SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
Abnormal AI adds email controls & phishing training

Abnormal AI adds email controls & phishing training

Fri, 28th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Abnormal AI has expanded its email security platform with Control Centre, Email DLP Rules and upgrades to AI Phishing Coach. The additions extend coverage across inbound email threats, outbound messages and employee training.

The move reflects a shift in email risk as attackers use generative AI to create more convincing messages that resemble routine business communications. Abnormal's approach uses behavioural analysis to detect when email activity diverges from an organisation's normal patterns.

Control Centre is designed to give security teams more direct oversight of how the platform responds to potential threats. It allows customers to create custom detection models and rules for their own environments without writing code, and shows whether a decision came from the company's core models, a custom model or a custom rule.

That visibility addresses a recurring challenge for security teams that need to investigate alerts quickly and explain why a message was blocked, flagged or allowed. By showing which detection layer reached a verdict, the tool is intended to help internal teams map automated actions to their own policies and review processes.

Outbound focus

Email DLP Rules pushes beyond inbound email protection into outbound data loss prevention. The feature combines policy controls such as regular expressions, phrase matching, metadata conditions, Boolean logic and exclusions with an AI Triage Agent that reviews the broader context of each message.

The agent evaluates the purpose of a rule, the sender and the message context before deciding whether to release a message or quarantine it. Each verdict is then recorded in an outbound log, giving organisations an audit trail for policy enforcement.

Data loss prevention has often been difficult for large organisations to manage because high alert volumes can create a heavy manual review burden. Abnormal is positioning the new feature as a way to reduce that workload while still applying explicit rules to outbound communications.

Training changes

The AI Phishing Coach updates focus on employee awareness and simulation training. Rather than sending the same phishing tests to all staff on a fixed schedule, the updated system adjusts simulation difficulty and recommends follow-up training using engagement and risk signals gathered across an organisation.

Administrators can also generate customised simulations and training materials from plain-language prompts, while retaining visibility into the resulting content and the follow-up actions attached to it. That means security teams can adapt training to the attacks users are most likely to face instead of relying on generic exercises.

The latest changes underline how email security vendors are trying to extend their role beyond filtering malicious messages. Businesses are increasingly looking for tools that address employee behaviour, outbound policy controls and the ability to adjust automated decisions to internal requirements.

Abnormal says it protects more than 4,500 organisations, including more than 25% of the Fortune 500. The company describes itself as an AI-native behaviour security provider, with a broader platform that also covers identity and insider threat risks.

In its announcement, Abnormal also referred to three broader product areas: Identity Threat Protection, AI Governance and Infiltration Prevention. The main additions detailed were the three email-related features, which together aim to cover what enters the inbox, what leaves an organisation and how employees respond to attempted attacks.

The release schedule differs across the new products. Custom AI Models within Control Centre and the latest AI Phishing Coach functions are generally available from the end of the month, while Custom Rules in Control Centre and Email DLP Rules are being offered first through early access.

Demand for greater control over security automation has grown as companies deploy more AI-based defences. Buyers increasingly want not only accurate detection but also clearer explanations of why systems made a decision, particularly where compliance, employee communications and sensitive data are involved.

At the same time, cyber criminals are using AI tools to make phishing emails more fluent, more targeted and easier to adapt during a campaign. That has made it harder for older security systems that rely on fixed indicators, such as known malicious domains or signature matching, to identify suspicious traffic before it reaches staff.

Abnormal argues that this shift requires email security systems to detect behavioural anomalies rather than rely only on traditional warning signs. In practice, that means assessing whether the message, sender and context fit the usual communication patterns within a business.

"The role of email security is expanding," said Evan Reiser, Chief Executive Officer and Co-founder of Abnormal AI.

"Organisations still need to stop sophisticated inbound attacks, but they're increasingly looking to the same platform to address outbound data loss, employee phishing risk, and greater control over automated detection. Securing email now means addressing risk from multiple directions: the threats coming in, the sensitive information going out, and the people attackers continue to target. These new capabilities expand how Abnormal helps organizations manage that risk," Reiser said.