ChatGPT’s impacts will be social, not technical

Issue 8 2022 News & Events

The technology world was on fire about the latest artificial intelligence demonstration by OpenAI in the waning months of 2022, ChatGPT. It is truly a remarkable achievement; an artificial intelligence (AI) that can converse and be asked to do everything, from writing essays, to coding of computer programs.

As a computer security expert, I immediately did what came naturally to people like me; I tried to hack it. Could I get it to do something bad, something malicious? Could this be abused by criminals or spies to enable new types of cybercrime?

The answer, of course, like most tools, is yes. Someone with ill intent can abuse these miraculous scientific achievements to do things that could likely cause harm. The surprising part, however, is that the danger lies in the social arena, not the technical one.

While ChatGPT can be tricked into writing malicious computer code; that is not very scary. Computer code can be analysed by computer security products in milliseconds and be deemed malicious or safe with a high degree of certainty. Technology can always counteract technology. The problems surface when what we are trying to detect is not computer code, but rather words and meaning that will be interpreted by humans, not machines.

Two factors make this dangerous. The first is that up until now, it was not practical to have a computer create tempting lures for tricking victims to interact. The technology is now, not only available, but also so easily accessible as to be cheap, or even free. The second is that the primary way users keep themselves safe today is by noticing mistakes made by attackers in their grammar and spelling to detect that an email or communication may be from an intruder.

If we take away the last remaining sign that someone without a strong command of the language created a malicious email or chat message carelessly, how will we defend ourselves?

In my eyes, this signals the end of most computer users’ ability to discern real mail from fake. Today these tools only work well for English language text, but that is a simple training issue. The ability to write fluently in any language in the world (including computer-programming languages) is here. We must rethink our approaches to user education and implement technical measures to prevent these messages from ever making it into their inboxes.

The good news is that computers are quite good at detecting and potentially blocking most of this content. Ultimately, a spam campaign always has some sort of call to action, they may want you to phone them, reply, click a link or open an attachment. These are impossible to remove and can aid in detection. We can also train AI models to detect when ChatGPT has generated text and add a warning banner, or perhaps block the message.

The problematic situations are when we fail to block them and they end up in someone’s inbox. It is a reasonably small percentage, but it is not zero, and therefore we must prepare a defence. Having defensive layers is essential and with humans’ having reduced ability to spot a scam it is even more important that users are connecting through firewalls and web protection that can detect and block threats.

User training will need to shift away from the ‘watch for spelling mistakes’ type of messaging, and more into risk-based approaches to verification of whom you’re talking to. If asked to do something financially, with a password, or with sensitive data, pick up the phone and confirm before proceeding.

As machine intelligence continues to advance, the work of separating fact from fiction will continue to get more and more difficult. We will need to be sure we build systems that are flexible enough to combat these messages, but also educate our staff on their need to take additional steps when receiving sensitive requests over email.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The impact of misguided viral campaigns
News & Events Training & Education
For many years, traditional media have been perceived as slower, more inflexible, and less responsive compared to digital platforms. But in an ecosystem flooded with content, its value is becoming clearer: verification, context, and accountability.

Read more...
Gallagher Security strengthens KwaZulu-Natal presence
Gallagher News & Events Integrated Solutions
Gallagher Security has reinforced its commitment to the KwaZulu-Natal region with its Command the Future event. The full-day event welcomed over 100 channel partners, end users, and consultants, marking Gallagher’s third major event in Durban.

Read more...
Rise in malicious insider threat reports
News & Events Information Security
Mimecast Study finds 46% of SA organisations report a rise in malicious insider threat reports over the past year: reveals disconnect between security awareness and technical controls as AI-powered attacks accelerate.

Read more...
Centurion raises the bar at HomeSec Expo
Centurion Systems News & Events Access Control & Identity Management Residential Estate (Industry) Smart Home Automation Commercial (Industry)
Centurion Systems unveiled its latest product lines at HomeSec Expo 2026, introducing SMART+, a simpler way for installers and end users to manage their Centurion installations - as well as a few new products.

Read more...
Duxbury SA Milesight distributor
Duxbury Networking News & Events Surveillance
Duxbury Networking has been appointed the exclusive distributor of Milesight surveillance solutions in South Africa, expanding its surveillance portfolio with a platform designed to deliver AI-driven analytics, rapid deployment, and open integration for modern security environments.

Read more...
New campaign exploiting Google Tasks notifications
News & Events Information Security
New phishing scheme abuses legitimate Google Tasks notifications to trick corporate users into revealing corporate login credentials, which can then be used to gain unauthorised access to company systems, steal data, or launch further attacks.

Read more...
SMARTpod talks about HomeSec Expo 2026
SMART Security Solutions Technews Publishing News & Events Residential Estate (Industry) Videos
SMARTpod, the podcast from SMART Security Solutions, finds out more about the upcoming HomeSec Expo happening at Gallagher Estate on 4 & 5 March 2026.

Read more...
“This Is Theft!” SASA slams Mafoko Security
News & Events Security Services & Risk Management Associations
The Security Association of South Africa (SASA) has issued a stark warning that the long-running Mafoko Security Patrols scandal is no longer an isolated case of employer misconduct, but evidence of a systemic failure in South Africa’s regulatory and governance structures.

Read more...
Coordinated efforts lead to successful crime response
News & Events Surveillance Integrated Solutions
A synchronised operation involving Vumacam’s control room operators, the Johannesburg Metropolitan Police Department (JMPD), and 24/7 Drone Force, resulted in the successful identification and apprehension of a suspect linked to a reported theft case.

Read more...
2025 Global OSPAs winners
News & Events
Bringing together the very best of the global security industry, the second Global Outstanding Security Performance Awards (OSPAs) was streamed live to a worldwide audience on 05 February 2026.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.