As automation and AI explode, artificial intelligence is positioned to become the primary force in offensive and defensive cybersecurity practices. Attackers use generative AI to launch sophisticated spear-phishing attacks and deepfake campaigns targeting individuals; they also leverage Internet-of-Behaviors data to customize attacks based on user behavior patterns. AI companionship tools, while offering emotional support and practical assistance, also pose significant security and privacy concerns. Defensively, practitioners increasingly rely on AI-based threat detection tools just to keep pace with AI-fueled external threats, simultaneously facing cognitive issues associated with AI-based cybersecurity incident responses.
With AI driving cybersecurity from both offensive and defensive angles, it seems important to remember that security is fundamentally a human phenomenon. Human-in-the-loop is a well-established design principle emphasizing human involvement in system training, tuning, and decision making to improve accuracy and safety. This approach addresses contexts where human performance of security-critical functions is imperative because fully automated systems may be restrictive, inconvenient, or dangerous. Applied to security, HITL also guides designers and operators in identifying and mitigating human errors that cause security failures, premised on the notion that humans are the weakest link. Humans are thus a necessary yet vulnerable link in the security chain.
In this special issue of Information Systems Frontiers, we invite IS security researchers to consider how to balance AI's inevitable role in the future of information security while keeping humans such as users, employees, clients, patients, and students in the loop as a research focus. As security becomes increasingly AI-oriented, behavioral IS scholarship faces a growing challenge to retain focus on human behavior, cognition, and motivation. Now more than ever, it is imperative that humans remain central to research on secure systems, training programs, and assistive technologies such as chatbots.
This special issue will consist of papers from two sources: the best submissions from an open call for papers selected on a competitive basis, and invited submissions that are substantial revisions of selected papers accepted at the 2026 Dewald Roode Workshop on Information Systems Security Research. If from the latter, the submitted manuscript is required to have more than 40% new and original technical or scientific content, distinct from the workshop paper. Authors will be required to submit a letter detailing the differences between the workshop paper and the version submitted to this special issue.