"AI supercharges attackers" is repeated often enough that it has stopped carrying information. The honest version is narrower and considerably more useful.
No new technique has appeared. What disappeared is a cost.
What the cost used to buy
A targeted phishing message that works requires research.
You need the target's role and who they report to, so the request comes from a plausible direction. You need a live piece of context — a project, a vendor relationship, a renewal, a trip. You need the internal vocabulary, because an organisation's words are specific and getting them wrong is the giveaway. You need timing that makes the request unremarkable.
That was hours of work per target, and it is precisely the kind of work that is now fast: reading widely across public sources, extracting what matters, correlating it into a picture.
What the cost was doing
It was acting as a filter, and it was protecting people who never knew it existed.
A 200-person manufacturer was not defended by its controls. It was defended by not being worth several hours of an adversary's time when larger targets were available at the same effort.
That is a real form of protection, and for a substantial number of mid-sized organisations it was the primary one. It is gone, and its removal is invisible from the inside — nothing about your environment changed on the day it stopped applying.
Volume and targeting, not method
Hold the distinction precisely, because it is what makes the rest of this actionable.
The technique is unchanged. It is still a message that asks someone to do something, relying on plausibility and time pressure. The controls that address the technique are the controls that always did.
What changed is how many such messages can be produced, and how well-aimed each one is. The same shift applies to the reconnaissance behind them: large-scale harvesting of public data about an organisation is now cheap enough to run against anyone.
So the correct response is not new categories of control. It is a re-examination of which existing ones were quietly relying on the cost filter.
What degrades
Awareness training built on tells. Look for spelling mistakes, awkward grammar, generic greetings, an address that is slightly wrong.
Every one of those was an artefact of the old cost structure. They appeared because a person writing at volume in a second language could not afford to polish each message. They were never properties of the attack; they were symptoms of the budget.
Training that still teaches them is worse than neutral. It hands people a test that now returns a false negative — the message is well written, therefore it is legitimate — which is exactly the inference you do not want them making.
Anything that depends on volume as a signal. Detection tuned to catch a hundred near-identical messages does less against a hundred distinct ones.
What holds
Out-of-band verification. An unusual request gets confirmed through a different channel than the one it arrived on, using a contact detail you already had rather than one supplied in the message.
This works for a structural reason: it does not require anyone to detect anything. The person does not have to judge whether the message is real. They follow a procedure triggered by the request type, and the procedure is indifferent to how convincing the request was.
Controls that assume the person is fooled. Payment approval thresholds. Separation of duties on anything irreversible. Second approval for changes to banking details.
Same structural property. They do not ask a human to win a judgement call under time pressure, which is the contest that has become unwinnable.
Reducing what is worth researching. The reconnaissance still has to find something. Decommissioning forgotten subdomains, keeping internal hostnames out of public repositories and pruning stale accounts all shrink what the cheap research returns.
The reframe worth making
Split your awareness programme in two.
One half teaches people to recognise something. That half is depreciating, and the rate is not under your control.
The other half teaches people a procedure to follow when a request has certain properties — money, credentials, urgency, a change to payment details — regardless of how legitimate it appears. That half holds, because its effectiveness never depended on the quality of the attacker's writing.
Most programmes are heavily weighted to the first. The rebalance costs nothing except the willingness to stop teaching a tell that no longer exists.
Want help putting this into practice?
We work alongside your team to design, build, and operate the controls described above.