Why learning is not just information transfer
Modern cognitive and educational science underscores a fundamental truth about adult learning: knowledge is not equivalent to behaviour change. Learners may be able to recall information, yet still fail to apply it in real-world contexts where automatic habits and social pressure dominate decision-making.
Knowing a rule and acting on it are different things.
A 2024 meta-analysis out of Leiden University, reviewing 69 studies on cybersecurity training, found that while training reliably shifts the precursors to behaviour — attitudes, knowledge, awareness — the actual behaviour change that follows is minimal without reinforcement and behavioural support systems.
Adults learn most effectively when training is active, contextualised, and reinforced — and when learners see direct relevance to their role and get consistent feedback over time.
AI as a tool — helpful, but not sufficient
AI-generated content and adaptive learning systems have a genuine role. A December 2025 study out of the University of Bari, run across two controlled trials with 480 participants, found that AI-generated phishing training produced measurable pre-post learning gains regardless of which prompting strategy was used — evidence that generative AI is a viable, scalable way to author training content.
But the same evidence points to clear limits:
- Training alone often fails to produce sustained behavioural change. The Leiden meta-analysis found that while awareness and attitudes improved after standard training, actual secure behaviours did not change substantially without follow-up strategies.
- Generic or unmodified AI output may deliver short-term gains but doesn't address the underlying habits and decision processes that lead to unsafe choices.
AI is best understood as one component of a broader, human-centric strategy — not a stand-alone solution.
AI is a co-pilot. It is not yet an autopilot.
It can generate the training content faster and cheaper than a person can write it by hand. It cannot yet read a room, sense which employee is quietly struggling, or decide when a policy needs a human conversation instead of another module. Those are still, for now, a person's job.
The importance of behavioural reinforcement and feedback
Training that only transmits knowledge leaves learners without the behavioural anchors they actually need. Programs that build in frequent simulations, feedback loops, and adaptive intervention show a far stronger link to improved behaviour in real organisational contexts.
studies reviewed in a 2024 meta-analysis found only minimal real behaviour change without reinforcement.
Prümmer et al., Leiden Universityaverage drop in susceptibility when training happens at the point of error, not on a fixed schedule.
Carnegie Mellon, via SoSafe meta-analysisincrease in employee reporting of suspicious emails after recent phishing-simulation training.
Verizon DBIR, 2025These outcomes happen because repeated exposure, contextual reflection, and ongoing reinforcement help learners adapt not just what they know, but how they act under pressure.
Why measurement matters
One of the biggest gaps in cybersecurity training is the absence of meaningful measurement. Automated systems can generate completion rates and quiz scores, but without deeper analysis, those figures can mislead as easily as inform.
Effective measurement goes beyond completion and looks at:
Reporting rates
Who is reporting suspicious items, and how fast?
Behavioural change over time
Is there sustained improvement across repeat exposures?
Realistic scenario outcomes
Are learners making the right call in context, not just picking an answer?
Running training without these metrics risks producing reports that look activity-rich while masking poor behavioural impact.
Human context and support networks
Cyber threats are social as much as technical. People are shaped by factors no automated platform can fully account for:
Training that accounts for these — through facilitated discussion, role-specific examples, and contextual reinforcement — fosters deeper internalisation than an isolated AI module ever can. Even the most advanced adaptive AI can't yet simulate these human and organisational dynamics without human oversight.
The Mono perspective
At Mono, we treat AI and automation as useful tools — not complete solutions. Effective learning prioritises behaviour change anchored in organisational context, with ongoing measurement and adaptive response at the centre of real-world effectiveness.
We build training that combines thoughtful human facilitation, realistic simulation, and data-driven adjustment — so learners do more than know.
They act securely.
What this means for your organisation
Knowledge ≠ behaviour
Information alone rarely produces lasting behaviour change. Completion rates tell you almost nothing about real-world security.
AI has a role — but it's not sufficient
AI can generate training content, but it needs human-centric support and meaningful measurement to produce real results.
Measurement enables improvement
Without real analytics — reporting rates, behavioural trends, scenario outcomes — training outcomes stay opaque at best.
Reinforcement and context are critical
Real learning is built on repeated practice, feedback, and relevance to daily work — not a single module completed once a year.
See how Mono puts this into practice.
Click or Flick Corporate is built on exactly the principles explored here — intelligence-driven, human-led, and designed to produce behaviour change that actually lasts. If this resonated, the program page is the natural next step.