For more than 25 years, I’ve been the “Computer Guy” for friends, family, and colleagues who call when something digital goes sideways. Lately, those calls have changed. The questions used to be about slow computers and forgotten passwords. Now, almost every conversation circles back to the same two words: artificial intelligence.
The concern is understandable—and underscored by recent warnings from high-profile AI researchers about the threat of superintelligence. AI is in our home appliances, work products and even attends our meetings. It shapes the apps we use, the content we see, and the messages we receive. Voice assistants listen to our commands, shopping sites predict what we’ll buy next, and AI tools quietly learn from the data we create. Meanwhile, the traditional cybersecurity risks of stolen passwords, compromised accounts, and phishing emails haven’t gone anywhere. They’ve only gotten more sophisticated and harder to spot.
What frustrates me is that most of the “protection advice” floating around reminds me of Cold War–era guidance telling schoolchildren to hide under their desks during a nuclear attack: well-intentioned, but not exactly practical.
The good news is you don’t need a computer science degree to meaningfully reduce your risk. Four simple habits can help you protect your privacy, spot digital deception, and keep your accounts safer in an AI-driven world.
Two ways to limit AI’s reach into your world
Start by limiting your digital footprint. Every app permission you grant, online quiz you complete, voice command you speak, and prompt you enter can add to the data profile companies build about you.
Remove the apps you never use from your phone, then review app permissions on the ones you do use, opting out of unnecessary data collection where possible.
Always avoid sharing personal details with AI chatbots. Be especially cautious with free AI sites that use your prompts, conversations, or uploaded files to train their systems. Anything you share could be stored, analyzed, or reused in ways you did not intend. Privacy-focused options such as proton.com and duck.ai may be better choices because they are designed to reduce data collection.
You should also learn to recognize AI-generated content. AI can now create realistic fake images, videos, audio, and phishing messages that appear to come from people or organizations you trust. Verify unexpected messages, reverse-image search photos that seem unusually polished, and pause before reacting to content designed to make you angry, afraid, or excited.
Two basic cybersecurity protections to start
Even in the AI age, these are two things everyone should do to protect themselves online. It not only helps fight against human hackers but also, with AI-generated attacks.
First, use strong, unique passwords and store them in a dedicated password manager. Reusing the same password across multiple sites means one breach can expose your email, banking, shopping, and social media accounts at the same time. A password manager creates long, random passwords for each account and remembers them for you, so you only need to memorize one strong master password.
Second, enable multi-factor authentication, or MFA, on every account that offers it. MFA adds a second proof of identity, such as code from an authenticator app or a tap on a hardware security key. Even if someone steals your password, MFA makes it much harder for them to get into your account.
Some examples of how strong passwords and MFA can help include:
Deepfake Social Engineering — AI-generated voice clones or video deepfakes can impersonate trusted individuals, such as a CEO calling IT, your daughter, or your grandmother, making social engineering far more convincing. Even if an attacker successfully tricks someone into handing over their credentials, MFA ensures that stolen or socially engineered passwords alone aren’t sufficient to gain access.
AI-Optimized Password Spraying — AI can analyze publicly available data from social media and past breaches to build targeted password lists for a group of people. It then sprays the most likely passwords across many accounts while staying just below lockout thresholds to avoid detection. Strong, complex passwords are unlikely to appear on any spray list, and MFA blocks access even if a common password happens to be matched.
Four simple steps
These four habits — shrinking your data footprint, spotting AI-generated deception, using a password manager, and enabling MFA — give home users a practical first line of defense.
Cybersecurity is not something you finish once and forget. Threats evolve, and your habits should evolve with them. Start with one step today: review your app permissions, set up a password manager, or turn on MFA for your most important account. A few minutes now can prevent far bigger problems later.
- Limit your digital footprint — review app permissions and opt out of data collection
- Be careful with free AI tools — avoid entering sensitive personal, financial, medical, or work information unless you understand how the service uses your data
- Use a password manager — generate strong, unique passwords for every account
- Enable multi-factor authentication — use an authenticator app or hardware security key for your most important accounts