By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Abnormal AI Innovation: Engineering Personalized Security Training at GenAI Speed” (July 15, 2025)

TL;DR: Hyper-personalised phishing simulations now use real, org-specific threats, user context, and human review to make awareness training more relevant while AI tools also sped up delivery of the MVP, according to Abnormal AI. Generic awareness programmes are losing force because the control problem is contextual identity governance, not just content volume.


At a glance

What this is: This is a product and strategy post about AI-driven phishing coaching that personalises simulations, training videos, and delivery using user context and real threats.

Why it matters: It matters because awareness programmes now intersect with identity data, campaign governance, and human behaviour controls, which IAM and security teams must manage deliberately.


Context

Hyper-personalised phishing training treats awareness as a context problem rather than a volume problem. The article describes a system that uses role, location, manager data, susceptibility history, and recent threats to shape simulations, while also using human review before campaigns launch.

For IAM, IGA, and security awareness teams, the governance question is how far identity context should flow into training systems and who validates that context before it is used. The article also shows that GenAI is now part of both the training content pipeline and the development workflow, which raises the bar for oversight even when the use case is defensive.


Key questions

Q: How should security teams govern hyper-personalised phishing simulations?

A: They should treat the simulation pipeline as a governed security workflow, not a marketing-style content exercise. That means defining which identity fields can be used, who approves the template, how PII is removed, and how campaign data is retained. The point is to preserve realism without creating a new privacy, trust, or misuse problem.

Q: Why do generic phishing training programmes lose effectiveness?

A: Generic programmes fail because they ignore context. Users see the same lures repeatedly, so the content becomes easy to predict and easier to dismiss. Personalisation matters when it reflects real role, threat, and timing context, but it only works if the organisation can govern that context carefully and consistently.

Q: Generative AI Security Risk

A: Generative AI security risk is the chance that a generative model, its prompts, outputs, training data, or integrations will cause harm to systems, data, or people. It includes prompt injection, data leakage, unsafe code generation, model manipulation, and misuse of generated content across identity, cloud, application, and SOC workflows.

Q: How do teams keep AI-generated training from becoming another unmanaged risk channel?

A: They should combine approval gates, content sanitisation, audit logging, and role-based access control around the workflow. That keeps the training system aligned with security governance rather than letting model output bypass the controls already used for sensitive identity and campaign data.


Technical breakdown

How hyper-personalised phishing simulations are assembled

The simulation engine described here starts with real threats associated with a tenant, then uses generative models to transform them into safe templates by stripping PII. It does not rely on generic lures. Instead, it injects user-specific context such as role, manager, location, prior susceptibility, and recent threats to tailor the scenario. That means the control is not just about message realism. It is about matching the simulation to the behavioural and organisational context that makes a user more or less likely to respond.

Practical implication: teams should treat simulation content as governed identity context, not as a static awareness asset.

What just-in-time coaching changes in awareness control

Just-in-time training shifts awareness from periodic instruction to event-triggered reinforcement. In the article, user interactions with a simulation trigger immediate coaching whether the user passes or fails, which means the feedback loop is tied to behaviour rather than to a training calendar. That matters because the learning moment arrives while the user still remembers the phish. It also changes the operational model: awareness systems now need reliable detection of interaction states and clear rules for which responses are delivered in each case.

Practical implication: define the trigger logic and review path for coaching content before putting behavioural feedback into production.

Why AI-assisted training production still needs governance

The video-training workflow described in the article uses LLMs for scripts, an avatar service for delivery, and a private storage and distribution chain for access control. That makes the content pipeline faster, but it also creates more places where quality, branding, and access controls can fail. The human-in-the-loop panel is therefore central, because it lets admins preview and validate simulations before launch. In practical terms, the system is only as trustworthy as the review and storage controls around the model outputs.

Practical implication: apply approval, sanitisation, and access controls to AI-generated training assets before they reach users.


NHI Mgmt Group analysis

Hyper-personalised awareness is now an identity governance problem, not just a training problem: Once simulations use role, manager, location, and susceptibility history, the training stack starts consuming identity context as an input to security control. That makes campaign governance part of the identity programme, because the same data used for access decisions can now influence behavioural nudges. Practitioners should treat that convergence as a governance boundary, not a convenience feature.

Security awareness is moving from templated content to context-aware control: Generic phishing simulations are easy to ignore because they train for the average employee rather than the actual recipient. The article shows why contextual realism matters: attackers already use AI to do this, so defensive training must mirror the operating environment if it is to change behaviour. The field is shifting from content libraries to contextual control planes for human risk.

Human-in-the-loop review remains the critical safeguard in AI-generated training: The article’s preview-and-validate workflow is the right lesson for the market, because AI output quality is not the same as AI governance. If simulation content can be generated quickly, the real differentiator becomes approval discipline, template immutability, and auditability. That is the governance layer security awareness teams need if they want speed without creating an unmanaged phish factory.

Contextual training introduces a new trust boundary around identity-derived data: The phrase that best captures this shift is identity-context amplification. Training systems can now combine user metadata, behavioural history, and current threat intelligence to shape intervention, which increases relevance but also expands the blast radius of poor governance. Practitioners should reassess who can access those inputs, how they are validated, and whether the training workflow is itself sufficiently constrained.

GenAI sped up delivery, but it also made the control surface larger: The article shows how AI tools accelerated prototyping and boilerplate generation, which is useful only if engineering standards keep pace. The broader signal is that security products built with GenAI inherit a dual requirement: they must secure the user-facing control and the AI-assisted development process. Teams should evaluate both before assuming operational maturity.

From our research library:

  • AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers, according to the State of Secrets Sprawl 2026.
  • Generative AI use specifically increased from 33% in 2023 to 79% in 2025, according to McKinsey’s Global Surveys on the State of AI.
  • Read next: Agentic AI Security Guide

What this signals

Identity-context amplification: Training systems that reuse role, manager, location, and behavioural data gain relevance, but they also expand the governance surface around who can see and shape those inputs. Practitioners should assume the awareness stack now sits closer to identity governance than most SAT programmes did in the past.

The control question is not whether GenAI can produce more convincing simulations. It is whether the organisation can keep generated content, user context, and review authority aligned tightly enough that personalisation improves resilience instead of creating a second-order privacy and trust problem.


For practitioners

  • Govern simulation inputs as identity context Limit which identity attributes can be used to personalise phishing training, and require explicit approval for fields such as manager, location, and behavioural history before they influence campaign targeting.
  • Require human review before launch Use an internal approval step for every template, test message, and training video so generated content is validated before it reaches recipients.
  • Separate training analytics from access decisions Keep awareness data, completion metrics, and susceptibility signals out of entitlement decisions unless there is a formally defined governance model for reuse.
  • Sanitise generated content before distribution Strip PII, verify branding, and check that every simulation and video asset matches the approved scenario before storing it in delivery systems.
  • Audit AI-assisted development workflows Track where coding assistants, UI generators, and LLM-written scripts are used so security and product teams can review the resulting changes with the same discipline as manual code.

Key takeaways

  • Hyper-personalised phishing training changes awareness from static content delivery into a governed identity-context workflow.
  • The article shows that role, location, susceptibility history, and human review now sit inside the training control plane.
  • Practitioners should tighten approval, sanitisation, and access controls before AI-generated awareness content reaches users.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI09 — Human-Agent Trust ExploitationAI-generated training and coaching rely on user trust and interaction timing.
Recommendation — Review AI-generated awareness flows for trust exploitation and add human validation before delivery.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article centers on governance of GenAI-generated content and workflows.
Recommendation — Define approval, audit, and accountability controls for AI-generated training outputs.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsTraining assets and identity context require controlled access and authorisation.
Recommendation — Restrict access to campaign data, templates, and generated assets by role.
CIS Controls v8CIS-5 — Account ManagementRole-based control over campaign administration is central to the workflow.
Recommendation — Limit campaign administration to authorised accounts and review their access regularly.

Key terms

  • Hyper-Personalized Phishing: Hyper-personalized phishing is a targeted social engineering technique that tailors malicious messages to a specific person or role using available data such as job history, contacts, and public profiles. The goal is to make the message feel routine and trustworthy enough to trigger a quick response.
  • Just-In-Time Training: Just-in-time training is immediate, short-form guidance delivered at the moment a risky action occurs, such as clicking a simulated phish. It turns a mistake into a learning event while the context is still fresh. In security programmes, this approach improves retention and supports behaviour change better than annual training alone.
  • Human-in-the-Loop Review: Human-in-the-loop review is a governance pattern that requires a person to validate, approve, or override an AI-influenced decision. It matters most when automated output affects people, regulated data, or high-risk actions where traceability and accountability are mandatory.
  • Identity context: The entitlement, ownership, and purpose information that explains why an action occurred and whether it was expected. For security operations, identity context turns raw alerts into decisions by showing which human or non-human identity acted and what it was allowed to do.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org