Because traditional programmes depend on users spotting obvious mistakes such as bad grammar, odd formatting, or generic language. AI removes those cues and personalises messages, so the old training model no longer matches the way the attack actually succeeds.
Why This Matters for Security Teams
AI-generated smishing changes the economics of user deception. Traditional awareness programmes were built around spotting blunt indicators such as spelling errors, odd formatting, and generic greetings. That model is increasingly weak when messages are drafted by large language models that can mimic tone, timing, and context. The operational risk is not just a higher click rate, but faster credential theft, token capture, and fraudulent approval workflows that bypass normal scrutiny.
This is a security operations problem as much as a training problem. A message can look convincing, reference real vendors or internal processes, and arrive at a moment when the target is busy, distracted, or expecting a delivery, invoice, or account alert. In that environment, the human checkpoint becomes unreliable unless it is reinforced by control design, reporting channels, and technical filtering. The NIST Cybersecurity Framework 2.0 remains useful here because it pushes organisations to treat awareness as one layer within a broader detection and response capability, not as the primary control.
In practice, many security teams discover the weakness only after a user has already complied with the message, rather than through intentional testing of the attack path.
How It Works in Practice
AI-generated smishing works because it compresses the attacker’s effort while expanding the message’s relevance. The same tooling that helps defenders summarise text can also help attackers vary tone, remove grammatical tells, localise language, and tailor the pretext to a department, supplier, or current business event. The message may not be perfect, but it is often good enough to defeat a programme that still teaches users to look for obvious defects.
Effective defence needs to shift from “spot the bad message” to “verify the request through a trusted channel.” That means combining awareness content with reporting friction, message filtering, device-level protections, and workflow controls for password resets, payment changes, and shared-document access. It also means updating simulations so that examples resemble realistic business language rather than cartoonish phishing attempts.
- Train for behavioural cues such as urgency, secrecy, and off-channel pressure, not just grammar errors.
- Require out-of-band verification for sensitive requests, especially account recovery and payment changes.
- Use mobile security controls and secure messaging gateways where enterprise messaging risk is high.
- Feed reported smishing into SOC triage so analysts can spot campaigns and block lookalike domains or numbers.
For broader control alignment, NIST guidance on governance and response is more durable than any single awareness script, and the same logic underpins identity-centric controls in CISA phishing and smishing guidance. Current best practice is to treat AI-generated smishing as a delivery mechanism for identity abuse, not merely as a literacy problem. These controls tend to break down when business processes allow urgent exceptions through text message because the attacker only needs one unverified approval path.
Common Variations and Edge Cases
Tighter verification often increases friction, requiring organisations to balance user convenience against the risk of fast-moving social engineering. That tradeoff is especially visible in high-volume environments such as retail operations, field services, healthcare, and outsourced support, where text messaging is already a normal business channel.
There is no universal standard for this yet, but current guidance suggests that the highest-risk journeys deserve stronger checks than general employee communications. For example, finance teams may need separate verification rules for invoice changes, while IT service desks may need stricter identity proofing before resetting access. AI-generated smishing can also target contractors, temporary staff, and executives, where awareness coverage is often weaker or inconsistent.
The other edge case is false confidence. A well-trained employee may still fail when the message is perfectly timed, highly personalised, and supported by a convincing reply chain. That is why NHI Management Group recommends treating the human as a signal, not a control endpoint. The message should be routed into technical detection, identity verification, and incident response workflows as quickly as possible, with lessons folded back into training and control testing.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATLAS and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST AI 600-1 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AT | Awareness training must adapt to AI-crafted smishing that evades old cues. |
| MITRE ATLAS | AML.T0058 | Generative attacks can be used to craft persuasive social engineering content. |
| OWASP Agentic AI Top 10 | LLM07 | Prompt-enabled generation can produce convincing phishing content at scale. |
| NIST AI RMF | The risk profile shifts from user error to AI-enabled manipulation and misuse. | |
| NIST AI 600-1 | GenAI-specific guidance is relevant to output abuse and deceptive content creation. |
Update training, reporting, and response controls so users verify suspicious requests off-channel.