target victims worldwide. No single government can solve this alone. Countries need shared standards, faster legal cooperation, joint takedowns of criminal infrastructure, and stronger norms against state tolerance of cybercriminal networks.

The rise of WormGPT-style tools is a warning sign. It shows that malicious actors will adapt every major technological breakthrough to their own purposes. But the future is not hopeless. The same AI revolution that empowers criminals can also strengthen defenders. AI can help detect unusual behavior, filter malicious messages, analyze threat intelligence, and accelerate response. The decisive question is whether institutions will modernize their policies quickly enough.

The best defense against AI-enabled cybercrime is not one tool or one law. It is a culture of verification, a policy of resilience, and a security model that assumes deception will become more sophisticated. In this new environment, cybersecurity is no longer only a technical discipline. It is a governance challenge, a public policy priority, and a civic responsibility.