A couple of years ago, you could spot a phishing email from a mile off. Bad grammar, a vague “Dear Customer” greeting, a weird logo, a sender address with a few too many random numbers in it. Most people binned them without thinking twice, and spam filters mopped up whatever slipped through. That’s not how it works anymore. Attackers are now feeding large language models the right prompts and getting back emails that sound like they were written by someone in your own office.
They’ll match the tone, reference actual projects, and read like any other internal message you’d get on a Monday morning. The UK government’s Cyber Security Breaches Survey 2025/2026 found that 85% of breached businesses pointed to phishing as the root cause. The old playbook of relying on filters and common sense isn’t cutting it, and the gap between what attackers can do and what most companies are prepared for is only getting wider.
How AI Makes Phishing Emails Harder to Catch
Traditional spam filters scan for known red flags. They’ll catch suspicious domains, blacklisted IP addresses, dodgy attachments, and clumsy wording. For a long time, that was good enough to stop most of the rubbish.
AI-generated phishing doesn’t trip any of those wires. Give a large language model the right prompt and it’ll spit out an email that’s grammatically clean, sounds natural, and dodges every pattern a filter’s been trained to look for. No spelling mistakes and no robotic phrasing that a filter would latch onto.
But grammar’s only part of the story. Attackers are pulling publicly available data from LinkedIn profiles, company websites, even press releases, and they’re folding all of that into the email. So if someone just got promoted, or their company announced a new partnership last week, that detail ends up in the message. The recipient gets an email that looks like it came from a colleague or a supplier, and it mentions something they actually know about. That’s a hard thing to second-guess when you’re halfway through your inbox before lunch.
The Verizon 2025 Data Breach Investigations Report puts the median time for someone to click a phishing link at just 21 seconds. That’s before most people have even finished reading the thing. When the message already looks believable, that instinct to click becomes almost automatic.
Why Spam Filters Fall Short
Most email security tools are reactive by design. They compare incoming messages against databases of known threats, scan for malicious URLs, and check sender reputations. If something matches a threat they’ve already catalogued, it gets blocked.
AI-generated phishing doesn’t match anything on file. Every email can be completely unique, with no reused templates and no recycled payloads. This is what’s known as polymorphic phishing, where every message is slightly different, and it makes signature-based detection close to useless.
On top of that, generative AI lets attackers churn out thousands of these personalised emails in minutes. Instead of blasting one generic template to 10,000 inboxes, they’re sending 10,000 individually tailored messages, each one built to convince a specific person.
What Actually Works Against AI Phishing
If filters alone won’t stop these emails from landing in people’s inboxes, the focus has to move towards what happens after they arrive. That means getting staff to a point where they can spot the subtle signs that something’s off, even when the email looks polished and professional.
- Security awareness training is the most direct way to tackle this. And not the once-a-year compliance tick-box that everyone clicks through in ten minutes. It needs to be ongoing, with realistic examples and regular testing. Phishing simulations are a big part of that. They’ll give organisations actual data on who’s clicking, who’s ignoring, who’s reporting suspicious messages, and where the weak spots are. Reputable cyber security firms like Equilibrium Security now run structured simulation programmes that track how employees respond across repeated exercises, so the training adapts based on real employee behaviour.
- Behavioural analytics add a different kind of protection. These tools monitor how people interact with their email and flag anything unusual. If someone on the finance team suddenly starts downloading attachments from an unfamiliar sender at 2am, that gets picked up. It’s less about blocking individual messages and more about catching what happens after someone takes the bait.
- Multi-factor authentication won’t stop anyone from clicking a dodgy link, but it will limit what an attacker can do with stolen credentials. Even if a username and password get harvested, MFA puts another barrier in the way before they can actually get into the account.
Don’t Wait for the Filter to Catch Up
None of these measures will do much on their own. Simulations without MFA leave a gap. Analytics without proper training means you’re always reacting after the fact instead of preventing the problem in the first place. The companies that get this right treat phishing defence as a layered stack, where each piece covers what the one before it misses.
AI-powered phishing isn’t something that’s coming down the line. It’s already the main method attackers use to break into UK businesses. Spam filters will keep getting better, but they’ll always be playing catch-up with attackers who can generate fresh, convincing content whenever they want. The organisations that stay ahead will be the ones putting money into their people and their processes, not just tweaking their inbox rules and hoping for the best.



