For years, one of the more reliable tells for a phishing email was the writing itself — a slightly off turn of phrase, an unusual formality, a typo in the wrong place. That tell is mostly gone. Oxford research cited across multiple 2026 security reports found AI-generated phishing emails now achieve a 54% click-through rate, statistically matching phishing written by human experts, and far above the 12% rate for older, generic phishing templates.

The volume shift is just as significant as the quality shift. IBM X-Force's 2026 reporting found generative AI has cut the time to produce a convincing phishing email from around 16 hours to about 5 minutes, and the FBI's IC3 unit tracked AI-attributed phishing losses formally for the first time in its 2025 annual report — $10.3 million across just 803 complaints that explicitly referenced AI.

Business email compromise, the more targeted and financially damaging variant, generated over $3 billion in reported losses last year from a relatively small number of complaints — an average of roughly $123,000 per incident, according to the FBI's IC3 data. It doesn't rely on malware or a malicious link; it relies entirely on a convincing impersonation and a legitimate-looking payment request.

The practical shift for training: telling employees to look for bad grammar or a strange tone is no longer useful advice. What still works is training people to notice behavioral red flags instead — unexpected urgency, a request that skips a normal approval step, a sender asking for something slightly outside the usual pattern — because those signals survive even when the writing itself is flawless.