AI-Written Phishing: What Has Changed
AI lets attackers write fluent, personalised phishing in any language. What has changed, what has not, and the checks that still catch AI-written phishing.

For years, the advice was to look for spelling mistakes and awkward grammar. AI writing tools have made that advice much less useful. Attackers can now produce fluent, polite, personalised messages in any language within seconds. Here is what has changed, and what still works.
What AI changes
| Before | With AI |
|---|---|
| Clumsy grammar and spelling | Fluent, natural language |
| Generic "Dear Customer" | Personalised with your name, role and context |
| Mostly English | Any language, including local phrasing |
| One template for all | Many variations that dodge filters |
| Slow replies | Instant, convincing conversations. See AI chatbot scams |
What has not changed
The message still has to get you to do something: sign in on a fake page, pay, share a code, call a number or open a file. That request is where you catch it.
Checks that still work
- Was I expecting this?
- Where does the link really go? See how to read a URL.
- Who really sent it? See checking the sender's real address.
- Can I verify it another way? Open the app or call a known number.
Technology helps where eyes cannot. Password managers refuse to fill passwords on fake sites, and passkeys cannot be phished at all. See passkeys vs phishing.
Received a polished message you are unsure about? Paste it into CyberWatch AI Scan for a free check.
For more, read our complete guide to phishing.
Frequently asked questions
Can I still spot phishing by spelling mistakes?
Less and less. AI tools produce fluent text, so good spelling and grammar no longer suggest a message is genuine.
Is AI phishing harder to stop?
It is more convincing to read, but the request is the same: click, sign in, pay, share a code or open a file. Checks based on the request still work.
Do AI detection tools help?
Tools can help flag suspicious messages, but verification habits and phishing-resistant sign-in remain the strongest defences.
Sources
- Phishing: spot and report scam emails, texts, websites and calls, UK National Cyber Security Centre
- How To Recognize and Avoid Phishing Scams, US Federal Trade Commission
- Implementing phishing-resistant MFA (fact sheet), US Cybersecurity and Infrastructure Security Agency


