AI has eliminated the bad grammar tells. Here are the new signals that identify phishing emails in 2026.
The traditional phishing detection wisdom — look for poor grammar, strange formatting, and generic greetings — is now dangerously outdated. AI-generated phishing emails are grammatically perfect, contextually appropriate, and often personalized with specific details about you, your organization, and your colleagues. After consulting with three enterprise security teams on their post-AI phishing incident analyses, here is what the new detection signals actually are.
The grammar-based detection approach worked because mass phishing campaigns were written by non-native speakers at volume — quality was sacrificed for quantity. Large language models have eliminated this trade-off. A phishing campaign can now generate thousands of grammatically perfect, individually personalized emails at the cost of a few dollars of API usage. The security awareness training that taught employees to spot "bad writing" needs to be retrained around behavioral and contextual signals rather than linguistic ones.
The most reliable remaining signal: a request to bypass your organization's normal process due to time pressure. "The CEO needs this wire transfer completed before close of business today — normal approval channels would take too long" is the textbook pattern. Legitimate urgent requests from legitimate senders work through established channels even when urgent; requests to bypass channels are the primary behavioral marker of social engineering regardless of how well-written the email is. The signal is not urgency itself — urgent legitimate requests exist — but urgency combined with a request to deviate from normal verification or approval process.
AI-generated phishing specializes in creating scenarios that are plausible enough to not trigger skepticism but that cannot be quickly verified through normal channels. "Your manager asked me to contact you directly while they are in meetings" creates a plausible scenario that you cannot quickly verify. The detection technique: verify through a separate channel (call your manager directly, not reply to the email) before taking any action the email requests. If the scenario is legitimate, verification takes one minute. If it is phishing, verification prevents the harm.
Legitimate requests can withstand the time required for verification. Phishing attacks depend on creating pressure to act before verification occurs. Any email that creates time pressure specifically around verification — "don't call IT about this, it will delay the security update" or "reply here rather than calling to avoid the issue being escalated prematurely" — is using social engineering to prevent the verification that would expose the attack. The instruction to not verify through normal channels is itself the tell.
AI phishing personalizes using publicly available information — LinkedIn profiles, company websites, press releases, social media. The specificity can feel convincing but often has a particular quality: it references things that are publicly searchable rather than things only an internal person would know. A colleague asking about "the Q3 initiative" knows the internal name; a phishing email is more likely to reference "your recently announced expansion" from a press release. The specificity of internal terminology and context is harder to fake than the specificity of publicly available facts.
The defenses that remain effective against AI-generated phishing: out-of-band verification for any unusual request (call the requester on a known number, not a number provided in the suspicious email); phishing-resistant multi-factor authentication (hardware security keys or passkeys that cannot be phished even when credentials are entered on phishing sites); and organizational policies that make bypassing verification explicitly prohibited — so employees have institutional backing for saying "I need to verify this through our normal process" even when pressured.
Bottom Line: Grammar-based phishing detection is obsolete — AI generates perfect text at scale. New detection signals: urgency combined with requests to bypass normal process; scenarios designed to prevent verification; instructions specifically discouraging verification through normal channels; and specificity that uses public information rather than internal knowledge. The defense that works: out-of-band verification for unusual requests, phishing-resistant MFA, and institutional policies that support employees taking time to verify rather than acting immediately under pressure.