Ripples · Champions Weekly Briefing

Week 36: Humans in the Loop

31 August 2026 · 5 min read · Andy
← All Ripples editions

31 August 2026 · A 4-minute read

Hello Champions! This week brought a wave of fresh research about how people really behave around security, much of it from a big annual conference where scientists watch how ordinary people (not experts) handle scams and technology. The common thread: as AI does more of our work, the human touch matters more, not less. Five stories, each with something you can run with this week.

1. The people who run security training say AI is now their second biggest worry

SANS, a well-known security training organisation, asked more than 1,700 people who run security programmes worldwide what worries them most. For the first time, AI came second on the list, behind only scams that trick people. The worries are practical: colleagues pasting work information into AI tools the company has not approved, and AI doing tasks no human ever checks. The same report found that changing habits across an organisation takes years of steady effort, not one big campaign. Which is exactly why Champions exist.

Evidence you can use: When someone asks whether AI at work is really a security issue, you can say that in a survey of over 1,700 security training professionals this August, AI was the second biggest people-related worry, behind only scams. That is a strong, current fact for making the case for simple AI ground rules in your team.

Learn more: SANS 2026 Security Awareness and Culture Report

2. When AI does the work, people forget to ask for safety

Researchers watched 15 professional computer programmers use an AI helper to write code. Every one of them cared about security when asked in conversation. But when they sat down and asked the AI to build something, not a single person mentioned security in their request. They just hoped to spot problems afterwards, and even the most experienced missed hidden flaws.

The lesson is not really about programming. When any of us asks an AI to draft an email, a report or a spreadsheet, we tend to skip saying what matters (keep this confidential, double-check these numbers) and then skim the result rather than truly checking it.

Try this activity: At your next team catch-up, try a two-minute experiment. Ask everyone: "When you last used an AI tool for work, did you tell it what to be careful about? And did you properly check what came back?" Then agree one team habit: say what matters in the request, and give the answer one honest read before using it.

Learn more: From Preventive to Reactive (research paper)

3. The UK's cyber experts say every AI needs a human minder

The National Cyber Security Centre (the UK government's cyber security experts) published new advice on AI "agents", which are AI tools that can take action on their own, such as sending messages or updating systems. Their advice is reassuringly human: a named person should be responsible for what each AI does, someone should be able to switch it off quickly, and AI activity should be watched the same way we would watch a new employee's work.

Talking point: If your team uses any tool with AI features, ask a simple question out loud: "Who is the human minding this?" If nobody knows, that is worth passing to your manager or security team. Not as an alarm, just as a good question that the UK's top experts think every organisation should be able to answer.

Learn more: NCSC: Managing the cyber risk of agentic AI

4. Ignoring a scam email can feel rude, and that's exactly the problem

Here is a study with real heart. Researchers watched 41 volunteers go about a pretend workday, then sent them a scam email. Those who missed the scam mostly saw it as an annoying interruption to be dealt with quickly. The surprise: some people worried that not replying might look rude or unprofessional, especially if the message seemed to come from someone senior. Politeness, one of our nicest qualities, is exactly what scammers lean on. And those who did spot the scam mostly relied on gut feeling ("something felt off") rather than on any checklist.

Try this activity: Share one sentence with your team this week, in a meeting or your team chat: "Nobody here will ever be in trouble for pausing before replying to a message, or for checking it with someone first." Say it, mean it, and watch how much easier it becomes for people to trust that little "something feels off" voice.

Learn more: Emotional responses during phishing attacks (research paper)

5. Different people fall for different tricks

Researchers at University College London examined how feeling anxious in social situations affects how people respond to manipulation. The result was not what you might guess. People who feel socially anxious were sometimes safer, because they naturally pause and double-check. But tricks that pile on social pressure ("everyone is waiting on you!") hit them harder. In other words, there is no single "careless person" who falls for scams. Each of us has a trick with our name.

Talking point: Next time scams come up in conversation, try asking: "Which trick would work on you?" It flips the mood from judging people who get caught to honest reflection, and it usually gets a better conversation going than any warning ever does.

Learn more: Social anxiety and social engineering (research paper)


That's it for this week. One sentence said out loud in a team meeting, one good question asked about an AI tool. These things seem tiny, but they travel further than you think. Have a great week, and keep making waves.

The CyBehave Team

Get Ripples in your inbox

Subscribe and choose Ripples to receive each edition the morning it publishes.