By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Abnormal AI Named a Leader in the 2025 Gartner® Magic Quadrant™ for Email Security” (December 1, 2025)

TL;DR: Generative AI has accelerated targeted phishing and business email compromise, while Gartner’s 2025 Email Security Magic Quadrant places Abnormal AI as a Leader for the second year and highest in Completeness of Vision among 14 vendors. The real issue is not vendor ranking but that email security now has to keep pace with machine-speed deception and broader collaboration-tool attack surfaces.


At a glance

What this is: This is an Abnormal AI analysis of Gartner’s 2025 Email Security Magic Quadrant and the shift toward AI-driven social engineering across email and collaboration channels.

Why it matters: It matters because security teams now have to govern identity, context, and behavioural signals across an email surface where attacks are faster, more personalised, and increasingly machine-generated.


Context

Email security is no longer just about filtering malicious messages at the gateway. Generative AI has lowered the effort required to create persuasive phishing and business email compromise lures, while collaboration tools have expanded the practical attack surface beyond the inbox.

For identity and access teams, the governance problem is broader than email hygiene. It now includes how trust is established, how behaviour is profiled, and how detection and response keep pace when social engineering is produced and adapted at machine speed.


Key questions

Q: How should security teams handle AI-generated phishing that looks like normal business mail?

A: They should treat it as a trust problem across identity and workflow, not only as an email-filtering problem. The most effective response combines behavioural detection, mailbox telemetry, and fast containment actions for high-confidence cases. Security teams also need playbooks for finance, procurement, and executive correspondence, where trusted channels carry the highest fraud value.

Q: Why do social engineering attacks spread so easily across collaboration tools and email?

A: They work because these platforms are trusted for routine business interaction, which lowers user suspicion and helps attackers blend malicious messages into normal workflows. Shared files, direct messages, and meeting invitations create multiple entry points for phishing, impersonation, and credential theft. When controls are tuned only for email, attackers can move to adjacent apps and keep the same pressure on users.

Q: What are the signs that traditional email security is failing against AI-driven threats?

A: Common failure signs include malicious emails reaching inboxes despite known scam patterns, phishing that reads like normal internal correspondence, and controls that depend too heavily on static rules or known signatures. If defenders cannot spot subtle behavioural anomalies or adapt quickly to new attack styles, the email security stack is already behind the threat curve.

Q: How do organisations balance layered email security with overlapping vendors?

A: They should define which trust paths each control owns, where one vendor covers detection and another covers response or adjacent channels, and where duplicated coverage adds value versus noise. The objective is not vendor count, but clear coverage of the full social-engineering path.


Technical breakdown

Why AI changes phishing and BEC economics

Generative AI reduces the cost of customisation, language variation, and campaign volume. That matters because phishing and business email compromise historically depended on attacker labour, manual targeting, and slower iteration. With AI, attackers can tailor tone, role references, and timing at scale, which compresses the window in which defenders can spot patterns. The result is not just more phishing. It is a shift from opportunistic spam to high-confidence social engineering that blends into normal business communication. Practical implication: detection must evaluate behavioural anomalies and context, not just static indicators in message content.

Practical implication: tune controls for behavioural and contextual detection, not only content filtering.

What machine-speed defence means for email identity

Email security increasingly depends on understanding who is sending, who is being impersonated, and whether the communication pattern matches prior relationships. That is an identity problem as much as a messaging problem. Behavioural analysis can score deviations in sender history, reply chains, relationship graphs, and unusual requests that fit BEC patterns. In an AI-shaped threat model, response also needs to be more automated because manual review cannot keep up with campaign velocity. Practical implication: connect email telemetry to identity context so suspicious communications are evaluated against relationship and behaviour baselines.

Practical implication: integrate email telemetry with identity and relationship data for faster triage.

Why collaboration tools widen the email security boundary

The article points to collaboration tools becoming the new inbox, which means the attack surface is no longer limited to SMTP flows. Attackers can use chat, shared files, comments, and delegated workflow channels to establish trust and then pivot into credential theft, payment fraud, or access abuse. That broadens the governance scope for IAM and security operations because the same social engineering logic now reaches into adjacent systems where email controls do not fully apply. Practical implication: treat collaboration platforms as part of the email security control plane, not as separate risk domains.

Practical implication: extend governance and monitoring to collaboration channels that carry business trust.


Threat narrative

Attacker objective: The attacker aims to turn believable business communication into credential theft, payment fraud, or unauthorized access.

  1. Entry begins with AI-generated phishing or BEC lures that imitate trusted contacts, business processes, or ongoing conversations.
  2. Credential harvest or fraud execution follows when a recipient clicks, responds, or approves a deceptive request inside email or collaboration tooling.
  3. Impact is account compromise, fraudulent payment activity, or broader trust abuse across adjacent collaboration channels.
  • CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
  • Mailchimp breach 2022: Attackers socially engineered Mailchimp staff, used a support tool to export 102 customer lists and exposed customer API keys for phishing.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

AI-driven social engineering is now an identity governance problem, not only a content problem. Email security that focuses on message characteristics alone misses the way attackers exploit trust relationships, sender history, and business context. The article reflects a market in which detection has to reason about who should be trusted, not just what should be blocked. The practitioner implication is that email controls and identity controls need to be managed as one trust system.

Behavioural AI changes the defender’s unit of analysis. Traditional filters assume threats can be classified after delivery, but AI-generated attacks evolve fast enough that timing, relationship signals, and anomaly detection matter more than static signatures. That shifts the centre of gravity toward pre-delivery assessment and rapid post-delivery response. The practitioner implication is to measure how quickly a programme can detect impersonation, not just how well it classifies spam.

Collaboration tooling has become part of the email threat surface. Once business trust moves through chat and shared-workflow platforms, email-only governance leaves a blind spot. That widens the scope for BEC-style abuse because the attacker no longer needs the inbox alone to establish legitimacy. The practitioner implication is to align IAM, messaging security, and collaboration monitoring under a single social-engineering control model.

Multi-vendor protection reflects detection uncertainty, not procurement fashion. Gartner’s point that sophisticated social engineering can justify multiple vendors signals a market where no single detection layer is sufficient across every communication path. That does not mean overlap for its own sake; it means practitioners should re-evaluate where coverage ends and where adjacent controls must take over. The practitioner implication is to design for layered trust assurance across email, collaboration, and identity workflows.

Compliance pressure is rising alongside threat pressure. The article’s reference to FedRAMP Moderate and ISO/IEC 42001 shows that email security is being judged on governance as well as detection. Security leaders should treat assurance, model oversight, and operational transparency as part of the buying and control conversation. The practitioner implication is to make AI governance visible in email security architecture reviews.

What this signals

AI-driven social engineering forces a wider control boundary. Email security programmes that stop at the gateway will miss the trust relationships now exploited through collaboration platforms, delegated workflows, and identity-aware impersonation. The practical shift is toward one operating model for email and adjacent collaboration channels, because the attacker does not respect product boundaries.

Identity context is becoming the decisive signal. If the same sender, request type, or workflow should not normally appear in a given business relationship, that mismatch is more useful than any standalone content indicator. Practitioners should expect security operations to consume more behavioural telemetry and fewer purely static rules.

Layering is a governance response, not a procurement fad. Gartner’s observation that sophisticated social engineering can justify multiple vendors reflects a control gap across channels, not a simple preference for redundancy. Security teams should map which layer handles detection, which handles response, and which handles adjacent collaboration risk.


For practitioners

  • Map social-engineering trust paths Identify which email and collaboration workflows rely on relationship trust, delegated approval, or informal verification so those paths can be monitored as identity-bearing channels.
  • Tune detections for behavioural anomalies Prioritise sender-pattern changes, reply-chain irregularities, and unusual request timing over static content rules that attackers can now generate at scale.
  • Extend governance beyond the inbox Bring chat, shared files, and delegated collaboration features into the same monitoring and response model you use for email.
  • Validate AI governance in vendor reviews Ask how the vendor governs model behaviour, response automation, and assurance evidence such as certifications and audit scope.
  • Test layered coverage across channels Check where one control stops and another begins across email, collaboration, and identity workflows so gaps do not emerge at handoff points.

Key takeaways

  • Generative AI is making phishing and BEC faster, more convincing, and harder to catch with static email controls alone.
  • The real boundary of email security now includes collaboration channels and the trust relationships that run through them.
  • Security teams should align identity context, behavioural detection, and response automation so social engineering is handled at machine speed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack surface, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-10 — Human Use of NHIAI-driven impersonation and trust abuse overlap with human-facing NHI misuse in email channels.
Recommendation — Review email trust workflows for places where human decisions are being manipulated through machine-generated content.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on identity trust and authorisation decisions across email and collaboration paths.
Recommendation — Align access and trust decisions with relationship-aware controls across communication channels.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementAI-driven phishing and BEC are designed to steal credentials and move through business trust paths.
Recommendation — Map AI-driven social engineering to credential access and lateral movement tactics in detection engineering.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential theft and fraudulent approval flows depend on weak authenticator governance.
Recommendation — Harden authenticator lifecycle controls and watch for credential abuse exposed by phishing.
ISO/IEC 27001:2022A.5.15 — Access controlThe article’s trust boundary problem is fundamentally an access-control governance issue.
Recommendation — Apply access control governance to communication workflows that influence business decisions.

Key terms

  • AI-powered social engineering: AI-powered social engineering is the use of generated text, voice, video, or interface content to manipulate a target into taking an unsafe action. The goal is not just deception, but trust transfer, where the attacker convinces a legitimate identity holder to approve, disclose, or execute something harmful.
  • Behaviour-based email security: A security approach that judges email risk by how messages and accounts behave over time, not only by content or sender reputation. It looks for unusual reply patterns, impersonation signals, and identity-linked anomalies that traditional perimeter filters often miss.
  • Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
  • Collaboration Channel Risk: The exposure created when chat, shared files, comments, and workflow tools become part of the trust path attackers can manipulate. For identity programmes, it means email controls alone are insufficient because business legitimacy now travels across multiple connected systems.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org