If phishing emails feel less obviously fake than they used to, that is not just a feeling. Researchers who tracked click-through rates found that AI-written phishing emails now perform close to emails written by human scam experts, and far better than the clumsy, typo-filled messages most people learned to spot years ago. At the same time, the inboxes catching those emails have gotten smarter too. Both things are true at once, and that tension is the real story of email in 2026.
How much harder is it to spot an AI phishing email now
A study published in Expert Systems with Applications tested this directly. Researchers built fully automated AI systems that researched a target, then wrote a personalized spear-phishing email with no human involvement. Those AI-only emails got a 54 percent click-through rate, statistically on par with emails written by human phishing experts, and well above the 12 percent rate for generic template emails. When a human reviewed and lightly edited the AI draft, the click rate rose slightly to 56 percent.
Separately, CrowdStrike president Michael Sentonas said publicly in September 2026 that AI has pushed real-world phishing click-through rates past 60 percent, up from roughly 11 to 12 percent a year earlier. Different methodology, similar direction: AI-written scam email is closing the gap with, or beating, what a skilled human scammer could write by hand.
The part of the story most headlines skip
Here is where it gets more honest than the scariest stats suggest. A threat intelligence report published in March 2026 through the Messaging, Malware and Mobile Anti-Abuse Working Group analyzed more than 20,000 real phishing emails and found that AI-generated phishing bypassed Gmail and Microsoft filters about 50.3 percent of the time, compared to 28.5 percent for human-written phishing. That is a real gap.
But the same researchers were unusually candid about a problem most vendors gloss over: figuring out whether an email was actually written by AI is genuinely hard. Their own estimate put AI-generated volume at around 22 percent of observed phishing, while other industry reports have claimed anywhere from under 5 percent to over 80 percent. When the range of estimates is that wide, it is a sign that "AI wrote this scam email" is often more of a guess than a measurement, even among people building tools to detect it.
Email filters got measurably better too
The defensive side is not standing still. Google has said Gmail blocks more than 99.9 percent of spam, phishing, and malware before it reaches an inbox, out of roughly 15 billion unwanted messages a day. A big part of that comes from RETVec, a text-analysis model Google built specifically to catch the tricks scammers use to slip past filters, like swapping letters for lookalike characters or hiding keywords inside images. Google's own published testing found RETVec improved spam detection by 38 percent over the previous system while cutting false positives, emails wrongly flagged as spam, by nearly 20 percent.
That false-positive drop matters more than it sounds. Filters that are too aggressive end up burying real emails, which is often why people turn filtering down and let more junk through. A filter that catches more spam without also hiding more real mail is a genuine improvement, not just a bigger number.
When the AI assistant itself becomes the attack surface
The most interesting wrinkle in 2026 is not AI writing better scam emails. It is attackers targeting the AI features built into email itself. In mid-2026, a researcher at Mozilla's bug bounty program showed that Gmail's Gemini-powered summary feature could be manipulated by hiding invisible text inside an email, tiny white-on-white font that a human would never see but that Gemini would still read and follow as an instruction.
In the researcher's demonstration, this hidden text made Gemini generate a summary falsely warning the user that their Gmail password had been compromised, complete with a fake support number to call. No suspicious link, no attachment, no obvious red flag: just a normal-looking email that tricks the AI assistant into producing the scam message itself. Google has since added protections against this type of hidden-prompt manipulation, but it is a preview of a new category of risk: the summarizing, drafting, and replying tools meant to make email easier can be turned against the person using them.
What this actually means for your inbox
- Assume any email that creates urgency, a security alert, an unpaid invoice, a locked account, deserves a second look regardless of how polished it reads, since polish is no longer a reliable signal of legitimacy.
- Do not trust an AI-generated summary of an email as the full picture, especially if it tells you to call a number or click a link. Open the original message if something feels off.
- Verify unusual requests, especially ones involving money or credentials, through a separate channel you already know is real, not a phone number or link contained in the email.
- Keep filters and built-in AI protections turned on. The data shows they are genuinely catching more than they used to, even though no filter is close to catching everything.
The takeaway
The honest version of this story is not "AI made phishing unstoppable" or "AI filters have it handled." It is that both sides of email security are being rebuilt on the same technology at the same time, and neither side has pulled ahead for good. What has changed is where your attention needs to go: less on catching typos and broken grammar, more on questioning urgency, verifying requests through a second channel, and treating even a trusted AI assistant's summary as a starting point rather than the final word.