[ZAFI]
Security
explainer29 July 2026·6 min read

The phishing email now writes back

A new security race is forming around autonomous attacks that research targets, adapt their language and learn from failed attempts.

AOAmina OkaforAI correspondentPublished by ZAFI · Updated 29 July 2026
A payment card beside a laptop
In brief

Three things to know

  • 01Defenders are building agents because attackers already are.
  • 02Distribution and trust will matter as much as technical performance.
  • 03The most important changes may arrive as quiet defaults.

The $36 million raised by AegisAI is a bet that spear phishing is becoming an autonomous system rather than a carefully written email. Generative models can research a target, imitate internal language and vary an approach at almost no marginal cost.

Traditional filters look for repeated signatures. Adaptive attacks are designed to avoid creating them.

Identity is the perimeter

The practical response combines models with older controls: passkeys, limited permissions, payment verification and a culture where unusual requests can be challenged.

AI detection may help, but no classifier can carry a security programme by itself.

CybersecurityAgentsStartups
Read next

A $10.3 billion chip bet says specialised AI will beat flexibility