TL;DR: AI-generated phishing can rewrite sender infrastructure, phrasing, and payloads for every target, making signature-based rules increasingly fragile, according to Abnormal AI. The practical shift is from cataloguing known-bad indicators to detecting deviations from identity-specific behavioural baselines that attackers have to imitate in real time.
At a glance
What this is: This analysis argues that AI-generated phishing defeats signature-based detection because each campaign can change infrastructure, wording and payloads without losing malicious intent.
Why it matters: IAM and security teams need to shift from static indicators to identity-linked behavioural baselines, because phishing now adapts faster than rule maintenance cycles.
Context
Signature-based phishing detection assumes the next attack will resemble a previously observed one closely enough to match a rule. That model breaks when the attacker can regenerate sender infrastructure, wording and payload structure for every target. In identity security terms, the problem is not only message content but the behavioural pattern around the identity being impersonated.
For practitioners, this is a detection and governance problem rather than a simple email filtering problem. The relevant question is which identity behaviours, relationship patterns and communication deviations can be modelled reliably enough to expose phishing that has no stable signature.
Key questions
Q: Why do signature-based phishing rules keep missing AI-generated attacks?
A: Because the attacker can regenerate sender infrastructure, wording and payloads for each target, so there is no stable artifact to match. Signature rules are effective when malicious content repeats, but AI-generated phishing is designed to avoid reuse. Defenders need controls that look for deviation from expected identity behaviour, not just known-bad indicators.
A: Security teams should place detections higher on the Pyramid of Pain, where they target generic attacker behavior instead of easy to change artifacts like URLs, IPs, or page titles. The strongest controls focus on actions that must happen for the attack to succeed, such as entering credentials into the wrong page. That approach makes detections harder to evade and more durable over time.
Q: What are the signs that phishing detection is relying too much on signatures?
A: Common signs include frequent misses on new variants, heavy dependence on known malicious domains or hashes, and weak detection when wording changes but intent stays the same. If analysts can only explain a hit after the fact, the control is lagging behind the threat. The programme needs behavioural context, not only indicator lists.
Q: What is the difference between phishing detection and behavioural email security?
A: Phishing detection usually looks for malicious content or known indicators, while behavioural email security evaluates how senders, messages, and accounts behave over time. That shift matters because AI-generated attacks can appear clean at the content layer while still looking suspicious in context. Behavioural approaches better fit identity-led abuse patterns.
Technical breakdown
Why signature-based phishing detection breaks
Signature rules work by matching stable indicators such as domains, hashes, sender patterns or exact phrasing. AI-generated phishing removes that stability. If the malicious content is regenerated per target, the defender loses the fixed artifacts that make rule-based controls efficient. The result is a moving target where each new sample invalidates the previous signature set. That is why traditional known-bad catalogues are increasingly useful only for retrospective correlation, not first-contact prevention.
Practical implication: use signatures as one input, but do not treat them as the primary control for modern phishing detection.
Behavioural baselines and identity context in phishing defence
The article’s core alternative is behavioural modelling. A baseline describes how a person normally writes, who they contact, what systems they access and when they do it. In this model, detection is triggered by deviation, not by matching a known malicious pattern. That matters because phishing often succeeds through contextual inconsistency rather than overtly malicious technical markers. Identity-linked behaviour creates a richer signal than content inspection alone, especially when the attacker is deliberately varying the content to evade static controls.
Practical implication: build detection around identity-specific behaviour, communication relationships and access patterns, not only message content.
Signal fusion is what makes adaptive phishing detectable
Single anomalies are often too weak to act on. A plausible login, a slightly off tone and an unusual request can each look benign in isolation. When fused together, they create a higher-confidence phishing signal because the attacker must mimic several dimensions at once. This is the practical advantage of scoring combinations rather than isolated artifacts. It raises the cost of evasion, because the adversary has to imitate an entire behavioural profile instead of a single technical indicator.
Practical implication: correlate multiple weak signals before escalation, so attackers cannot bypass controls by mutating one artifact at a time.
Breaches seen in the wild
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
- Mailchimp breach 2022: Attackers socially engineered Mailchimp staff, used a support tool to export 102 customer lists and exposed customer API keys for phishing.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Signature-based phishing detection is now structurally incomplete. The hidden assumption behind signatures is that malicious infrastructure, payloads or phrasing will recur in recognisable form. AI-generated phishing breaks that premise by regenerating each instance to avoid reuse. The implication is that defenders cannot rely on stable artifacts as the centre of gravity for detection any longer.
Identity-specific behavioural baselines are the more durable control boundary. When a phishing message is evaluated against how a person normally writes, contacts and works, the attacker has to imitate a living profile rather than evade a static rule. That shifts the control point from content matching to behavioural consistency. Practitioners should treat deviation modelling as the primary lens for modern phishing governance.
Signal fusion is the named concept that matters here: phishing risk increasingly emerges from the combination of small inconsistencies, not from any single bad indicator. One anomalous login or one awkward sentence is rarely enough. But when message tone, sender behaviour and relationship pattern all drift together, the attack becomes materially easier to distinguish. The practical conclusion is that detection needs scoring logic that weights combinations, not isolated events.
Email security and IAM are converging around the same problem: proving identity continuity under adversarial change. A message that looks valid in isolation may still be a fraud if it violates the expected identity relationship behind it. That makes phishing defence part of broader identity governance, not just mail hygiene. Security teams should align detection models with how identities actually behave across communication and access flows.
Adversaries can mutate faster than rule maintenance cycles, so governance has to move earlier in the detection chain. The defender’s job is no longer to catch known bad faster; it is to recognise when the behaviour cannot be reconciled with the identity’s normal operating pattern. That is the practical lens for modern phishing resilience.
What this signals
Adaptive phishing changes the control question. The issue is no longer whether a message matches a known bad pattern, but whether it fits the identity and relationship history it claims to represent. That pushes detection toward behavioural context, which is harder for attackers to regenerate than a domain or payload.
Identity-specific baselines are becoming a practical security boundary for email and collaboration abuse. When sender infrastructure, phrasing and payload all mutate, defenders need a model of what normal looks like for each user, team and workflow. Without that baseline, static controls will always be one step behind.
For practitioners
- Prioritise behavioural baselines over static signatures Tune phishing detection around normal writing patterns, contact relationships and access timing so each identity has a behavioural reference point.
- Fuse weak signals before escalation Score combinations of sender novelty, tone drift and relationship anomalies together, because any single indicator may be too ambiguous to act on.
- Review identity-linked communication patterns Map which users, service desks and systems are commonly impersonated, then watch for requests that break established communication paths.
- Treat signature rules as a secondary control Keep known-bad indicators for correlation and hunting, but do not depend on them as the first line of defence against adaptive phishing.
Key takeaways
- AI-generated phishing weakens the value of known-bad signatures because every campaign can be rewritten before defenders catalogue it.
- The stronger detection model is behavioural, using identity-linked baselines that expose when communication patterns drift from normal.
- Security teams should fuse multiple weak anomalies together, because attackers can mutate single indicators faster than static rules can adapt.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP API Security Top 10 | API2 — Broken Authentication | Phishing succeeds by undermining trust in identity assertions and login context. |
| Recommendation — Harden authentication assumptions and treat anomalous identity context as a high-risk signal. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Identity-linked behavioural baselines help validate whether access and requests fit expected authorisations. |
| Recommendation — Use PR.AA-05 to align access decisions with normal identity behaviour and communication patterns. | ||
| CIS Controls v8 | CIS-5 — Account Management | Phishing often abuses trusted accounts and relationship paths rather than raw malware delivery. |
| Recommendation — Apply account management controls to reduce abuse of trusted identities in phishing chains. | ||
Key terms
- Behavior Baseline: A record of normal activity for a non-human identity, including typical consumers, resources, and actions over time. Baselines help security teams detect when an identity is being used in an unusual way and provide the context needed to enforce least privilege safely in dynamic environments.
- Signal Fusion: Signal fusion is the practice of combining multiple weak indicators into one stronger judgment. Instead of treating a strange login, odd message tone, and broken relationship pattern separately, the system scores them together. That makes it harder for highly variable attacks to hide behind any single plausible clue.
- Signature-Based Detection: Signature-based detection identifies malware by comparing files or patterns against known malicious indicators. It is effective for previously seen threats but weak against polymorphic malware, fileless execution, and attacks that reuse legitimate tools, because the malicious behaviour may never match a stable signature.
- Identity-specific detection: Identity-specific detection evaluates risk against the normal behaviour of one person, vendor, or account instead of using broad organisational averages. That approach is stronger for impersonation and thread hijacking because it can recognise when a request is abnormal for the relationship even if it looks acceptable in isolation.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on July 1, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org