AI Made Phishing Convincing. Here Is What Still Stops It.
The traditional advice for spotting a phishing email was to look for bad grammar. It was decent advice for roughly two decades. It is now close to useless, because generating fluent, contextually appropriate text in any language costs essentially nothing.
That change deserves a clear-eyed response rather than alarm. The attacks got better at the surface layer. The defences that actually work were never about the surface layer.
What actually changed
Three things, and it is worth separating them because they call for different responses.
Fluency became free. The spelling mistakes and awkward phrasing that used to mark a fraudulent message are gone. So is the assumption that an attacker targeting you must speak your language natively.
Personalisation became cheap. Writing a message that references your employer, your role and a plausible current project used to require research time that only justified targeting executives. That research is now largely automated, which means ordinary employees receive the quality of attack that used to be reserved for the C-suite.
Voice stopped being proof. Convincing voice cloning from a short sample is widely available. A phone call from a familiar-sounding colleague is no longer evidence of anything.
What did not change
Here is the part that matters. Every one of these attacks still has to end in the same place: you doing something. Entering a credential on a page. Approving a login prompt. Moving money. Installing something.
The message got more persuasive. The action it needs from you did not change at all. That is where defence belongs.
The defences that hold up
Passkeys, wherever they are offered
This is the single highest-value change available to most people. A passkey is cryptographically bound to the real site. On a convincing replica, it simply will not offer itself, because the domain does not match. It does not matter how good the fake looks, and it does not matter whether you were fooled. There is no secret to hand over.
A password manager, used consistently
The same logic applies as a fallback. A password manager autofills based on the domain. If you land on a lookalike and the manager stays silent, that silence is information. Many people have caught a phishing page this way without consciously inspecting anything.
Treat urgency as the signal
Fluency is no longer a tell, but pressure still is. Nearly every one of these attacks needs you to act before you verify: an account closing, an invoice overdue, an executive who needs it done quietly and now. Legitimate organisations tolerate you calling them back. Fraud does not survive the delay.
Verify through a channel you chose
If a message asks for money or credentials, confirm through contact details you already had, not the ones in the message. For voice specifically, agree a phrase within your family or finance team that a caller must be able to produce. It sounds theatrical. It works, and it costs nothing.
Prefer phishing-resistant second factors
Not all two-factor authentication is equal. Codes sent by SMS can be relayed by an attacker in real time. App-generated codes are better. Hardware keys and passkeys are better still, because they verify the site rather than trusting you to.
For small teams specifically
- Require a second human approval for payment changes. Most business email compromise dies at this step.
- Make reporting frictionless and blameless. If people fear looking foolish, they stay quiet, and silence is what turns a click into a breach.
- Retire shared logins. They make it impossible to know whose credentials leaked.
- Stop training staff to spot bad grammar. Train them on the actions that matter, and on the fact that a perfect message proves nothing.
The realistic view
Phishing got better at looking legitimate, and it will keep improving. What has not improved is the attacker’s need to convert persuasion into a specific action on your part. Remove the value of that action, through passkeys, domain-aware autofill and a verification habit, and the quality of the writing stops mattering.
That is the useful reframing. Stop trying to detect fakes. Make being fooled survivable.