Draft, not published

Most hackers start before they turn sixteen

The people who study how AI affects us are finding it as hard to keep pace with as the rest of us.

Event
Cyberpsychology Section Annual Conference (British Psychological Society)
When
6 to 7 July 2026
Where
York (University of York)
  • Events

This is a multidisciplinary conference on how technology and the human mind shape each other, held this year in York. The room was mostly academics and students, some working clinically, a few of us from industry. The talks ranged across gaming, virtual reality, and social media, with a strong thread of children and young people, and a lot about AI. Being able to walk to it was a nice bonus.

The hacking games

One of the sponsors, The Hacking Games, gave a talk that was not at all what I expected. The global cost of cybercrime is put at somewhere between ten and twenty trillion dollars a year, roughly what the pandemic cost the world. Nearly all hackers are gamers, and a striking share of the most-wanted are young: 61% start before they are sixteen. Many begin by modding games or finding ways to cheat, their actions get more extreme over time, and a lot of them do not notice the point where they cross into something criminal.

The organisation has built an aptitude tool that reads someone’s gaming history, their public code, and their scores on its own puzzles, and produces a profile of what they would be good at in cybersecurity. It works with government to steer some of the strongest candidates towards legitimate work, often people who would not otherwise have had the opportunity. A clever way to turn a risk into a pipeline.

Protecting young minds

The keynote came from Amy Orben, whose work has fed into policy, including the UK guidance on screen time for under-fives. Her honest summary of the field was sobering: psychologists are being asked constantly about the risks of AI for different groups of people, and we will be lucky to have solid evidence for another five to ten years. Research is slow and badly funded, and the big technology companies limit the access to data that would let academics study their products properly, which she believes is deliberate.

She also had a useful warning against tech exceptionalism: treating the online world as something that must affect people in an entirely new way, rather than as another environment they live in. When there is barely an online and offline divide left, some of what we blame on a given platform may just be more of the same.

Security is a culture, not a checkbox

Anete Poriete presented a method for finding the cognitive biases that make staff vulnerable to attack, so training can be aimed where it is needed. She tested it at two companies, and the result was counter-intuitive: people at the cybersecurity firm were more relaxed about security, assuming someone else had it covered, while the finance firm’s culture made it feel like a personal responsibility and people were more proactive. IT teams sometimes did worst of all, through overconfidence, waving away the basic training as not meant for them. It chimed with something we heard at the AI Security Summit: security is a habit everyone has to hold, not a box a specialist ticks.

Where the humans fit

Nathan Hughes asked how psychology could help build safe human-AI teams, and posed good questions. What do we even mean by a team here: who is in charge, is it one AI and several people or some other shape, and should we be asking how AI fits into a well-functioning human team rather than the other way around? When pushed on what to actually do about it, the honest answer was that the field has far more questions than answers right now, which is fair enough given how new all of this is.

AI in education

The findings here were the ones I keep thinking about. Students, at school and at university, often do not trust their teachers to handle AI well, and teachers frequently admit they are out of their depth. Young people get mixed messages: AI is bad and they should not use it, but also they should use it for their homework. Most children who use AI first met it at school.

The suggested fix was to redesign assessment rather than police it: make tasks so local that a model would not have the material, focus on the process rather than the finished artefact, use spoken presentations where AI cannot sit in as a crutch, and have markers run their own questions through a model first to see how easily they can be gamed.

What I took from it

The clearest takeaway is that the people whose job is to understand AI’s effect on us are struggling to keep pace with it, even more than those of us building with it. It will be a while before they can offer much beyond caution and good questions, and that is worth remembering when anyone claims certainty about what all this is doing to us.

I had a great time. I would have felt a little out of place without a psychology background, but everyone was welcoming, and I came away with a handful of genuinely interesting conversations and a few people to stay in touch with.

Back to The Stack