By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “The AI Threat: Protecting State and Local Agencies from AI-Generated Email Attacks” (June 26, 2026)

TL;DR: AI-generated phishing, business email compromise, and other social engineering tactics are increasing in scale and realism across state and local agencies, according to Abnormal AI. Email remains the primary entry point, and behavioural detection is becoming more important because static defences cannot keep pace with rapidly adapting attack content.


At a glance

What this is: This session argues that generative AI is amplifying email-based phishing and BEC against public agencies, with behavioural detection positioned as the practical response.

Why it matters: It matters to IAM and security teams because email identity abuse is still a primary path into public-sector environments, and content-quality filtering alone is no longer enough.


Context

Generative AI is changing the economics of email fraud by letting attackers produce more convincing messages at scale. In public-sector environments, that matters because email remains a central identity surface for staff, contractors, and external correspondents, and the attack content now adapts faster than static controls can.

The security problem is not that email has become new. It is that the authenticity cues defenders used to depend on are easier to imitate, which weakens traditional phishing and business email compromise defences. Abnormal AI frames the response around behavioural detection, which is consistent with the need to detect anomalies in message patterns, sender behaviour, and account activity rather than rely only on content inspection.


Key questions

Q: How should public agencies respond to AI-generated phishing and BEC in email?

A: They should assume that message quality is no longer a reliable indicator of legitimacy and shift to controls that verify sender behaviour, conversation context, and the business process behind the request. Public agencies should also tighten verification for payments, credential resets, and urgent exceptions, because those are the steps AI-generated lures are designed to trigger.

Q: Why do generative AI phishing campaigns bypass traditional email controls?

A: Because traditional controls often depend on patterns that attackers can now imitate or vary cheaply at scale. Generative AI can produce highly plausible wording, but it cannot as easily hide anomalous sending behaviour, abnormal reply chains, or unusual request patterns. Those behavioural signals are where defenders need more emphasis.

Q: What are the signs that behavioural email detection is missing AI-generated attacks?

A: Repeatedly convincing messages that still produce odd sender reputation, unusual thread structure, or mismatched request timing are a strong warning sign. If users keep receiving polished lures that pass content filters but still look operationally inconsistent when viewed in context, the detection model is too focused on text and not enough on behaviour.

Q: What should teams do when email is used for approvals and handoffs?

A: They should treat the inbox as a risky trust boundary and move high-impact approvals into a separate verification flow whenever possible. Email can still notify and coordinate, but it should not be the only place where a sensitive request is both delivered and authorised.


Background and context

Why generative AI changes email attack economics

Generative AI lowers the cost of producing persuasive phishing and BEC messages, which increases both volume and variation. Attackers do not need perfect grammar or repetitive templates anymore, so message quality is no longer a reliable filtering signal. That pushes defenders toward signals that are harder to fake at scale, including sender behaviour, conversation context, and account activity. In public agencies, where many users expect external correspondence and urgent tasking, that shift makes the inbox a high-friction trust boundary.

Practical implication: tune detection to behavioural anomalies, not just message content.

Why public agencies are exposed through email identity

Public agencies concentrate a lot of human trust in email. Staff, vendors, and citizens all interact through the same channel, which gives attackers room to impersonate internal workflows, external partners, and leadership. When email is used for requests, approvals, and payment or data handoffs, the mailbox becomes an identity control point, not just a communications tool. AI-generated content makes that control point easier to abuse because the message can match the expected tone and urgency of the target organisation.

Practical implication: treat email as an identity channel and apply stronger controls around high-risk conversations.

How behavioural AI changes detection

Behavioural security looks at how users, senders, and messages behave over time rather than whether a single email looks suspicious in isolation. That approach can surface anomalies such as unusual reply chains, atypical sending patterns, and sender behaviour that does not fit the normal baseline. For AI-generated attacks, that matters because the message content can be polished while the surrounding behaviour still betrays the campaign. In practice, the value is in detecting coordinated deception before the user engages with it.

Practical implication: add behavioural models that can flag impersonation even when the text appears credible.


NHI Mgmt Group analysis

Email identity is now being attacked as a behaviour problem, not a content problem. Generative AI has made wording quality cheap, which means the old assumption that bad grammar and obvious tells expose malicious email is eroding. The practical consequence is that email security has to inspect interaction patterns, sender behaviour, and conversation drift, because the message itself is no longer a dependable trust signal.

Public agencies face a concentration risk because email still carries both trust and workflow authority. When approvals, notifications, and external exchanges all route through the inbox, a convincing message can trigger real operational action without any system compromise. That makes the mailbox an identity enforcement point, and it raises the bar for controls that rely only on user judgement or static filtering.

Behavioral detection is becoming the control layer that compensates for synthetic persuasion. Static content inspection was built for repeatable patterns, while AI-generated attacks can mutate quickly enough to bypass rule-based signatures. The field needs more emphasis on baseline deviation, account reputation, and interaction anomalies, because those signals are harder for attackers to fully normalise.

Email identity and BEC in the public sector now demand cross-domain governance. This is no longer just a messaging-security issue. It sits at the intersection of human identity, account recovery, and fraud prevention, which means defenders need to align mailbox controls, user reporting, and privileged workflow protections instead of treating phishing as a standalone awareness problem.

AI-driven phishing is creating a trust-collapse window that defenders must close at the channel level. The named concept here is the trust-collapse window: the period in which a synthetic message is convincing enough to move a user from suspicion to action. Practitioners should treat that window as a governance boundary, because once trust transfers to the message, downstream controls are already late.

What this signals

Generative AI is collapsing the value of surface-level email cues. Security teams that still depend on tone, grammar, and obvious spoofing mistakes will keep missing convincing lures. The better control model is to detect abnormal sender behaviour and risky workflow triggers before the user acts.

Public-sector phishing defense now needs identity-aware email governance. The inbox is not just a message store. It is a trust channel that can initiate approvals, payments, and account changes, so defenders should align email security with identity verification and fraud controls rather than leaving it inside awareness training alone.


For practitioners

  • Harden high-risk email workflows Require stronger verification for payment changes, credential resets, vendor banking updates, and other requests that attackers commonly exploit in public-sector inboxes.
  • Deploy behavioural email detection Look for sender, thread, and interaction anomalies that indicate impersonation even when the email text appears credible and polished.
  • Separate communication from approval Move sensitive authorisations out of reply-based email threads and into a separately governed approval path where possible.
  • Train users on AI-generated lures Update awareness material with examples of synthetic phishing and BEC so staff can recognise that realism alone is no longer a safe trust cue.

Key takeaways

  • Generative AI is making email phishing and BEC more convincing and more scalable, which weakens controls that rely on obvious textual flaws.
  • Public agencies are exposed because email still carries real workflow authority, so a believable message can trigger meaningful action without a system breach.
  • Behavioural detection matters because attacker content can be polished while the surrounding sending and interaction patterns still reveal the campaign.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0001;TA0006 — Initial Access; Credential AccessEmail phishing and BEC map to initial access and credential abuse patterns.
Recommendation — Map AI-generated email lures to initial access and credential access techniques in your detection and response program.
CIS Controls v8CIS-5 — Account ManagementAccount and workflow abuse through email depends on weak identity and approval governance.
Recommendation — Review account and approval paths that let email requests trigger sensitive actions.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsEmail-driven fraud succeeds when authorisations can be acted on without stronger verification.
Recommendation — Strengthen authorization checks around email-initiated requests that change access or money movement.
OWASP Non-Human Identity Top 10NHI-10 — Human Use of NHIEmail attackers often weaponise human trust to misuse identities and workflows behind the scenes.
Recommendation — Identify where humans can trigger privileged or identity-bound actions through email and add independent verification.

Key terms

  • Behavioural email detection: A detection approach that looks for patterns in sender behaviour, message timing, language change, and downstream user interaction rather than relying only on signatures. It is designed to catch attacks that mutate quickly. For identity programmes, its value is in finding the moment an email becomes an access risk.
  • Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
  • Synthetic Phishing: Phishing content created or heavily assisted by generative AI to appear more natural, contextual, and persuasive. In practice, it increases campaign scale and reduces the obvious mistakes defenders once used to filter malicious mail, which makes behavioural and identity-aware controls more important.
  • Email identity: The use of an email address as the practical identifier that ties a user or system to accounts, recovery, and notifications. In modern environments, email identity often becomes the trust anchor for authentication flows, which makes inbox compromise an identity problem rather than a messaging problem.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org