Generative AI Phishing: What It Is and How an SMB Defends
Generative AI Phishing: What It Is and How an SMB Defends
Phishing used to have tells — bad grammar, generic greetings, the wrong logo. Generative AI removed every one of them. The defense is not a better spam filter; it is a smaller attack surface, a trained team, and a verification habit.
For years, an SMB could rely on phishing being noisy. A poorly worded email from "the IT department" asking for a password was spotted by half the staff before it reached finance. Generative AI changed the economics. A model writes a flawless, context-aware spear-phishing email in the target’s language, referencing a real project and a real colleague, for near-zero cost. Voice clones of a CEO asking the controller for an urgent transfer have already succeeded against real companies. The signal that used to make phishing easy to catch — that it was cheap and therefore rough — is gone.
This article explains what AI-crafted phishing looks like in 2026, why the legacy detection signals fail, and what an SMB actually does about it. It sits in the ISO 42001 series because the offensive use of generative AI is an AI-system risk — and it pairs with the prompt injection piece, which covers the inverse risk (attackers targeting your AI rather than using AI to target you).
What generative AI changed
Three shifts matter for an SMB.
Fluency. Large language models write email in perfect business French, English, or Quebec French, with the register and idiom of a real colleague. The grammar-and-translation tells that flagged older phishing are gone.
Personalization at scale. A model fed a LinkedIn profile, a company "About" page, and a recent press release produces a spear-phishing email that names the right project, the right manager, and the right deadline. What used to take an attacker an hour per target now takes seconds per target across thousands of targets. Everyone gets the spear-phishing treatment, not just executives.
New modalities. Voice cloning from a few seconds of public audio produces a convincing call from "the CEO." AI-generated images and video make fake invoices, fake video-call invites, and fake identity documents that pass a glance. The phishing surface is no longer just email.
Why the old signals fail
The detection heuristics built into legacy email filters were trained on human-written phishing. They look for spelling errors, mismatched sender domains, generic greetings ("Dear Customer"), and known bad URLs. AI-crafted phishing:
- has no spelling or grammar errors,
- uses the correct domain (often via a compromised real account or a look-alike registered cheaply),
- addresses the target by name and references real context,
- links to attacker infrastructure that may be brand-new and not yet on any blocklist.
The filter catches the lazy attacks and misses the dangerous ones. This is not a filter-tuning problem; it is a signal-evaporation problem. The defense has to move upstream and downstream of the filter.
Defense layer 1 — reduce the surface
The cheapest control is to make the target smaller. Three actions cut the bulk of the exposure:
- Reduce public signal. Limit what executives and finance staff publish about travel, reporting lines, and projects on LinkedIn and the company site. AI personalization needs public context; less context means blander, more detectable lures.
- Tighten inbound channels. Disable external email auto-forwarding, strip attachments at the gateway where possible, and rewrite or quarantine links from new senders. The patch cadence discipline applies to the email infrastructure too — keep the gateway and endpoint tools current.
- Shrink the payment and data-exit paths. The point of most AI phishing is a wire transfer, a credential harvest, or a data exfiltration. A mandatory callback on a known number for any payment change or new payee, and a no-exception rule against acting on email-only instructions, closes the highest-impact exit.
Defense layer 2 — train for the new tells
The tells moved from the email to the request. Train the team to look at what is being asked, not how it is written:
- Urgency and secrecy — "do this now, don’t discuss it" is the constant. AI fluency makes the urgency sound calm and reasonable; the pressure is still the signal.
- Context mismatch — the email references a real project but asks for something the project would never require (credentials, a payment, a document export).
- Channel shift — an email that pushes the target to a text, a chat app, or a call. The shift to a less-monitored channel is the attack moving to where the filter cannot see.
- Verification is always allowed — the single most important behavior. Anyone, at any level, may stop and verify a request by a second channel without penalty. Make it the culture, not the exception.
Run a tabletop exercise with an AI-crafted phishing scenario once a year. The scenario tests whether the verification habit holds under a realistic, fluent lure — and it is the rehearsal that makes the habit stick.
Defense layer 3 — technical controls that still work
A few technical controls remain effective against AI phishing, because they do not depend on the email’s text:
- MFA everywhere, phishing-resistant where it counts. Push-based MFA can be fatigue-attacked; FIDO2 security keys resist phishing by binding the authentication to the real domain. Put keys on finance and admin accounts first.
- Endpoint detection and response on every device, so a clicked payload gets caught even when the email did not.
- Identity and access hygiene — least privilege, quarterly access reviews, and fast offboarding. If a credential is harvested, the blast radius is what determines the outcome.
- Logging and monitoring (ISO 27001 A.8.15 / A.8.16) — watch for impossible-travel logins, new-mailbox-forwarding rules, and bulk downloads. These are the post-click signals that catch what the pre-click filter missed.
The governance angle
ISO/IEC 42001:2023 expects the organization to manage AI-related risks, including those arising from others’ use of AI. AI-crafted phishing is exactly that — a risk to your organization created by an attacker’s use of generative AI. Recording it in the risk register, with the controls above as the treatment, is how it shows up in your Statement of Applicability and your AI impact assessment. It is one of the AI risks that is also a pure information-security risk — tag it "both" in the integrated register.
What to do next
Mandate the callback rule for any payment or credential change this week — it is the single highest-impact control and costs nothing. Then run one AI-crafted phishing test against your own team (a vendor or a crafted internal simulation) and measure the click rate. Train to the result, and schedule a tabletop with a voice-clone scenario. The defense is a habit plus a few technical controls, not a product.
Want an outside test of how your team holds up against AI-crafted phishing? Book a 30-min AI governance gap assessment — we scope a phishing simulation and a tabletop, and map the controls to your ISO 27001 + 42001 SoA. Bilingual EN/FR, no obligation. → /iso-42001-assessment/
Get Your Free Security Readiness Assessment
Map your controls, identify compliance gaps, and secure your systems before the audit.