Writing index
INTERVIEW — 25 Apr 2026

Citizens are fundamentally unprepared for the AI era

On the practical dark side of AI in Montenegro: deepfakes, voice cloning, AI-written phishing and confidential data quietly leaking into public chatbots.

Standard
Published in
Standard
Role
Interviewee

The starting diagnosis is that using AI and understanding it are two different things. Montenegro has roughly 472,000 active social media users — effectively everyone who is online — and most of them touch AI daily through chatbots and recommendation algorithms. Public attitudes split between two extremes: treating AI as an oracle that always tells the truth, and treating it as a science-fiction threat to flee from. Both come from the same gap in basic digital and AI literacy, and both leave people making business, health and parenting decisions on top of tools they cannot evaluate.

The concrete harms are already local. In 2025 fraudsters took an interview with a well-known Montenegrin doctor, altered it with AI and used it to advertise a dubious medical product on a site built to imitate a local television portal; the likeness of the prime minister and several MPs has been used for fake statements about wages, pensions and crypto. By early 2026 deepfakes had eroded trust so far that the public genuinely argued over whether videos of a fugitive were real at all — a reasonable doubt, since forensic analysis often can no longer settle the question. Voice cloning needs about three seconds of audio; an Arup employee lost 25.5 million USD in a video call where every other participant was synthetic. Roughly 82% of phishing email is now AI-generated, which removes the clumsy grammar that used to be the easiest tell.

For companies the sharpest risk is Shadow AI: employees pasting contracts, financial reports or source code into public chatbots, something research finds 77% of staff in large companies do. Samsung banned ChatGPT internally after source code went in, and Shadow AI incidents cost on average 670,000 USD more than ordinary breaches. The defensive advice is deliberately domestic and cheap — a family code word against voice-cloning calls, verification through a second known channel whenever urgency appears, and never feeding personal, medical or confidential data into free AI tools. For organisations: an acceptable-use policy, a register of approved tools, Shadow AI training, human-in-the-loop on every critical decision, and frameworks like the NIST AI RMF and ISO/IEC 42001. The EU AI Act has made AI literacy a legal obligation since February, and Montenegro, as a candidate country, will have to align.

Key findings

  • 01Roughly 472,000 active social media users in Montenegro — near-universal AI exposure, minimal AI literacy.
  • 022025 Montenegro case: a doctor's interview altered with AI to sell a product on a site imitating a local TV portal; PM and MPs' likenesses used for fake statements.
  • 03Voice cloning needs about three seconds of audio; one Arup employee lost 25.5M USD to a fully synthetic video call.
  • 04About 82% of phishing email is AI-generated — the grammar tell is gone.
  • 05Shadow AI: 77% of employees in large companies paste confidential data into public AI tools; such incidents cost on average 670,000 USD more.
  • 06Practical defences: a family code word, verification through a second channel, no sensitive data in free AI tools, and human-in-the-loop on critical decisions.
  • 07The EU AI Act makes AI literacy a legal obligation; Montenegro must align its legislation as a candidate country.
More interviews & press