TL;DR: More than 70% of customers have moved away from traditional secure email gateways because AI-driven attacks are bypassing legacy detection and filtering, according to Abnormal AI, and it frames SEG replacement as a practical response to modern email threat tactics. The real takeaway is that email security now depends on adapting controls to attacker behaviour, not preserving old perimeter assumptions.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “The Great SEG Migration: 7 Lessons Learned from Replacing 200+ Secure Email Gateways”.
Key questions
Q: Where do legacy secure email gateways fail against AI-driven phishing?
A: They fail when attacks no longer carry stable signatures, repetitive wording, or obviously malicious infrastructure.
Q: Why do AI-generated email attacks increase identity risk?
A: AI-generated email attacks increase identity risk because they make malicious requests more convincing at the exact point where people decide whether to trust, approve, or act.
Practitioner guidance
- Reassess SEG efficacy against AI-crafted phishing Test current email controls against highly personalised, low-signal lures that avoid obvious malicious infrastructure and brand them by business context rather than known templates.
- Add identity risk signals to email triage Correlate suspicious email events with authentication anomalies, impossible travel, new-device logins, and MFA fatigue patterns so the email layer informs identity defence.
- Measure post-delivery containment, not only inbox blocking Track whether your stack limits clicks, credential submission, and downstream compromise after delivery, because those outcomes define real control effectiveness.
Bottom line: AI-generated email attacks weaken the assumptions that traditional secure email gateways were built on, especially around stable indicators and reusable malicious patterns.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Legacy SEG-era assumptions are breaking under AI-assisted phishing. Secure email gateways were built for a message threat model that assumed limited personalisation, slower attacker iteration, and stronger indicator reuse. AI-generated lures undermine all three conditions, which means the control may still operate but no longer governs the real risk surface. The implication is that email security programmes must stop treating perimeter filtering as the decisive control.
A question worth separating out:
Q: What should organisations do when their email stack no longer matches current attack tactics?
A: They should evaluate whether the control architecture still reflects current adversary behaviour or whether it is preserving a legacy perimeter assumption. In practice, that means adding behavioural detection, identity correlation, and post-delivery containment rather than relying only on message filtering. The objective is to reduce successful social engineering, not to defend an outdated gateway model.
👉 Read our full editorial: AI-driven email attacks are exposing the limits of legacy SEGs