Common signs include highly personalised messages, accurate internal language, believable invoice requests, and fewer obvious grammar mistakes. Teams should also watch for unusual urgency, requests that bypass normal approval paths, and multi-channel pressure from email, voice, or video. When these patterns appear together, rule-based filters are usually no longer sufficient on their own.
Why AI-Enabled Phishing Looks More Legitimate to People and to Filters
AI changes phishing from a mass-noise problem into a precision social-engineering problem. The biggest clue is that the message reads like it belongs inside the organisation: the wording matches real teams, the request fits a real workflow, and the sender no longer relies on obvious spelling errors or generic urgency to create pressure.
That matters because traditional email defences were built to catch scale, imitation, and known-bad patterns. When the content is personalised and context-aware, security teams need to look for signals that sit outside content matching, such as sender anomalies, reply-path manipulation, and whether the request aligns with the normal business process.
One useful reference point is that attackers increasingly pair phishing with account or token abuse rather than relying on a single fake message. The Ultimate Guide to Non-Human Identities is helpful here because it shows why stolen credentials and tokens can let an attacker move from convincing email into broader access and persistence.
What Changes When BEC Adds Voice, Video, and Workflow Abuse
Business email compromise is no longer limited to email-only fraud. A suspicious request becomes more credible when it is reinforced by a phone call, a voice note, a video message, or a follow-up from a compromised account that appears to confirm the same story. That multi-channel pattern is a strong indicator that the attacker is trying to defeat caution, not just inbox filtering.
Teams should also pay attention to approval-path bypass. BEC often succeeds when the request is framed as exceptional, confidential, or time-critical so that the target skips normal verification steps. In practice, the danger is not just the fraudulent message itself, but the way it pushes a recipient away from established controls, segregation of duties, and callback verification.
When the request involves payment, account changes, vendor banking updates, gift card purchases, or urgent document release, the control question is whether the organisation can still verify intent out of band. If the answer depends on the same channels already being abused, then the defence has already been reduced to trust in the attacker’s narrative.
Risk and Threat Considerations
AI-assisted phishing raises risk because it can produce high-quality lures at scale, while BEC raises the stakes by converting deception into financial loss, data exposure, or unauthorized account change. The most dangerous cases combine believable language with social pressure, because that combination reduces the chance that a recipient stops to validate the request.
Failure mechanism: attackers use generated or assisted content to mirror internal language, impersonate executives or vendors, and redirect the victim into a rushed action path that bypasses normal approval, validation, or callback checks.
Impact: the likely outcomes are fraudulent transfers, payment diversion, credential capture, mailbox takeover, and follow-on compromise of other business systems if the attacker turns one successful conversation into broader access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1566 — Phishing | AI-enabled phishing is a phishing delivery and pretexting problem. |
| T1656 — Impersonation | BEC often relies on impersonation of executives, vendors, or internal staff. | |
| Recommendation — Map suspicious lures to T1566 and hunt for sender, content, and reply-path anomalies. Use T1656 to investigate impersonated identities and verify high-risk requests out of band. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | High-risk requests depend on stronger identity proofing and verification than email content alone. |
| Recommendation — Apply stronger identity verification before approving sensitive account or payment changes. | ||
| CIS Controls v8 | 5 — Account Management | BEC often abuses account changes and standing access to move from message to action. |
| Recommendation — Review and restrict account-change paths that can be triggered from unverified requests. | ||
Practitioner Guidance
What to verify: treat a message as higher risk when it combines personal detail, urgency, and an unusual request path. Verify whether the sender identity, reply chain, domain, and requested action all line up with the normal business process, not just whether the wording looks polished.
Decision rule: if a request asks for payment, banking, gift cards, password resets, MFA changes, or document release outside the usual workflow, require an out-of-band confirmation path that does not depend on the same email thread or channel.
What practitioners underestimate: the control failure is often human process drift rather than email detection failure. The best signal of compromise is frequently the combination of credible language and a request that is abnormal for timing, authority, or approval route, not a malformed message.
Practitioner takeaway: the right response is to validate the business action, not just the message, because AI can now make the email look normal while the request remains operationally abnormal.
Related resources from NHI Mgmt Group
- Why do AI-generated phishing emails weaken traditional email security models?
- Why do AI-generated BEC attacks bypass traditional secure email gateways?
- What is the difference between traditional email security and behavioural AI for stopping modern phishing campaigns?
- What is the difference between traditional secure email gateways and AI-native email detection for stopping AI-powered phishing?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org