AI GovernanceBy Noor Ul Ain Ali · 23 Jul 2026 · 5 min readShare on LinkedIn

AI Has Made Phishing Unspottable: Why Awareness Training Is No Longer Enough

Generative AI removed every tell that phishing training taught. A cybersecurity assessor explains why user detection can no longer be your primary defence, and what replaces it.

For twenty years, phishing awareness training has taught the same tells: look for bad grammar, generic greetings, awkward phrasing, a sense of urgency from a stranger. That advice built an entire compliance industry. It is now dangerously out of date, and pretending otherwise is putting organisations at risk.

Generative AI has removed every one of those tells. In our socio-technical analysis of AI-enabled phishing, drawing on 238 empirical and conceptual sources, the pattern is consistent: AI does not make phishing a little better. It changes what phishing is.

What AI actually changed

Three shifts matter, and they compound.

Realism. AI-generated phishing has no spelling mistakes, no clumsy translation, no tonal giveaways. It writes in fluent, native-quality prose, mirrors a brand’s house style, and produces a message indistinguishable from a legitimate one. The single most-taught detection signal, “it looks off,” is gone.

Personalisation at scale. Historically there was a trade-off: attackers could send generic phishing to millions cheaply, or craft convincing spear-phishing to a few executives expensively. AI collapses that trade-off. It can ingest a target’s public data and recent posts and generate thousands of individually tailored messages, each referencing real projects, colleagues and context. Mass-produced spear-phishing is now economically viable.

Cost. The marginal cost of a sophisticated, personalised attack has fallen close to zero. When the economics change this fundamentally, volume and quality both rise at once. Defenders are no longer facing occasional well-crafted attacks against high-value targets. They are facing well-crafted attacks against everyone.

Why user training cannot win this

Here is the uncomfortable conclusion for any security leader still measuring success by phishing-simulation click rates. If a message is genuinely indistinguishable from a legitimate one, then a human being cannot reliably distinguish it. Asking employees to catch what is designed to be uncatchable is not a control. It is a way of transferring blame to the least-equipped person in the organisation.

This does not mean awareness is worthless. People should still know to verify unusual requests through a second channel and to report anything suspicious. But awareness has to be repositioned from a primary defence to a backstop. The primary defence has to be technical and structural, because that is the only layer that does not depend on a human out-thinking a machine built to deceive them.

The forensic problem nobody is discussing

There is a second-order effect that receives too little attention: AI complicates investigation after the fact. Traditional phishing forensics relied on linguistic fingerprints, reused templates and infrastructure patterns to attribute campaigns and connect incidents. AI-generated content is unique every time, leaves fewer reusable artefacts, and can deliberately mimic other actors. Attribution gets harder, and the ability to say “these three incidents are the same campaign” degrades. Organisations should assume their post-incident analysis will be slower and less certain than it used to be, and plan their response accordingly.

What actually works now

If humans cannot be the filter, the architecture has to be. Four moves matter most.

Deploy phishing-resistant authentication. This is the single highest-value control. Multi-factor authentication that resists replay and phishing, such as FIDO2 and passkeys, breaks the attack even when the user is fully deceived and hands over a password. Standards are catching up: PCI DSS v4.0.1’s Requirement 8.5.1 now demands MFA that resists replay and cannot be bypassed, and other frameworks are moving the same way. Bare SMS codes and simple push approvals are no longer enough.

Assume credentials will be phished, and limit the blast radius. Segment access, apply least privilege, and monitor for anomalous behaviour after login, because that is where a successful phish becomes a breach.

Harden the processes attackers target. Payment changes, credential resets and data requests should require verification that does not depend on trusting an inbound message, no matter how convincing.

Reposition awareness as reporting, not detection. Reward people for reporting quickly rather than punishing them for clicking, because in an AI world some clicks are inevitable, and speed of reporting is what limits damage.

The shift in mindset

The organisations that will struggle are the ones still treating phishing as a user-education problem to be solved with another training module and a quarterly simulation. The ones that will hold up have accepted a harder truth: the deception is now good enough that the only reliable defences are the ones that work even when the human is fooled.

AI has not made phishing unstoppable. It has made it unspottable. Those are very different problems, and they call for very different defences.

Frequently asked questions

Can employees still spot AI-generated phishing emails?

Not reliably. AI removes the traditional tells (bad grammar, generic greetings, awkward tone) and produces messages indistinguishable from legitimate ones. Awareness training still has value as a reporting backstop, but it can no longer be your primary defence against phishing.

What is the best defence against AI phishing?

Phishing-resistant multi-factor authentication such as FIDO2 or passkeys. It breaks the attack even when a user is fully deceived and enters their password. PCI DSS v4.0.1 Requirement 8.5.1 now requires MFA that resists replay and cannot be bypassed, reflecting this shift.

Is SMS-based MFA enough to stop AI phishing?

No. SMS one-time codes and simple approve/deny push notifications can be defeated by real-time phishing and push fatigue. Phishing-resistant factors (hardware keys, FIDO2, passkeys, or number-matching authenticators) are the direction the standards and the threat both point to.

How does AI make phishing investigations harder?

AI-generated content is unique each time and leaves fewer reusable linguistic or template fingerprints, and it can mimic other actors. That weakens attribution and makes it harder to link related incidents into a single campaign, so post-incident analysis is slower and less certain.

Build defences that work when the human is fooled

Cianaa is an independent cybersecurity certification and assessment body serving New Zealand and Australia, assessing MFA and authentication controls against PCI DSS and ISO standards. Talk to our assessors or read our open-access research.

AI governance

Talk to Cianaa Technologies

ISO 42001 readiness and AI risk assessments aligned to the EU AI Act and emerging Australian guidance.

Book a discovery call
Enjoyed this article?

Get the next one in your inbox

One email when we publish. Written by named auditors, never by a marketing robot. Unsubscribe anytime with one click.

Double opt-in. No spam, no list-selling, covered by our privacy policy.

Similar Posts