Monday 28 Sep 2026
main news image

IN March 2026, Fortune reported that unpublished documents from Anthropic, the company behind Claude, were briefly exposed online because of a configuration mistake. Among the material was information about Claude Mythos, an advanced artificial intelligence (AI) model that Anthropic’s own preview later showed was highly capable at finding software flaws. The episode carried a lesson that reaches well beyond one company. A small oversight opened access to sensitive material. In an AI-rich environment, that kind of opening can travel far and fast.

A warning that matters in Malaysia

Malaysia should take that lesson seriously. The country is moving quickly into AI, cloud services, digital payments, connected supply chains, and data-driven operations. That momentum can support growth, better services, and greater productivity. It also raises the cost of weak governance, rushed approvals, and poor digital habits.

Research highlighted in April 2026 found that 75% of Malaysian IT decision-makers felt pressure to approve AI tools despite unresolved security concerns. The same reporting showed Malaysian organisations detect only around 33% of malicious AI activity, slightly below the global average. Those numbers point to a simple problem: many organisations are adopting powerful tools before they have built the culture and discipline to manage them well.

The public response is taking shape. Malaysia's National Cyber Security Agency — Nacsa is expected to roll out AI security guidelines in July 2026 amid growing concern over voice scams that imitate family members. Malaysia’s AI legislative framework is also expected to go to Cabinet in June 2026. These are important steps. They signal recognition, direction, and intent. They also show that the threat environment is already moving quickly. It reaches companies of every size, including SMEs that rarely have large security teams.

CyberSecurity Malaysia’s 4Q 2024 report underlines the urgency. Ransomware cases rose from nine in the third quarter to 16 in the fourth. Phishing accounted for 73% of reported fraud incidents. Ransomware locks organisations out of their own systems and demands payment. Phishing uses fake emails, messages, websites, or calls to trick people into handing over money, passwords, or confidential information. In both cases, people sit at the centre of the attack path.

Why human agency deserves investment

This is where the Anthropic episode becomes especially relevant. Advanced systems now help attackers move with greater speed, stronger targeting, and lower cost. Anthropic later disclosed a cyber-espionage campaign in which AI carried out 80% to 90% of the operational work, including identifying vulnerabilities, writing exploit code, harvesting credentials, and sorting stolen data. For business leaders, the practical meaning is clear. Cyberattacks can now be planned and adapted at a pace that puts organisations under pressure.

That is why Malaysia needs to invest in human agency amid AI. Human beings still decide whether to click, approve, transfer, disclose, ignore, escalate, or verify. They configure systems, set permissions and decide whether speed should override caution. When those choices are made under fatigue, stress, urgency, or misplaced confidence, risk grows.

Human agency becomes stronger through double literacy. Human literacy means understanding how attention, emotion, judgement, and behaviour work in daily life. It helps humans notice when fear, urgency, flattery, or familiarity are shaping a decision. Algorithmic literacy means understanding how digital systems and AI tools generate content, personalise messages, imitate voices, and influence behaviour. Together, these two forms of literacy help people stay alert, ask better questions, and make sounder decisions.

In practice, double literacy can be taught. Finance teams can rehearse how to verify urgent payment requests. Human resource staff can learn how fake resumes, deepfake interviews, or spoofed benefit messages appear. Customer service teams can practise spotting account-reset manipulation. Senior leaders can help by making it acceptable to question unusual instructions, even when they seem to come from the top. Agency grows through repetition, shared language, and permission to verify before acting. It supports calmer decisions when messages, calls, and requests arrive in a rush during busy days.

Leadership sets the standard

Cybersecurity belongs in the boardroom, in operations, in finance, in procurement, in human resources, and in every team that handles data or money. Once leaders encourage digital transformation, they also need to fund access controls, reviews, supplier checks, incident drills, and staff learning.

This is especially important because AI-generated scams are becoming far more convincing. Microsoft warned in April 2026 that phishing campaigns using AI were seeing click-through rates of 54%, compared with roughly 12% for more traditional campaigns. Training can no longer be a yearly slideshow. People need practical routines: pause, verify, call back, confirm through a second channel, and escalate early.

A company’s suppliers, vendors, and contractors matter here as well. Access should be limited. Sensitive information should be segmented. Payment approvals should be clear. Unusual requests should trigger verification. One hurried exception can create a wide opening. Regular tabletop exercises and short scenario-based drills can strengthen confidence long before a real incident arrives.

The A-Frame for your Monday morning

Awareness. Map your real digital environment. Include cloud services, AI tools, third-party access, contractor accounts, payment processes, and the locations of sensitive data. Measure where the organisation is exposed.

Appreciation. Value people as a core part of cyber resilience. Their judgement, habits, and confidence shape what happens in moments of pressure. Build Double Literacy across the workforce so staff understand both human behaviour and AI-enabled manipulation.

Acceptance. Treat regulation as a useful guide and an evolving baseline. Keep building internal discipline alongside it. Clear decision rules, rehearsed responses, and regular reviews make organisations steadier when something goes wrong.

Accountability. Put cyber risk on the leadership agenda every quarter. Assign clear ownership. Review access rights, supplier standards, staff exercises, and incident response readiness. Track whether Double Literacy training is actually reaching the people who need it most.

Malaysia's digital future will not be decided by the sophistication of its tools alone. It will be shaped by whether the people using those tools have the judgment to pause, the confidence to question, and the discipline to verify. Technology sets the conditions; people determine the outcome. Organisations that invest in both will be steadier when pressure arrives, and better placed to recover when something goes wrong. 

Dr Cornelia C Walther is associate professor at Sunway University’s Institute for Global Strategy and Competitiveness (IGSC) and senior fellow at the Sunway Centre for Planetary Health (SCPH). She is a senior fellow at Harvard, the Wharton School and an external advisor on Hybrid Intelligence at UNFPA. 
 

      Print
      Text Size
      Share