The Second Congressional Commission on Education (EDCOM 2) ended its three-year examination of the Philippines’ education system with an uncomfortable conclusion: “Most Filipino learners are not mastering foundational competencies—literacy and numeracy—leading to lifelong handicaps.”
The problem does not end with literacy and numeracy. EDCOM 2’s National Achievement Test findings point to weaknesses in the skills students need to work with information itself. National averages for Grade 10 problem solving, information literacy, and critical thinking ranged from 42 to 45 points. Its National Education Plan for 2026–2035 treats the development of critical thinking and digital skills as one of six major priorities for Philippine education reform.
While none of these problems began with AI, the country will be trying to solve them in the midst of a generative AI boom. Students can now use AI tools to simplify lessons and help with homework. Those same students are also growing up alongside its more nefarious applications.
AI can generate lifelike text, images, audio, video, and online personas at scale. A polished message is not necessarily legitimate. A photograph may not document something exactly as it happened. A familiar voice may just be an imitation.
Cybersecurity usually involves passwords, firewalls, data access limits, and device protection. But some attacks do not need to defeat these at all. They just need to defeat the person. Social engineering works by manipulating someone until they willingly give up information, money, access, or control by mistake.
For a country still trying to strengthen foundational and higher-order skills, what happens when the same abilities students struggle to develop in school become part of what protects them from manipulation outside it?
THE FOUNDATIONS ARE ALREADY SHAKY
The numbers behind the learning crisis are difficult to ignore. The Organisation for Economic Co-operation and Development’s (OECD) 2022 Programme for International Student Assessment (PISA) reported that only 24% of 15-year-old Filipino students reached at least Level 2 proficiency in reading, versus the OECD average of 74%. At this level, students can identify the main idea of a moderately long text, locate information according to specified criteria, and reflect on a text’s purpose and form when directed to do so.
The World Bank’s April 2024 Philippines brief put the country’s learning poverty rate at 91%, based on the latest available pre-pandemic data. Learning poverty measures whether children by late-grade-school age can read and understand a simple age-appropriate text.
It would be a leap to take these figures and conclude that Filipino students are therefore unusually susceptible to scams, deepfakes, or social engineering. The data does not establish that. What it does establish is a serious learning problem, as deception becomes cheaper to personalize and harder to judge from appearances alone.
WHEN THE PERSON BECOMES PART OF THE SECURITY SYSTEM

AI did not invent social engineering. It changed some of its economics.
A 2026 study involving 7,700 participants used large language models to automatically search for information about individual targets and generate personalized phishing emails from what they found. The AI-personalized messages produced almost three times the click rate of generic phishing, while the researchers estimated that personalizing each message cost only around USD0.03 (just under PHP2).
Familiar AI tells are disappearing too. A 2024 assessment by the UK National Cyber Security Centre noted that generative AI can help produce phishing material without the spelling, grammatical, and translation mistakes that often signify a scam. Voice cloning and deepfakes further push impersonation beyond text.
The goal of social engineering remains the same in the age of AI: have someone believe in something long enough and strongly enough to act on it. AI makes some of the work involved cheaper, faster, and easier to repeat at scale.
That changes what the person on the receiving end has to do. Not clicking a suspicious link or sharing a one-time PIN remains good practice. But now, you also have to be wary of who is actually contacting you, recognize when urgency or emotion is being used to make you act without thinking, check whether the request makes sense, and verify it somewhere else before doing anything.
Those checks sound more like critical thinking and information literacy than traditional cybersecurity. Research suggests the connection is more than conceptual. A study published in Human Factors tested people’s ability to distinguish legitimate content from phishing emails, scam text messages, and false news headlines. Participants with lower digital literacy and lower cognitive reflection, or the tendency to reconsider an intuitive response, were poorer at distinguishing legitimate material from deception across all three.
That does not mean weaker critical thinking automatically turns someone into an easy scam victim, much less prove that Filipino students are unusually vulnerable. But the research does show that some of the mental work students practice in school can matter when they have to judge deception outside it.
Paradoxically, the same technology that makes social engineering easier is also becoming a tool students can use to avoid doing some of that mental work themselves.
THE SAME AI CAN STRENGTHEN THE SKILL. OR BYPASS IT
Generative AI can help students learn. It can simplify a difficult concept, quiz you until you know a topic’s ins and outs, critique an argument, or explain it from another angle. The problem begins when assistance becomes a permanent crutch.
A 2025 Microsoft Research study surveyed 319 knowledge workers about 936 examples of using generative AI in their work. Higher confidence in AI was associated with less self-reported critical-thinking effort, while higher confidence in one’s own ability was associated with more. The researchers also found that AI could shift cognitive work away from performing a task and toward verifying, integrating, and overseeing its outputs.
These were adult knowledge workers, not Philippine students, so the research does not show that generative AI is reducing critical thinking among Filipino learners. But the distinction it draws is useful.
Asking AI to explain why your answer is wrong requires something different from asking it for the answer. Arguing with AI is different from asking it to write the argument. Getting it to summarize everything so you never wrestle with the original material removes cognitive work that asking it to explain the section you could not understand would still require.
UNESCO’s student AI framework similarly emphasizes critical judgment of AI systems rather than simply knowing how to operate them.
While AI can remove some unnecessary effort, education has to decide which effort was never unnecessary in the first place. If reading carefully, comparing evidence, recognizing manipulation, solving unfamiliar problems, and evaluating claims help people resist social engineering, students still need opportunities to do those things themselves, away from the conveniences of AI.
SOCIAL ENGINEERING CANNOT BE HOMEWORK FOR THE USER

That does not make the student the entire security system. Skills in critical thinking, information literacy, and verification can make someone harder to deceive. But they cannot guarantee that a student will recognize every sophisticated scam. Social engineering often takes advantage of situations where judgment is rushed, distracted, emotional, or working with incomplete information.
Schools nevertheless have a role in developing that judgment. Under the Strengthened SHS Curriculum, fully implemented for incoming Grade 11 students beginning SY 2026–2027, the Department of Education identifies information, media, technology, digital literacy, and critical thinking as competencies meant to run across the curriculum. Its 2026 framework for responsible AI integration likewise calls for AI literacy while protecting human agency and judgment through risk-proportionate safeguards.
Whether students can effectively apply those lessons also depends on the systems around them. A student can be taught to verify a suspicious bank request, but that works better when the bank provides a trusted channel through which the request can actually be checked. Platforms can make impersonation harder to sustain and respond faster when fraudulent accounts are reported. AI developers can place safeguards around tools that can be abused for impersonation. Government agencies investigate fraud and set the rules under which those systems operate.
Some of that work is already happening locally. In August 2026, Meta committed to more proactive removal of harmful AI-generated deepfakes and stronger local cooperation on cybercrime investigations. The National Privacy Commission has separately clarified that a person’s face and likeness are personal information under the Data Privacy Act, and that creating or sharing AI-generated media using a person’s likeness constitutes personal-data processing.
Social engineering attacks trust. Defending against it cannot depend on teaching students to become permanently suspicious of everything.
TEACHING WHOM AND WHAT TO TRUST
Again, the answer cannot be to teach today’s students to distrust everything online. Everyday digital life would be nearly impossible if we treated every message, request, account, or interaction as hostile by default.
The better question is what earns that trust. A message from a bank should not become legitimate simply because it looks professional. A relative asking for money is not necessarily your relative because the account has the right photograph or the voice sounds right. An urgent request from somebody claiming authority should still survive a few moments of scrutiny before you act on it.
This is where the learning crisis and AI-assisted social engineering converge. A student who learns to read closely, question a claim, compare information, recognize emotional manipulation, and verify something independently is gaining more than a good exam score. Those habits can make it harder for an attacker to turn familiarity, authority, fear, or urgency into a successful scam.
The goal, then, is to teach students how to decide what deserves trust, and to build institutions and digital systems that give them reliable ways to check.
Cybersecurity Awareness Month often focuses on protecting accounts, devices, and personal information. In the age of generative AI, another part of that protection is knowing whether something deserves to be believed.
Words by Chris Noel Hidalgo
Also published in GADGETS MAGAZINE Volume 27 Issue No. 3