The AI landscape doesn't move in one direction — it lurches. Some techniques leap from experiment to table stakes in a single quarter; others stall against regulatory walls, technical ceilings, or organisational inertia that no amount of hype can dislodge. Knowing which is which is the hard part. The State of Play cuts through the noise with a rigorously maintained index of AI techniques across every major business domain — classified by maturity, evidenced by real-world adoption, and updated daily so you always know where you stand relative to the field. Stop guessing. Start knowing.
A daily newsletter distilling the past two weeks of movement in a domain or two — delivered to your inbox while the index updates in the background.
Each dot marks the weighted maturity of practices within a domain — hover for a brief summary, click for more detail
AI that identifies phishing attempts across email, messaging, and web, including sophisticated spear-phishing campaigns. Includes NLP-based email analysis and URL reputation scoring; distinct from data loss prevention which protects outbound data rather than detecting inbound threats.
AI-powered phishing detection is a proven, widely deployed practice — but it faces a critical bifurcation in 2026 between technical capability and operational effectiveness. Detection research and vendor platforms have reached theoretical maturity: models exceed 97% accuracy in controlled settings, production deployments block billions of emails monthly, and the ecosystem spans leading vendors (Proofpoint, Barracuda, Cofense) to specialized entrants (Abnormal, IRONSCALES). Yet real-world evidence reveals persistent gaps. UK government data shows 38% of businesses report phishing attacks and 85% of breached organisations involve phishing in the attack chain. Real-world deployments reveal detection failures: large organisations consistently find 3,000+ phishing emails missed quarterly by leading platforms, while attackers have systematised response with phishing-as-a-service (90% of high-volume campaigns) and AI-assisted code generation (hybrid human-AI attacks achieving 54% click-through vs 12% human baseline). The defining tension is not technical but operational: the organisations deploying pure-detection play defenses face attackers adapting faster than filters improve, with multi-channel tactics (email, Teams, calendar, reverse proxies) overwhelming email-only controls. Practitioner surveys confirm overconfidence masking underpreparedness: 86% of attacks now use AI while only 17% of organisations deploy AI-powered defences. The practice remains on a plateau—mature capability coexisting with expanding threat surface and human-factor limitations that no detection improvement overcomes.
July 2026 telemetry confirms an inflection in attacker tactics toward post-authentication vectors while AI-powered phishing reaches human-level sophistication. Adversary-in-the-middle (AitM) and OAuth consent phishing have emerged as the dominant credential-theft mechanism: Tycoon2FA and related campaigns reached 500,000+ organizations with 40,000 incidents detected daily, employing CAPTCHA evasion and MFA-bypass infrastructure at industrial scale. Real incident data now shows AitM attacks achieving 84% MFA failure rates, collapsing the assumption that multi-factor authentication alone protects against modern phishing. Peer-reviewed research validates the escalation: AI-automated spear phishing now matches human expert performance at 54% click-through rates (vs. 12% for traditional campaigns), while AI-generated attacks have grown from 40% of volume (mid-2024) to 86%+ prevalence. Detection capability has simultaneously matured: Red Canary's orchestrated AI subagent deployment achieves 94% accuracy with transparent reasoning, Abnormal's behavioral baseline approach protects 3,200+ organizations including 25% of Fortune 500, and Proofpoint's multi-vendor benchmarking shows 27.1% additional threat detection beyond leading cloud platforms.
Yet real-world effectiveness gaps persist. Behavioral AI detection successfully blocks sophisticated attacks (Australian Football League prevented 8M+ threats monthly at 99.99% effectiveness), but 20% of phishing attacks still bypass enterprise detection at the browser layer where late-stage redirects and CAPTCHA overlays execute. Post-delivery analysis shows 30% of business email compromise emails land in inboxes despite passing technical filters—evidence that context-aware detection exceeds message-scoring capability. The multi-channel fragmentation documented in May continues through July: calendar phishing, Teams-based attacks, and reverse proxy credential interception remain elevated, forcing detection systems to correlate signals across identity, access, and email layers rather than treating inbox defense in isolation. Detection latency compounds the gap: AI-generated phishing variants reach production at machine speed, outpacing signature-based defenses' ability to fingerprint novel payloads. The foundational constraint remains organizational: 86% of attacks use AI while only a fraction of enterprise deployments employ behavioral AI detection, signaling that mature technical capability exists but organizational adoption and skill gaps limit operational impact.
— Critical negative signal: 89% of phishing domains active <2 days; 25+ device code phishing kits in wild; 95% use bot protection evasion. Demonstrates indicator-based defenses structurally inadequate against AI-accelerated infrastructure rotation and automated page generation.
— Cisco Talos independent incident response data: phishing primary attack vector in >50% Q2 2026 engagements (up from 33% Q1); 65% involved authentication abuse; ARToken phishing-as-a-service exposed 80+ API endpoints. Documents attacker adoption of evasion and credential-theft platforms.
— IBM/Ponemon Cost of Data Breach study (602 orgs): AI-driven attacks increased 56% YoY, adding USD 1M per breach; attackers can 'generate persuasive phishing content, adapt malware and test exploits at machine speed.' Quantifies deployment impact and attacker AI adoption.
— Microsoft Threat Intelligence Q2 2026: 7.6B phishing threats detected; Tycoon2FA disruption achieved 92% volume decline; QR code phishing peaked 18.7M (March), declined 38% (May). Documents both detection scale and threat evolution adaptation to evasion techniques.
— Production detection examples with monthly scale metrics: 4.9M brand impersonations, 46K QR phishing, 242K CEO impersonations, 960K Bayesian-poisoning detected monthly. Demonstrates multi-layer AI detection of evasion techniques in real-world deployment.
— PRISMA systematic review of 36 studies (2023-2025) across IEEE/ScienceDirect/ACM/Scopus showing LLMs accelerate and automate phishing processes while advancing defensive capabilities; LLM-based detection approaches outperform traditional ML and approach human-level performance.
— Barracuda threat research on evasion technique: 1M+ retail-themed campaigns since April 2026 using CSS/HTML to hide benign text, diluting malicious keyword concentration. Demonstrates attacker adaptation targeting AI filters and LLM detection limitations; LLMs lack user-perspective rendering.
— Named fintech deployment: behavioral AI detects phishing attacks missed by legacy secure email gateway; fast incident response with transparent remediation. Demonstrates real-world deployment advantage of behavioral detection over rule-based systems.