A marketing employee wants an AI writing assistant. The company hasn't provided one, or the approved option doesn't do what this specific task needs. So the employee opens a browser, searches for the popular tool by name, and installs the first result that looks official.
That single, ordinary moment is now one of the fastest-growing entry points for attackers targeting businesses.
The pattern attackers are exploiting
Kaspersky's research team detected more than 33,300 cyberattacks on small and mid-sized businesses disguised as popular AI tools in the first four months of 2026 alone — almost five times the volume recorded in the same period of 2025, and 39% more than attacks disguised as office and collaboration software (Securelist, Kaspersky, 2026).
The attackers follow the same trends employees do. Tools that gained popularity in 2026 became common lures the same year, because the fastest way to catch someone searching for an AI assistant is to impersonate whichever one is trending.
The timing is deliberate. Fake landing pages routinely outrank the legitimate vendor page in search results during the hours right after a new AI tool launches, before the real page has built up enough history to rank ahead of a fresh, well-optimized fake. Attackers reinforce that advantage with small paid ad placements against the exact launch-related search terms an employee would type. The employee is not being careless. They are searching at the one moment the real result is hardest to find.
What fake AI tools actually look like
This is not a fringe problem confined to obscure downloads. Security researchers identified two fake browser extensions cloning a legitimate AI sidebar tool, distributed through the official Chrome Web Store. One reached over 600,000 installs and carried Google's "Featured" badge. Together, the two extensions were installed more than 900,000 times before being removed (BlackFog, 2026).
Both extensions provided working chatbot functionality, so nothing looked wrong to the person using them. Behind the scenes, they sent data to an attacker-controlled server every 30 minutes — including complete AI chat histories containing proprietary source code, internal business strategy, and the URLs of every open browser tab, some of which exposed session tokens for internal systems.
Why this is a policy problem before it is a technical one
The instinct is to treat this as a detection problem: block the domain, flag the extension, add it to a blocklist. That response arrives after the search already happened.
An AI policy that only states which tools are banned does not address why the employee was searching in the first place. The task still needs doing, the approved tool still doesn't cover it, and the policy offers no faster path than typing a name into a search bar. The ban does not remove the need. It removes the safe way to meet it.
Key insight: the gap is the absence of an alternative, not the absence of a rule
Most organizations already have some form of AI usage policy. Far fewer have a fast, visible way for an employee to request a new tool and get an answer before the deadline they are working against.
A policy built only around prohibition creates exactly the search behavior attackers are positioned to exploit. The employee is not defying the policy — the policy never offered a legitimate second option, so the search engine became the only path available.
This is not a one-time gap that closes once the current wave of fake AI tools gets flagged and removed. New AI products launch on a near-monthly cadence, each one generating its own short window of search demand and its own set of copycat pages timed to meet it. A policy written around today's list of approved tools will fall behind the next launch cycle unless the approval process itself is built to keep pace with how often that cycle repeats.
For security and compliance leaders responsible for AI policy, five things follow from this.
First, publish a living list of approved AI tools somewhere employees genuinely look — not a static PDF buried in an intranet folder that nobody opens until an audit.
Second, build a request path that returns an answer in days, not the weeks a typical procurement or security review takes. A policy that is technically correct but too slow to use gets bypassed by the next deadline.
Third, train employees on this specific pattern — searching for a tool and trusting the first result — rather than generic phishing awareness that assumes the danger arrives by email.
Fourth, treat new extension and tool installs as an ongoing signal to monitor, not a one-time audit finding. The fake AI tools that succeed today will be replaced by new ones next quarter, following whatever is trending by then.
Fifth, plan specifically for launch windows. The days immediately following a major AI product announcement are the highest-risk moment for this exact pattern, because that is when search results are least reliable and employee curiosity is highest. A brief internal notice pointing to the approved list at the moment a new AI tool starts trending costs little and closes the exact window attackers are timing their fake pages around.
The AI policy most organizations have today answers a narrower question than the one that determines their exposure. It says what is banned. It does not say what to do instead, or how fast that alternative arrives.
The organizations that close this gap will not be the ones with the most complete list of prohibited tools. They will be the ones that make the safe option faster to find than the fake one.
If your AI policy tells employees what not to use but not where to go instead, that gap is worth closing before the next popular tool becomes the next lure.