Back to vendors
A

Abnormal AI

Also known as: Abnormal AI, Abnormal Security, AI Security Mailbox, AI Phishing Coach, AI Data Analyst, Attune, Attune 1.0

Visit site
Entry priceContact salesFull pricing detail

Behavioural AI email security with three named autonomous agents: a mailbox that triages user reports and explains itself to employees, a coach that trains at the point of error, and an analyst queried by email.

Abnormal AI, formerly Abnormal Security, built its business on a single architectural bet stated plainly in its own words: understanding normal behaviour is a more durable defence than cataloguing known threats, particularly against AI generated attacks designed to look different every time. In March 2026 it shipped Attune 1.0, its own behavioural AI foundation model.

The agent layer is named and distinct rather than a single assistant. AI Security Mailbox autonomously triages user reported emails around the clock, sorting them into malicious, spam, safe or phishing simulation, then replies to the employee with a detailed explanation and answers their follow up questions. AI Phishing Coach delivers a personalised micro lesson the moment someone interacts with a suspicious message, replacing annual training with instruction at the point of error. AI Data Analyst is queried by email in natural language and returns executive ready reports covering funnel metrics, attack vectors and detection performance.

Underneath sits a behavioural detection engine combining large language models with graph intelligence, evaluating sender history, content anomalies and relationship signals across tens of thousands of signals, plus identity baselines that surface account takeover. URL rewriting routes every click through real time analysis and revokes access if a page weaponises after delivery. Deployment is API native, connecting to Microsoft 365 or Google Workspace in minutes.

The posture worth noting is autonomy. An independent review observes that autonomous blocking by default means less granular manual control for security teams, which places Abnormal at the autonomy forward end of a market where most large vendors are arguing the opposite.

Vendor details

Canonical URL

https://abnormal.ai

Category

Security / SOC agent

Subcategory

Behavioural AI email and collaboration security

Funding status

Private. Named to the CNBC Disruptor 50 for a third consecutive year in May 2026. Recognised as a Leader in the Gartner Magic Quadrant for Email Security Platforms.

Company status

independent

Use cases & customers

Primary use cases

autonomous triage of user reported suspicious emailsbusiness email compromise and social engineering detectionaccount takeover detection with real time session revocationpoint of error security awareness coachingbehavioural threat detection across Slack, Teams and Zoom

Target customers

large enterprisemid-marketMicrosoft 365 and Google Workspace estatessecurity operations teams

Deployment options

API native SaaS, one click connection to Microsoft 365 and Google Workspace with no mail flow changes

Integrations

API native rather than inline: one click API connections to Microsoft 365 and Google Workspace deploy in minutes without infrastructure changes or mail flow disruption. Behavioural analysis extends beyond email across Slack, Teams and Zoom as a unified surface, and the platform reaches into identity threat protection and monitoring of third party AI usage.

In practice

An employee reports a suspicious email and receives an explained verdict within minutes rather than waiting for an analyst to reach the queue the next working day.

Someone clicks a link that was clean at delivery and weaponised afterwards, and access is revoked at click time rather than discovered later.

A security lead emails a natural language question to the AI Data Analyst and receives an executive ready report on attack vectors and detection performance without building it by hand.

Agentic Index coverage score

9.0 / 14 capabilities · 64%

Integrations & Tool CallingAPI NATIVE rather than inline: one click API connections to Microsoft 365 and Google Workspace deploy in minutes with no infrastructure changes and no mail flow disruption, with unified behavioural analysis extending across Slack, Teams and Zoom, plus identity threat protection and monitoring of third party AI usage. Abnormal AI platform and trends pages 2026-08-08 Full
Workflow OrchestrationShips an INTEGRATED MULTI AGENT ARCHITECTURE rather than isolated point agents, with AI Security Mailbox, AI Phishing Coach and AI Data Analyst coordinating across triage, remediation and user education, and the vendor explicitly argues for integrated agent architectures over isolated task specific agents. Abnormal AI autonomous agents and market pages 2026-08-08 Full
Knowledge Grounding & RAGATTUNE 1.0, its own behavioural AI FOUNDATION MODEL shipped March 2026, sits under a detection engine combining large language models with GRAPH INTELLIGENCE, evaluating sender history, content anomalies and relationship signals across tens of thousands of signals plus identity baselines. Grounded in the customer's own learned normal rather than a global threat catalogue. Abnormal AI product pages and independent review 2026-08-08 Full
Human Oversight & GuardrailsTHE INTERESTING GRADE ON THIS RECORD. Agents explain every verdict to the employee in detail and answer follow up questions, which is transparency, but an independent review states that AUTONOMOUS BLOCKING BY DEFAULT MEANS LESS GRANULAR MANUAL CONTROL for security teams. That is a deliberate autonomy forward design choice rather than an omission, and it places Abnormal opposite palo-alto in the same lane. Abnormal AI product pages and independent review 2026-08-08 Partial
Security, Identity & GovernanceNOT RETRIEVED AND LIKELY AN UNDERGRADE - FLAGGED FOR CORRECTION. Abnormal is a Gartner Magic Quadrant Leader selling to large regulated enterprises, so attestations certainly exist, but none were retrieved in this pass. EIGHTH instance of the Sec paradox. Check abnormal.ai trust or compliance pages and correct. Abnormal AI public sources 2026-08-08 Partial
Observability & AuditabilityAI Data Analyst generates executive ready reports on demand covering funnel metrics, top attack vectors and detection performance, while AI Security Mailbox returns a detailed written explanation of every verdict to the reporting employee - so reasoning is exposed to both the security team and the end user, which is unusual. Abnormal AI trends and autonomous agents pages 2026-08-08 Full
Memory & State PersistenceBehavioural baselines and identity profiles persist per organisation and adapt continuously without manual tuning, which is durable learned state, but it is a DETECTION MODEL rather than agent memory and is graded the same way as darktrace. No conversation or task context persistence is documented. Abnormal AI platform description 2026-08-08 Partial
Deployment & Data ResidencyAPI native SaaS only, connecting to Microsoft 365 or Google Workspace without infrastructure changes - which is a genuine deployment advantage in speed but offers no self hosting, and no regional residency matrix was retrieved in this pass. Abnormal AI platform description 2026-08-08 Partial
Prebuilt Agents, Templates & PacksThree NAMED prebuilt agents ship ready to run - AI Security Mailbox, AI Phishing Coach and AI Data Analyst - alongside packaged inbound email security, account takeover protection and identity threat protection, all activated through a one click connection rather than assembled by the customer. Abnormal AI autonomous agents page and independent review 2026-08-08 Full
Triggers & Channel CoverageAI Security Mailbox triages user reported email 24/7 rather than in business hours, AI Phishing Coach fires INSTANTLY after a suspicious email interaction, URL rewriting evaluates at click time rather than delivery time, and AI Data Analyst is invoked BY EMAIL in natural language - an unusual agent interface worth noting. Abnormal AI autonomous agents and trends pages 2026-08-08 Full
Model Flexibility & RoutingRuns its own ATTUNE 1.0 behavioural foundation model as the core intellectual property alongside large language models inside the detection engine; no model selection, provider choice or bring your own model capability exists or would be architecturally coherent. Honest absence by design, same reasoning as darktrace. Abnormal AI product materials 2026-08-08 Unable to verify
APIs, SDKs & MCP ExtensibilityThe platform is API native by architecture and integrates across email, collaboration and identity surfaces, which implies a substantial programmable surface, but no public API reference, SDK family, developer portal or MCP support was retrieved in this pass. Abnormal AI public sources 2026-08-08 Partial
Testing, Debugging & OptimizationDetection performance is reported as a first class metric through AI Data Analyst, and the platform distinguishes phishing simulations from real threats during triage which is a form of continuous calibration, but no customer facing evaluation harness, simulation mode or regression testing of agent behaviour was documented. Abnormal AI trends page 2026-08-08 Partial
Browser & Computer UseOperates on email, collaboration and identity telemetry through APIs; URL rewriting routes clicks through analysis but that is traffic interception rather than an agent operating a browser. No computer use capability is documented. Abnormal AI product documentation 2026-08-08 Unable to verify

The Agentic Index coverage score grades every vendor Full, Partial or Unable to verify against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Pricing

Contact sales

per user or per mailbox, not disclosed

Included quota

Not disclosed.

What is public

Nothing on price. Everything in this record is third party reported and flagged.

Billing mechanics

Not publicly disclosed. Direct enterprise sales requiring a quote, with reported minimum seat counts and volume thresholds on enterprise contracts.

Cost watchouts

**THE AGENTS ARE THE UPSELL. Third party analysis reports AI Security Agents may sit behind add on licences, which means the capability the product is marketed on may be a separate line from the platform. Establish explicitly which agents are included before comparing a quote to a rival.** Minimum seat counts and volume thresholds are also reported on enterprise contracts. The offsetting argument, also third party, is that behavioural AI may reduce total cost by decreasing SOC headcount - a real but hard to verify claim that should not be accepted without the customer's own baseline.

Variable cost rationale

Graded medium rather than high because the licence base is per user or per mailbox, which is a stable and forecastable quantity that does not grow with agent activity, and Abnormal runs its own models so there is no pass through token consumption or agent consumption unit. The offsetting risk is the reported add on licensing for the AI agents themselves, which can move the real cost materially away from the platform quote.

Additional watchouts

Do not assume the named agents are included. Ask which of AI Security Mailbox, AI Phishing Coach and AI Data Analyst are in the base licence before treating a quote as comparable.

Overage / add-ons

Not disclosed.

Sales call required

Yes, required for paid access

Free / trial

Demo on request

Commercial notes

Private company, CNBC Disruptor 50 for a third consecutive year and a Gartner Magic Quadrant Leader for Email Security Platforms. **CATEGORY CONTEXT WORTH KEEPING: the email security market was valued at roughly 5.17 billion USD in 2024 and is projected to reach 13.22 billion by 2032, a CAGR near 12.5 percent. Competitors Mimecast and Proofpoint are equally opaque on price; IRONSCALES is cited as the transparent per user alternative for smaller teams.**

Key ambiguities

Which of the three named agents are included in a base platform licence and which require add ons. That single question determines whether a quote is comparable to any competitor, and it is not answerable from public sources.

Missing data

All pricing, and specifically which AI agents are bundled versus licensed separately.

Agentic Index verified 2026-08-08

Alternatives to Abnormal AI

The closest documented capability profiles to Abnormal AI among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Darktrace9.0 / 14Matches Abnormal AI across all 14 documented capabilities
  • Vanta8.5 / 14A lighter documented profile than Abnormal AI
  • Arctic Wolf9.0 / 14Fuller documented coverage on Human Oversight & Guardrails
  • Crogl10.0 / 14Fuller documented coverage on Human Oversight & Guardrails and Deployment & Data Residency
  • Magnitude9.0 / 14Fuller documented coverage on Security, Identity & Governance
  • Mycroft9.0 / 14Fuller documented coverage on Security, Identity & Governance

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.