Depends what you're targeting. For example targeting a much smaller self select group of 'computer experts' for a watering hole attack of one type or another is a great way to get in to some juicy systems.
If a system is machine readable and writable (which AI is fastly increasing this definition) you must assume that not only can you be attacked, you must assume that you are being attacked.