Security awareness has long been the unglamorous end of cybersecurity, the annual click-through module that staff endure and quietly forget. KnowBe4, the Nasdaq-listed vendor that built a business teaching workers to spot dodgy emails, is betting that generative AI can make that training stick, and it has now switched on an AI video builder for its Australian and New Zealand customers.
According to SecurityBrief Australia, the tool lets organisations generate custom training videos from simple text inputs, cutting what used to be a costly production process down to a matter of minutes. Instead of licensing a generic library of clips made for a global audience, an ANZ business can, in theory, produce material that reflects its own policies, its own branding and the specific scams doing the rounds in its industry.
Why the timing matters
The launch arrives at a moment when the economics of phishing have been rewritten by AI. The same generative tools that let a marketing team knock up a polished explainer video also let a criminal draft a flawless spear-phishing email, clone a chief executive’s voice or stitch together a convincing deepfake on a video call. The old advice about watching for spelling mistakes and clumsy grammar is close to useless when the attacker is using the same language models as everyone else.
Australian organisations have felt this sharply. The fallout from the Optus and Medibank breaches still shapes boardroom conversations, and the Australian Signals Directorate has repeatedly warned that the human layer remains the softest target. Training that is stale, generic or delivered once a year does little to move the needle. KnowBe4’s pitch is that fresh, frequent and locally relevant content is more likely to change behaviour, and that AI is the only practical way to produce it at the volume and cadence required.
The case for, and the case for caution
Supporters of this approach argue that speed is the whole point. When a new invoice-fraud tactic surfaces on a Monday, a security team should be able to warn staff by Wednesday rather than waiting for the next scheduled content refresh. An in-house video builder collapses that lag, and it lets smaller firms without a production budget compete with the polished modules that only large enterprises could previously afford. Personalisation helps too: a warehouse worker and a finance officer face very different threats, and tailored clips speak to each more directly than a one-size-fits-all reel.
The sceptics are not hard to find. Security professionals have watched plenty of technology promise to fix the human factor and then fail to shift the culture that actually drives risky clicks. There is a real danger that AI-generated video simply industrialises mediocrity, flooding staff with more content of the same forgettable kind, only faster. Poorly supervised generation can also introduce errors, an out-of-date policy reference or a subtly wrong instruction that a rushed reviewer waves through. And there is an irony worth sitting with: a tool built to help staff distrust synthetic media is itself producing synthetic media, complete with AI avatars and voices. If the training normalises slick artificial presenters, it may quietly blunt the very scepticism it is trying to sharpen.
Measurement is the other open question. Vendors in this space have historically leaned on simulated phishing click rates as their headline metric, yet a lower click rate in a controlled test does not always translate to safer behaviour under real pressure. Buyers will want to see whether AI-produced content genuinely improves outcomes or merely makes the reporting dashboard look busier.
What it means for Australia
For Australian and New Zealand businesses, the local angle is more than marketing gloss. Compliance obligations here are specific, from the Privacy Act reforms working their way through Canberra to sector rules covering banking, health and critical infrastructure under the SOCI regime. Training built for a United States audience often references the wrong regulators, the wrong reporting timeframes and the wrong cultural cues. The ability to generate material that names the Office of the Australian Information Commissioner, references Australian scam patterns and reflects local workplace norms is a genuine practical benefit for compliance teams.
Data residency is likely to be the sticking point that decides how quickly local buyers embrace the tool. Australian organisations, particularly in government and financial services, are increasingly wary about where their content is processed and whether staff likenesses or corporate material are used to train external models. Sovereign capability has become a live theme in the local market, and any AI service that touches sensitive internal content will face hard questions about hosting, retention and model training before it clears procurement. KnowBe4 will need clear answers on all three for the pitch to land with cautious CISOs.
The workforce dimension cuts both ways as well. Australia’s cyber skills shortage is well documented, and anything that lets a lean security team do more with less has obvious appeal. At the same time, automating content creation nudges the security awareness role away from production and towards curation and strategy, which is a shift the profession will need to manage rather than resist.
What is next
The immediate test is adoption. ANZ customers already on KnowBe4’s platform will be the first to trial the builder, and the early signal to watch is whether they use it to produce genuinely fresh, threat-specific material or simply to churn out more of the same. Rivals in the awareness market are moving in the same direction, so buyers can expect a wave of comparable AI features from competing vendors over the coming year, which should sharpen the questions around quality, governance and measurable impact.
The deeper question is whether AI-assisted training can keep pace with AI-assisted attackers. Both sides now draw on the same underlying technology, and the advantage will go to whoever deploys it with more discipline. For Australian organisations still recovering trust after a run of high-profile breaches, a faster way to warn and educate staff is welcome, provided it is matched by the oversight to ensure the message is accurate, the data is protected and the training actually changes what people do.
Sources: SecurityBrief Australia.



















































