80% of phishing now uses AI content — so 'sounds AI-written' stopped being a tell
ENISA's Threat Landscape 2025 finds AI content in over 80% of observed phishing. What that means for detection, and why authentication is what's left standing.
By Norbelys Chirinos, Co-founder
Founder-reviewed ·How we research and correct articles
For years, the advice for spotting a phishing email was some version of “look for the bad grammar.” ENISA’s Threat Landscape 2025 — the EU cybersecurity agency’s annual analysis of nearly 4,900 incidents reported between July 2024 and June 2025 — puts a hard number on why that advice is now close to useless: more than 80% of the phishing and social-engineering activity ENISA observed involved AI-generated or AI-enhanced content. Phishing itself, per the same report, remains the leading way attackers get initial access, involved in roughly 60% of the incidents analyzed.
That 80% figure isn’t a prediction. It’s a description of what already happened, across a full year of incident reporting from a body that sits on top of dozens of national CSIRTs. The awkward, robotic phishing email — the one with a missing article, a strange verb tense, a subject line in slightly-off English — was never a reliable signal, but it used to be a common enough one that “reads like a native speaker wrote it” carried some weight. ENISA’s numbers say that weight is close to gone.
What this actually changes for detection
The practical consequence isn’t that phishing got harder to write. It’s that phishing got harder to distinguish from legitimate mail using the one signal humans have always relied on most: does this sound right. A model that’s had a few hundred million emails’ worth of business correspondence in its training data does not make the mistakes that used to give away a scam — mismatched register, garbled idioms, subject-verb disagreement. It produces prose that reads like a competent native speaker wrote it, because in a statistical sense, that’s exactly what it’s modeling.
That leaves two kinds of signal still standing, and they weren’t affected by any of this, because they were never about the words.
The signals that still work
| Signal | Still reliable in 2026? | Why |
|---|---|---|
| Grammar / phrasing quality | No | AI content matches native-speaker fluency by default |
| Generic greeting / no personalization | Weak | Still a tell for low-effort attacks, but AI closes this gap fast too |
| Urgency / pressure language | Weak | Common but easy for AI to soften, and legitimate mail uses it too |
| SPF / DKIM / DMARC alignment | Yes | Cryptographic and DNS-based; content has no bearing on it |
| Sending domain age and history | Yes | Attackers can't fake a track record they don't have |
| Recipient engagement pattern | Yes | Complaint rate and reply behavior reflect real relationship quality |
Authentication and domain reputation were always the load-bearing part of email trust — content quality was a convenient proxy, available to a human reader who couldn’t check DNS records in real time. Filters, on the other hand, have always checked DNS records in real time. Gmail’s published sender requirements describe exactly this: authentication status, sending consistency, complaint rate, and engagement — nothing about whether the copy reads as machine-generated. That mechanism doesn’t care whether the 80% figure exists. It was built for a world where the content signal was never the one doing the real work.
Why this cuts against attackers less than it sounds
It’s tempting to read “AI phishing is more convincing” as “AI phishing is winning.” Microsoft’s 2025 Digital Defense Report found AI-generated phishing lures get a 54% click-through rate versus 12% for manually written ones — a real, measured jump in effectiveness at the recipient level. But click-through isn’t delivery. A message that never lands in the inbox never gets the chance to be persuasive, and the filters deciding delivery are the ones still running on authentication and reputation, not prose quality. The 80% figure describes attackers getting better at the part of the funnel that was always easiest to automate — drafting — while leaving the part that was always hardest to fake — a clean sending history — exactly as hard as it was before.
The same shift is showing up beyond email
ENISA’s report doesn’t stop at written phishing. It also flags audio and video deepfakes feeding a new generation of business email compromise, where a follow-up phone call — a synthesized “voice” of an executive requesting an urgent transfer or a credential reset — reinforces a written request that would otherwise be easy to second-guess. That’s the same underlying dynamic as the 80% figure, applied to a channel where there’s no DNS record to check at all: once the content-quality bar clears “sounds like a real person,” the burden shifts entirely onto process — verifying a request through a second, known channel — rather than onto anyone’s ear for what sounds synthetic.
What this means if you send legitimate cold email
The honest read for anyone running outbound is that AI-assisted drafting was never the liability the “spot the bot” folk wisdom implied, and the ENISA numbers are further proof the industry has moved on from judging content by its origin. What actually keeps a legitimate sender out of the same bucket as the 80% is the boring infrastructure work: SPF, DKIM, and DMARC correctly configured and aligned, a domain with real sending history behind it, and a spam complaint rate under the roughly 0.3% threshold where providers start suppressing delivery regardless of who or what wrote the message. None of that changes because the words got better on both sides of the fence — if anything, it matters more, because it’s now doing a larger share of the work that “this doesn’t read like a scam” used to do for free.
That’s the layer Norbelys is built around rather than bolted onto after the fact. New senders ramp through gradual warmup instead of the sudden-volume burst that both phishing operations and sloppy cold-email tools rely on, and Norbelys’s own DMARC monitoring flags an alignment break on your sending domain before a mailbox provider’s filter does it for you. Content quality was never the signal keeping a legitimate sender out of the 80% bucket — a domain Norbelys has actually authenticated and warmed correctly is.