By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “An Abnormal Update: AI, Email Security, and What to Expect in 2024” (June 26, 2026)

TL;DR: Email attacks remain the leading cause of cybercrime losses as generative AI increases attack volume and sophistication, while unfilled cybersecurity roles widen exposure, according to Abnormal AI. The implication is that email defence now has to scale like an industrial control problem, not a human-review problem.


At a glance

What this is: Abnormal AI’s webinar argues that AI is making email attacks more scalable and more effective while organisations remain exposed by unfilled security roles.

Why it matters: This matters because email remains a central identity and fraud entry point, so teams need controls that can keep pace with automated attack volume rather than relying on manual review alone.


Context

Email attack risk is now a governance problem as much as a detection problem. When attack volume and sophistication rise at the same time, security teams cannot assume that existing user awareness programmes or human triage will absorb the load.

For identity and access teams, the practical issue is not just phishing resistance. It is whether the organisation can scale defensive decisions across email, identity, and related access signals quickly enough to keep pace with AI-assisted abuse and staffing gaps.


Key questions

Q: How should security teams use AI-driven detection to reduce human-centric attack risk across email, cloud and collaboration tools?

A: Security teams should treat AI-driven detection as a layered control, not a replacement for policy, awareness or access governance. The strongest use case is spotting intent, context and behavioral anomalies across email, cloud and collaboration activity before a user is tricked or a compromised account can act. That means combining semantic analysis, threat intelligence and continuous monitoring to stop phishing, BEC and account takeover earlier.

Q: Why do unfilled cybersecurity roles increase email attack exposure?

A: Because gaps in staffing slow tuning, triage, and response. When analysts cannot keep up, suspicious messages wait longer, exceptions linger, and controls drift out of date. Email security then becomes less effective even if the technology stack is unchanged, because the programme cannot operate at the pace of the threat.

Q: What are the signs that traditional email security is failing against AI-driven threats?

A: Common failure signs include malicious emails reaching inboxes despite known scam patterns, phishing that reads like normal internal correspondence, and controls that depend too heavily on static rules or known signatures. If defenders cannot spot subtle behavioural anomalies or adapt quickly to new attack styles, the email security stack is already behind the threat curve.

Q: What should teams do when phishing and business email compromise converge?

A: They should treat the problem as both a fraud and identity issue, with ownership shared across security operations, IAM, and incident response. That means faster mailbox investigation, tighter access correlation, and clear escalation paths for account compromise before the attacker can convert email access into downstream loss.


Background and context

How generative AI scales email attack operations

Generative AI lowers the cost of producing convincing lures, variant-rich phishing messages, and follow-on social engineering content. That shifts the attacker model from bespoke campaigns to repeatable, high-volume targeting where variation is cheap and manual review becomes a bottleneck. The real change is operational: the attacker can test, adapt, and repackage messages faster than traditional human-led filters or awareness workflows can respond. In identity terms, this increases the number of attempts to capture credentials, tokens, or approval actions through the inbox.

Practical implication: treat email attack detection as a high-throughput control problem, not a one-off awareness problem.

Why unfilled security roles worsen email exposure

Unfilled cybersecurity roles reduce coverage across triage, tuning, incident response, and control maintenance. That matters because email defence depends on continuous adjustment of policies, detections, and exception handling. When staffing is thin, alert backlogs grow, response latency increases, and attackers get more time to exploit missed signals. In practice, personnel shortages do not simply slow work down; they create governance drift where controls are present on paper but under-operated in reality.

Practical implication: measure whether staffing gaps are delaying triage, rule tuning, or account recovery rather than assuming the tooling alone is sufficient.

Why defensive AI becomes part of the control stack

The article’s core claim is that bad AI needs good AI in response because the attack environment has outgrown manual-scale defence. Defensive AI in this context means systems that can classify, correlate, and prioritise email threats at machine speed across a large message stream. This is not about replacing human judgment in every case. It is about moving repetitive detection and first-pass analysis to automation so analysts can focus on the highest-risk identity and fraud cases.

Practical implication: place AI-assisted detection in front of analyst workflows where message volume and variant diversity exceed practical manual review capacity.


NHI Mgmt Group analysis

Email has become an industrial-scale identity attack surface: The central problem is no longer whether users can recognise a suspicious message, but whether the organisation can govern inbox-driven identity abuse at machine speed. Generative AI increases both message quality and message quantity, so the old assumption that human review can absorb risk no longer holds. The implication is that email security now sits inside the identity control plane, not beside it.

Staffing gaps are a control-quality issue, not just an operations issue: Unfilled cybersecurity roles widen exposure because they slow tuning, triage, and response across the very controls that reduce email-driven fraud. A control that cannot be maintained at pace degrades into policy theatre. Practitioners should read resourcing as part of control effectiveness, not as a separate HR metric.

Detection must shift from message inspection to behaviour correlation: AI-generated phishing matters because message content is becoming less reliable as a signal. Security programmes need to correlate sender reputation, inbox behaviour, identity anomalies, and downstream access activity rather than depend on a single malicious-content verdict. The practitioner conclusion is that email defence has to analyse interaction patterns, not just text.

Defensive AI is now a governance requirement for scale: The article reflects a wider market reality that manual-scale security operations cannot keep up with automated adversarial production. That does not make AI a silver bullet; it makes AI-assisted prioritisation a necessary layer in the control stack. Teams should treat AI as a scaling mechanism for identity and email defence, while keeping human oversight on the highest-impact cases.

What this signals

Email attack governance now depends on throughput: The question is not whether teams can detect phishing in principle, but whether they can process enough suspicious activity quickly enough to prevent compromise. When attack generation becomes cheap, the control point shifts to prioritisation, correlation, and response speed.

Defensive AI is becoming part of the identity stack: As inboxes remain a primary path into credentials and approval flows, practitioners need controls that connect email behaviour to identity behaviour. That makes email defence a shared concern across IAM, SOC, and fraud teams rather than a standalone messaging problem.


For practitioners

  • Recalibrate email risk ownership Assign email-driven identity abuse to both security operations and identity governance teams so phishing, business email compromise, and approval abuse are handled as one risk surface.
  • Automate first-pass triage Use machine-assisted classification for bulk email analysis, then reserve analyst time for high-confidence fraud, credential theft, and account takeover cases.
  • Measure control backlog and response latency Track how long suspicious messages, identity alerts, and recovery actions wait in queue, because staffing shortages show up first as delay.
  • Correlate email events with identity signals Join mailbox telemetry to authentication, access, and session data so a suspicious message can be evaluated in the context of downstream account behaviour.

Key takeaways

  • Email attacks remain a leading cause of cybercrime losses because AI is increasing both the volume and believability of malicious messages.
  • Staffing gaps worsen exposure by slowing the operational work that keeps detection and response controls effective.
  • The practical response is to pair behavioural email detection with identity correlation and automated triage so defenders can work at attack scale.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0001;TA0006;TA0009;TA0010 — Initial Access; Credential Access; Collection; ExfiltrationAI email attacks use lure delivery, credential theft, and follow-on collection patterns.
Recommendation — Map AI email attack campaigns to ATT&CK and prioritize detections for credential theft and downstream abuse.
CIS Controls v8CIS-5 — Account ManagementEmail compromise often becomes account abuse once credentials or approvals are captured.
Recommendation — Use account management controls to limit the blast radius of inbox-led compromise.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsEmail-driven compromise becomes dangerous when approvals and access entitlements can be abused.
DE.CM-09 — Monitoring for Unauthorized Personnel, Connections, Devices, and SoftwareAbnormal inbox and identity behaviour requires continuous monitoring to catch AI-driven attack scale.
Recommendation — Review entitlements that can be activated through email-based social engineering. Correlate mailbox and identity telemetry to detect unauthorized access patterns faster.

Key terms

  • AI-Driven Email Attack: An email attack that uses generative AI to produce higher-volume, more convincing lures and follow-on social engineering. The practical risk is not only better wording but faster adaptation, which can outpace manual review and increase the likelihood of credential theft, fraud, or account compromise.
  • Email-Led Identity Abuse: Email-led identity abuse is a pattern where the mailbox is used as the entry point for broader fraud or access misuse. The email itself is the delivery vehicle, but the real objective is often to exploit trust, reset credentials, approve payments, or hijack business processes.
  • Defensive AI: AI used to help security teams detect, prioritise, or investigate threats more quickly. In practice, it is useful when it reduces analyst time to decision by correlating behaviour across email, identity, and endpoint data, rather than acting as a standalone security control.
  • Security Event Triage: Security event triage is the practice of reviewing, sorting, and prioritising alerts so teams can focus on the most relevant data loss events first. In a managed DLP model, triage reduces noise, accelerates response, and helps distinguish routine activity from genuine exposure risk.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org