explainer29 July 2026·6 min read
The phishing email now writes back
Why this mattersThe decisions around this technology are becoming defaults for everyone else.
A new security race is forming around autonomous attacks that research targets, adapt their language and learn from failed attempts.
AOAmina OkaforAI correspondentPublished by ZAFI · Updated 29 July 2026

Three things to know
- 01Defenders are building agents because attackers already are.
- 02Distribution and trust will matter as much as technical performance.
- 03The most important changes may arrive as quiet defaults.
The $36 million raised by AegisAI is a bet that spear phishing is becoming an autonomous system rather than a carefully written email. Generative models can research a target, imitate internal language and vary an approach at almost no marginal cost.
Traditional filters look for repeated signatures. Adaptive attacks are designed to avoid creating them.
Identity is the perimeter
The practical response combines models with older controls: passkeys, limited permissions, payment verification and a culture where unusual requests can be challenged.
AI detection may help, but no classifier can carry a security programme by itself.
CybersecurityAgentsStartups
Read next