Phishing Simulations Evolve for AI Era: What Organizations Must Do

Phishing is evolving through generative AI, and organizations can no longer rely on generic template drills to safeguard employees. In the latest episode of Apple @ Work, leaders from Sublime Security discussed how phishing simulations need to become tailored, realistic, and adaptive for the new AI-fueled threat landscape. Here’s what’s changing — and what teams can do to keep up.

How Generative AI Transforms Phishing

AI is accelerating phishing attacks in ways that make them far more convincing and difficult to flag. Unlike traditional scams rife with spelling mistakes or generic warnings, AI-crafted messages now incorporate personalized cues—real business workflows, internal lingo, vendor or project references—that mimic legitimate interactions. Phishing isn’t just emailing anymore; attackers coordinate across email, phone, and video using voice cloning or deepfake tools.

These advances blunt or bypass many standard defenses. Filters aimed at spotting misspellings or unfamiliar domains struggle when content is polished, domain names are subtle lookalikes, or campaign variants shift daily. Even user awareness programs—if built on recycled simulations—can fail to teach employees what real threats look like in 2026.

From Template-Based Tests to Realistic Simulations

According to Sublime Security, many phishing simulations today look different from the threats employees actually face. They rely heavily on predictable templates that employees learn to recognize. What’s needed instead are simulations that adapt to the real attack surface: job role, vendor relationships, communication style, and likely threat vectors.

Effective simulations should span multiple channels—not only email, but SMS, voice, and video—because modern phishing often chain these. Depth matters: tracking behavior signals like time-to-click or reporting delay reveals more than pass/fail click-tracking alone. Teams exposed to higher risk roles should receive more simulation volume; varied frequency helps prevent desensitization.

Sublime’s Approach: Automation & Adaptation

Sublime Security offers two AI-powered agents designed to shift the balance from reactive detection to proactive prevention. The first, ASA (Autonomous Security Analyst), inspects incoming messages—especially user-reported or flagged ones—provides verdicts, and in active mode can remediate automatically. It brings context from attachments, links, sender profiles, landing pages—and explains its reasoning so defenders can understand what triggered the alert.

The second agent, ADÉ (Autonomous Detection Engineer), steps in when novel attack variants emerge. It analyzes message structures, sender signals, and behaviors to generate new detection logic within hours—not days. These detections survive changes in superficial indicators, so attackers can’t easily evade them by rotating domains or slightly altering email content.

One broader point: prevention matters more than triage. Reactive tools that simply investigate after incidents without closing the underlying gaps leave an organization perpetually behind. Sublime emphasizes clustering similar threats, sweeping email inboxes when variants of a campaign appear, and creating durable detection rules. Such capabilities mean that one reported phishing message can preempt many more.

Real-world results back this up: some organizations report detecting many times more attacks, shrinking investigation times significantly, and reducing daily time spent managing email threats.

What this means: the era of static phishing tests is over. As AI upgrades the realism and scale of scams, organizations must recalibrate training, detection, and response systems. Leaders should ask not just how many phishing emails are blocked, but how fast systems adapt when something gets past them. Watch closely: vendors who can auto-generate tailored simulations, deploy behavior-based detection rules that survive superficial changes, and integrate prevention (not just monitoring) are likely to be the ones that steer security from cleanup into real protection.