For years, the advice for spotting a phishing email came down to a short list: watch for typos, awkward phrasing, a generic greeting, or a sender who "doesn't write like that." That advice assumed the attacker was working from a template, often translated badly, and reused against thousands of targets at once. That assumption no longer holds. AI writing tools produce clean, natural, contextually appropriate English by default, and they do it in seconds, in whatever tone or language the sender wants. The result is a phishing email that reads exactly like the vendor invoice, client request, or internal memo it's pretending to be.
1. The old red flags stopped being reliable
Broken grammar and stilted phrasing were never really about grammar. They were a proxy for a much more useful signal: this message probably wasn't written by a human who knows me or my business. That proxy is gone. An attacker can now produce a message referencing your industry, your vendor's actual invoice format, or a coworker's usual tone, without ever having written a word of it themselves. Training employees to scan for writing quality is training them to rely on a signal that mostly stopped appearing.
2. Personalization used to be expensive. Now it isn't
Convincing, targeted phishing used to require real time from a real person: research on the target, a written draft, and often a native speaker to make it read naturally. That labor cost is why small businesses were sometimes treated as lower-value targets than large enterprises, worth a generic blast rather than a custom message. AI removes most of that labor cost. A message tailored to your business, your software vendor, or your own business email compromise exposure now takes about as much effort to produce for a 10-person company as a 1,000-person one. That changes who gets targeted, and how often.
3. What still gives a phishing attempt away
The request behind the email hasn't changed even though the writing has. A message asking you to reset a password, approve a wire, open an unexpected attachment, or log in through a link is still worth pausing on, regardless of how polished it sounds. The practical shift is where you put your attention: away from judging the prose, and toward verifying the sender address itself (not just the display name), checking where a link actually points before clicking, and confirming anything involving money or credentials through a second channel, like a phone call to a known number, before acting on it.
Controls that don't depend on someone noticing
Since the writing quality tell is no longer dependable, the more durable fix is technical rather than behavioral. DNS and web filtering can block a malicious destination before a click ever resolves, regardless of how convincing the email that led there was. Phishing-resistant MFA means a stolen password alone isn't enough to get into an account, even if someone does click and enter credentials on a fake login page. And managed detection and response with a 24/7 SOC catches what happens after a message lands, which matters precisely because no filter or training program catches everything. Security awareness training still has a place, but it needs to teach verification habits instead of proofreading, because proofreading no longer works.
Frequently asked questions
How can I tell if an email was written by AI?
You often can't from the writing alone. Grammar and tone are no longer reliable signals. Instead check the sender's actual email address rather than the display name, hover over links before clicking to see the real destination, and treat any unexpected request involving money, credentials, or a login as suspicious regardless of how well it reads.
Does security awareness training still work if the emails look real?
Yes, but the content has to change. Training that teaches employees to spot typos and awkward phrasing is training them to catch a threat that has mostly disappeared. Effective training now focuses on verifying requests through a second channel and slowing down on anything urgent, rather than judging an email by how it reads.
What actually stops a well-written phishing email?
Controls that don't depend on a human noticing anything. DNS and web filtering that blocks known-bad destinations before a click resolves, phishing-resistant MFA that stops a stolen password from being enough on its own, and monitoring that watches for what happens after a message lands rather than only what the message says.
Are small businesses actually being targeted with AI-written phishing, or is this mostly a large-company problem?
Small businesses are targeted specifically because the payoff-to-effort ratio is high: fewer layers of review, and often no one whose job is to double-check a wire transfer or a password reset request. AI-written phishing lowers the cost of writing a convincing message, which makes targeting a 12-person company as cheap as targeting a 1,200-person one.
Not sure your current setup would catch this?
30 minutes with an engineer with DoD infrastructure experience. We'll walk through your email security, filtering, and MFA setup, and show you exactly where a convincing phishing email would and wouldn't get through.
Book your free assessmentPrefer to talk first? Email sales@ghosxt.com or call (831) 204-0501.