
There is a call that comes at the right time. The voice is familiar but not quite placeable, warm in a way that feels earned rather than performed.
Details surface that seem impossible to fake: a shared contact from a conference three years ago, a known preference for afternoon calls, and a reference to a project mentioned in a LinkedIn post months back.
For companies evaluating AI tech consulting as a way to harden operations and build smarter internal infrastructure, there is a particular vertigo in discovering that the same technologies they hope to apply for competitive advantage are being turned, quietly and at scale, against the organizations they do business with. That unsettling possibility has a name now: predatory personalization.
The term is blunter than the usual security industry vocabulary, which tends toward acronyms and abstract threat categories.
Consulting services focused on artificial intelligence are starting to encounter it as a practical concern in client conversations, not a theoretical construct pulled from a threat report.
And while the phrase is new, what it describes has been taking shape for several years, accelerating steadily as the relevant tools became cheaper and the barriers to deployment dropped toward zero.
Somewhere between the commercial availability of voice cloning tools and the normalization of large-scale social graph analysis, a category of fraud emerged that does not look much like fraud at all. It looks like a trusted colleague.
The World Economic Forum’s 2025 Global Risks Report placed AI-enabled identity fraud and synthetic impersonation among the fastest-moving commercial threats of the current period, noting that the gap between what machines can simulate and what humans can reliably detect has narrowed faster than most enterprise risk functions have adapted.
Building a Person from Scratch
Start with what is freely available. The average mid-level executive at a company of any real size has left a substantial public record: LinkedIn posts going back years, panel recordings on YouTube, conference photographs, and a network of tagged connections that maps organizational relationships more clearly than any org chart.
Voice patterns get extracted from those recordings. From follower lists and tagged photographs, a relationship graph takes shape.
What gets built in the end is a behavioral profile capturing not just what the person knows, but how they speak, what they defer to, and what kind of small talk registers to them as warmth rather than performance.
The result is an interaction model, and from that model, an agent is deployed — something that sounds like a trusted peer, references the right mutual names, and adjusts its tone in real time as the conversation unfolds.
This is industrialized social engineering as a business model. Not a skilled actor working one mark over weeks, but a system whose economics flip the old logic of targeted fraud: when the cost of research falls to near zero, and the quality of simulation keeps rising, it becomes rational to aim sophisticated attacks at targets who would previously have been too much work.
Already having evolved beyond compromised credentials into fabricated identities with constructed histories, business email compromise is no longer the fraud category it was five years ago.
The Federal Bureau of Investigation Internet Crime Report documented AI-driven BEC losses well into the billions, with a sharp rise in cases involving synthetic voice correspondence and generated written communication.
Infrastructure for running these campaigns is commercially available on criminal marketplaces, often at a lower cost per interaction than a legitimate outbound sales team would spend, and the barrier to entry keeps falling.
The Verification Problem Nobody Wants to Own
Categorically, most organizations treat fraud prevention as a financial controls problem. Social engineering gets filed under HR training: annual sessions, updated slides, and then largely forgotten until an incident resurfaces it.
Predatory personalization fits neither bucket. It touches data privacy, identity verification, AI governance, and internal communication culture at the same time, and few companies have a single owner across all of those domains.
Security awareness training updates on annual cycles. Attack methods update in weeks. Attackers are spending considerably more time on pre-attack research per target than in any prior period.
That pattern is consistent with what personalization at scale produces: the upfront cost of building a convincing persona shifts to machines, and the marginal cost of running that persona against each additional target approaches zero. When economics shifts that sharply, volume follows.
Here is what enterprise security teams engaged in AI tech consulting are now being asked to map and defend against, in practice:
- Fabricated executives delivering wire transfer instructions by voice, generated from real recorded speech samples.
- AI-produced client contacts who conduct weeks of plausible email correspondence before requesting contract modifications.
- Synthetic vendor representatives seeded across LinkedIn and email months before any direct ask.
- Sales agents calibrated to mirror a prospect’s communication style and professional concerns so closely that the interaction reads as a pre-existing relationship.
Firms like N-iX, which operates in the AI tech consulting space, are increasingly fielding early-stage requests from enterprise clients who want to understand their exposure before an incident forces the conversation.
The findings, once the mapping is done, tend to be uncomfortable. Most organizations have more surface area than they realized.
Defense requires more than refreshed awareness sessions. Behavioral biometrics and out-of-band identity confirmation both narrow the attack surface.
Equally useful, and rarely appearing on any security roadmap, is publishing less about employees and internal structures than most companies currently do — removing the raw material that persona construction depends on.
Organizations turning to AI-focused consulting teams for guidance on this threat often find that data minimization, unglamorous as it sounds, is among the more effective options available.
Conclusion
Predatory personalization adds something most risk registers have not caught up to: the possibility that trust, the currency on which business relationships run, can now be manufactured at an industrial scale and aimed at the people who depend on it most.
The practice of AI tech consulting has grown partly because the risks attached to deploying AI are real and layered, and partly because the risks of ignoring them keep growing. The friendly voice on the other end of the call may never have existed. That is the more important fact to sit with.