Saltar al contenido principal

Aug 26, 2026

AI Phishing Coach Gets Smarter: Training That Responds to Employee Behavior

Abnormal AI Phishing Coach adapts training to employee behavior, using real-world threats and behavioral signals to personalize simulations, measure risk, and build stronger security habits.

Every other attack surface in an organization gets measured. Security teams scan endpoints for infection, cloud infrastructure for misconfigurations, software and hardware for vulnerabilities, and identity for exposure. Then there’s the human layer, the layer that shows up in every incident, because all it takes is a careless mistake.

Security awareness training was designed to be a security and compliance checkbox for that human layer. But a checkbox doesn’t lower risk. Security awareness teams spent hours curating and assigning generic annual videos, selecting monthly phishing tests from a sea of irrelevant templates, and were pressured to ensure completion percentages were above an arbitrary line and click rates were in the low single digits. But that did not solve the problem. Security awareness teams got really good at getting people to sit through training videos and became adept at picking the simulations to keep click rates artificially low.

The results did not match the effort and time spent. The tasks got done, but risky behaviors didn’t change. Gartner found that 60% of data breaches involved the human element, and 41% of employees admit to bypassing their organization’s cybersecurity guidance

In conversations with hundreds of Abnormal customers, one thing is clear: even in the face of this continued risk, completion rates have never been higher and click rates never lower. Something is missing: what can’t be measured is behavioral change. And that is exactly what these organizations note they require. Even when tools are in place that claim to measure behavior, the training and simulations employees are forced to consume don’t reflect reality.

Organizations require a better class of human risk management. They need a program built on a deep understanding of human behavioral patterns and the real attacks targeting their employees. Abnormal has this understanding and attack knowledge. Now, we are upgrading AI Phishing Coach to better secure the human layer.

Inside this Evolution of AI Phishing Coach: Far Beyond Generic Templates

We have significantly expanded the core pillars of AI Phishing Coach while keeping to the foundation that has excited hundreds of customers over the last year. Employees are still trained on the real attacks Abnormal stops. But now, based on how employees interact with that training, programs are recalibrated, and administrators get a reliable way to measure behavioral change and risk trends.

AI Phishing Coach leverages the behavioral AI Abnormal was built on with a new capability, Precision Training, designed to calibrate simulation frequency and difficulty based on near-imperceptible behavioral nuances. AI Phishing Coach now delivers the right training to the right person in the right amount.

But it doesn’t stop there. Many organizations need the ability to customize training. Emerging threats that have not yet targeted the organization require proactive simulation campaigns. Specific policies or urgent changes to security best practices unique to the business necessitate tailored lessons. While automation is at the core of AI Phishing Coach, the AI backbone behind everything Abnormal does now extends to a generative AI surface in the Portal itself. With little more than a plain language prompt, email simulations and video modules can be generated when they’re needed the most.

FalCon_AIPC_Blog_Screenshot_1.png
Training programs are now calibrated based on behavior.

Precision Training: Simulations Tuned By Workforce Behaviors

Precision Training changes how the program runs day to day. Now, security teams don’t need to guess what an employee needs. As phishing risk and behaviors change over time, AI Phishing Coach recalibrates. Employees with elevated risk signals get more frequent, more difficult simulations. Those who have shown they can spot threats quickly and report them see less frequent simulations. And it doesn’t stop at simulations. Training videos are assigned when employees need remedial training, not queued on a static calendar but at the moment when training interactions indicate it’s warranted.

Example: An employee clicks a credential-harvesting simulation and enters their password into the landing page. The employee receives just-in-time coaching, but this may be a one-time event, so nothing else changes immediately. Then that employee enters their credentials again two weeks later. Precision Training kicks in: this employee now gets multiple credential phishing simulations in the same month. The simulations become a bit more obvious to try to nudge this individual to make the right call. To reinforce learning, that employee is also assigned a short training video on how to recognize a fake login page. Three months later their ability to recognize threats has improved, so training frequency lessens. No one on the security team ever touched a dial.

FalCon_AIPC_Blog_Screenshot_2.png
Three new surfaces are provided to create and deploy simulations and content.

Attack, Training, and Campaign Creator: Start Training Programs With a Prompt

Not every threat an organization wants to train against has reached the business yet, and not every lesson comes packaged in an off-the-shelf module. Attack Creator lets an admin describe a scenario in plain language, like a new phishing tactic a peer in the industry reported receiving, and generates a realistic simulation that is stored in the Attack Library. Additionally, this capability, and all other simulations generated by AI Phishing Coach, can now be scheduled and sent as ad hoc or baseline campaigns with the Campaign Creator, giving additional customization without sacrificing personalization and automation.

The same type of generation can be done for training videos. With Training Creator, all that’s needed is an idea. Enter a prompt and imagery into the Training Creator interface, and AI Phishing Coach guides security awareness owners through custom module creation. Training Creator also recommends modules to create based on threat patterns Abnormal observes. The content is still generated through Abnormal's behavioral understanding, so custom never means generic. Organizations now get the freedom to build without giving up the personalization and automation that make the program work.

Example: A hospital in the nearby county gets hit with a fake benefits-enrollment email during open enrollment season. The security awareness admin types that scenario into the Attack Creator, and shortly after a defanged version of that attack lands in the Attack Library and can be configured to specifically train the HR and finance teams. Plus, a short video on the tactic can be generated off of a similar prompt.

FalCon_AIPC_Blog_Screenshot_3.png
QR code simulations allow training on this common threat type.

QR Code Phishing Simulations

QR code phishing succeeds because people spent years being trained to scrutinize links, and no one taught them to distrust the little square that restaurants use to store their wine list. QR Code Phishing Simulations are aimed at closing that gap, training employees to treat a code in an email with the same suspicion as a strange URL. AI Phishing Coach’s QR Codes will display even in clients that block images, so the simulation shows up and interaction can be documented.

Example: An employee gets an email claiming their MFA enrollment expires today with a QR code to "re-verify." They scan it out of habit. As a simulation, that scan triggers coaching on why a QR code deserves the same scrutiny as a link, so the next time a real attacker is behind the code, that employee will likely think twice.

FalCon_AIPC_Blog_Screenshot_4.png
Follow-ups in existing threads nudge toward engagement.

In-Thread Follow-Up

The most convincing part of a real attack is often the second message. An attacker who gets no reply will typically follow up inside the same thread, because an existing conversation reads as legitimate even when it is not. In-Thread Follow-Up trains for exactly that move. When an employee neither clicks nor reports the first simulation, AI Phishing Coach re-engages inside the same thread, extending the simulation rather than treating no response as a dead end.

Example: A simulated invoice email lands in the inbox and the employee ignores it, neither clicking nor reporting. A day later a reply arrives in the same thread: "following up on the below, can you confirm payment today?" That nudge closely mirrors what a real attacker sends, and it is often the message that works. Whether the employee finally clicks or finally reports, AI Phishing Coach now has a signal where silence used to leave a blank.

From a Program You Run to a Program That Runs

Before, security awareness was something operated by hand: picking templates, scheduling campaigns, chasing completion, and reporting metrics that lacked context. After, it is a program that trains on real threats, on real scenarios, and is purpose-built to measurably change behavior to build better security habits.

For the CISO, that gives a defensible answer to the only question the Board cares about: is our human risk lower than last quarter? For the security awareness team, it is the hours back from running campaigns by hand. For the SOC, it is the first time the awareness program and the detection stack share the same signal, so the people likely to be targeted are the people getting trained.

These upgraded capabilities for AI Phishing Coach become generally available for all customers at Fal.Con. To see how it can lower human risk in your organization, connect with your Abnormal team or request access.

The above is intended to outline our general product direction. It is intended for information purposes only, and may not be incorporated into any contract. It is not a commitment to deliver any material, code, or functionality, and should not be relied upon in making purchasing decisions. The development, release, and timing of any features or functionality described for Abnormal AI's products remains at the sole discretion of Abnormal AI and is subject to change.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.