Artificial intelligence has dominated headlines for two years, with much of the conversation focused on how it can improve productivity and cut costs. Across local government, councils are exploring how AI can support everything from customer services to administrative efficiency. But there is another side to this technological revolution that deserves equal attention: cyber criminals are embracing AI just as quickly, and often more aggressively, than legitimate organisations.
The result is a significant shift in the cyber threat landscape. Attacks are becoming faster, more convincing, and increasingly difficult to detect. For local authorities responsible for delivering essential public services and safeguarding sensitive citizen data, this should serve as a timely reminder that cyber resilience must evolve alongside technological innovation.
The new face of cybercrime
Traditional cyber-attacks often relied on poor spelling, generic phishing emails, or opportunistic scanning of internet-facing systems. Today, AI enables attackers to operate with greater sophistication and at a much larger scale. Emails can now be generated in flawless English, tailored to individual recipients using publicly available information, and crafted to imitate the tone and writing style of trusted colleagues.
Voice cloning technology can replicate senior leaders during telephone conversations, while AI-generated documents and images make fraudulent communications increasingly believable. Rather than targeting thousands of people with a single generic message, attackers can personalise every email, dramatically increasing the likelihood that someone will engage with it. The technology lowers the barrier to entry for cyber criminals while increasing the effectiveness of experienced threat actors.
Why local government is an attractive target
Councils provide services that communities depend upon every day. Housing, social care, education, planning, environmental services, elections and finance all rely on digital systems that must remain available and trustworthy. At the same time, local authorities manage vast amounts of sensitive personal information, making them attractive targets for financially motivated criminals and organised cyber groups.
A successful attack rarely affects just the IT department. It can delay essential services, disrupt payments, affect vulnerable residents, damage public confidence, and require significant resources to recover. The question is no longer whether councils are likely to be targeted. It is how well prepared they are when an attack inevitably occurs.
AI doesn't replace hackers. It makes them more effective
Despite popular perception, AI is not independently launching cyber-attacks. Instead, it is becoming an exceptionally capable assistant. It helps attackers research organisations more quickly, identify key personnel through public sources, draft convincing phishing campaigns, analyse stolen information, write malicious code, and automate repetitive tasks that previously required significant manual effort. This means cyber-attacks can be developed more rapidly, adapted in real time, and repeated at scale.
Defenders are no longer facing isolated incidents. They are confronting adversaries who can continually refine their techniques using the same technologies businesses are adopting for legitimate purposes. For those working in security roles, understanding these AI-enabled threats is becoming a core part of the job - and dedicated training such as AI for Cybersecurity Analysts is increasingly relevant for teams tasked with defending public sector systems.
Technology alone will not solve the problem
Many organisations continue to view cybersecurity primarily as a technology challenge. Firewalls, antivirus software and endpoint protection remain important, but modern attacks frequently bypass these traditional controls by targeting people and identities rather than devices. If an attacker successfully steals legitimate credentials, many security tools may see nothing unusual.
This is why identity has become the new security perimeter. Strong authentication, conditional access policies, privileged access management, continuous monitoring and rapid detection of unusual behaviour are now essential components of a modern cybersecurity strategy. Equally important is ensuring employees understand the evolving nature of AI-enabled social engineering. Awareness training must move beyond recognising poorly written phishing emails and instead prepare staff to question unusually convincing requests, unexpected financial instructions and urgent communications that appear entirely genuine.
Building cyber resilience rather than chasing perfection
No organisation can guarantee it will never experience a cyber incident. The objective should instead be resilience: the ability to detect threats quickly, respond effectively and recover with minimal disruption. For local authorities, this means regularly asking practical questions: How quickly would we know if an attacker had compromised an account? Could we identify unusual behaviour before services are disrupted? Have we tested our incident response plan recently? Are backups regularly validated through recovery exercises?
Cyber resilience is not achieved through a single technology purchase. It is built through governance, planning, continual improvement and regular testing. As AI accelerates the pace of attacks, those working in the public sector need to stay current with how these tools are being deployed - both defensively and offensively. Resources like AI for Government can help teams understand the practical applications and risks relevant to their roles.
Cybersecurity is no longer solely the responsibility of IT departments. Senior leadership teams, elected members and service managers all play an important role in managing organisational risk. Investment decisions, supplier assurance, business continuity planning and incident response all require strategic oversight. Councils that treat cybersecurity as a business risk rather than simply an IT issue are generally better positioned to respond when incidents occur.
Why this matters for government professionals
Artificial intelligence will continue to deliver significant opportunities for local government, improving efficiency and supporting better outcomes for residents. Those opportunities should be embraced. However, councils must recognise that the same technology empowering innovation is also empowering cyber criminals.
The organisations that will be most successful over the coming years are unlikely to be those with the largest security budgets. Instead, they will be those that invest in resilience, strengthen governance, educate their workforce and continuously adapt to an evolving threat landscape. The question is no longer whether AI will change cyber-attacks. It already has. The real question every council should now be asking is: Are we changing quickly enough to keep pace?
Your membership also unlocks: