Abnormal AI
Also known as: Abnormal AI, Abnormal Security, AI Security Mailbox, AI Phishing Coach, AI Data Analyst, Attune, Attune 1.0
Behavioural AI email security with three named autonomous agents: a mailbox that triages user reports and explains itself to employees, a coach that trains at the point of error, and an analyst queried by email.
Abnormal AI, formerly Abnormal Security, built its business on a single architectural bet stated plainly in its own words: understanding normal behaviour is a more durable defence than cataloguing known threats, particularly against AI generated attacks designed to look different every time. In March 2026 it shipped Attune 1.0, its own behavioural AI foundation model.
The agent layer is named and distinct rather than a single assistant. AI Security Mailbox autonomously triages user reported emails around the clock, sorting them into malicious, spam, safe or phishing simulation, then replies to the employee with a detailed explanation and answers their follow up questions. AI Phishing Coach delivers a personalised micro lesson the moment someone interacts with a suspicious message, replacing annual training with instruction at the point of error. AI Data Analyst is queried by email in natural language and returns executive ready reports covering funnel metrics, attack vectors and detection performance.
Underneath sits a behavioural detection engine combining large language models with graph intelligence, evaluating sender history, content anomalies and relationship signals across tens of thousands of signals, plus identity baselines that surface account takeover. URL rewriting routes every click through real time analysis and revokes access if a page weaponises after delivery. Deployment is API native, connecting to Microsoft 365 or Google Workspace in minutes.
The posture worth noting is autonomy. An independent review observes that autonomous blocking by default means less granular manual control for security teams, which places Abnormal at the autonomy forward end of a market where most large vendors are arguing the opposite.
Vendor details
Canonical URL
https://abnormal.ai
Category
Security / SOC agent
Subcategory
Behavioural AI email and collaboration security
Funding status
Private. Named to the CNBC Disruptor 50 for a third consecutive year in May 2026. Recognised as a Leader in the Gartner Magic Quadrant for Email Security Platforms.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
API native rather than inline: one click API connections to Microsoft 365 and Google Workspace deploy in minutes without infrastructure changes or mail flow disruption. Behavioural analysis extends beyond email across Slack, Teams and Zoom as a unified surface, and the platform reaches into identity threat protection and monitoring of third party AI usage.
In practice
An employee reports a suspicious email and receives an explained verdict within minutes rather than waiting for an analyst to reach the queue the next working day.
Someone clicks a link that was clean at delivery and weaponised afterwards, and access is revoked at click time rather than discovered later.
A security lead emails a natural language question to the AI Data Analyst and receives an executive ready report on attack vectors and detection performance without building it by hand.
Sources & related URLs
Agentic Index coverage score
9.0 / 14 capabilities · 64%
| Integrations & Tool CallingAPI NATIVE rather than inline: one click API connections to Microsoft 365 and Google Workspace deploy in minutes with no infrastructure changes and no mail flow disruption, with unified behavioural analysis extending across Slack, Teams and Zoom, plus identity threat protection and monitoring of third party AI usage. Abnormal AI platform and trends pages 2026-08-08 | Full |
|---|---|
| Workflow OrchestrationShips an INTEGRATED MULTI AGENT ARCHITECTURE rather than isolated point agents, with AI Security Mailbox, AI Phishing Coach and AI Data Analyst coordinating across triage, remediation and user education, and the vendor explicitly argues for integrated agent architectures over isolated task specific agents. Abnormal AI autonomous agents and market pages 2026-08-08 | Full |
| Knowledge Grounding & RAGATTUNE 1.0, its own behavioural AI FOUNDATION MODEL shipped March 2026, sits under a detection engine combining large language models with GRAPH INTELLIGENCE, evaluating sender history, content anomalies and relationship signals across tens of thousands of signals plus identity baselines. Grounded in the customer's own learned normal rather than a global threat catalogue. Abnormal AI product pages and independent review 2026-08-08 | Full |
| Human Oversight & GuardrailsTHE INTERESTING GRADE ON THIS RECORD. Agents explain every verdict to the employee in detail and answer follow up questions, which is transparency, but an independent review states that AUTONOMOUS BLOCKING BY DEFAULT MEANS LESS GRANULAR MANUAL CONTROL for security teams. That is a deliberate autonomy forward design choice rather than an omission, and it places Abnormal opposite palo-alto in the same lane. Abnormal AI product pages and independent review 2026-08-08 | Partial |
| Security, Identity & GovernanceNOT RETRIEVED AND LIKELY AN UNDERGRADE - FLAGGED FOR CORRECTION. Abnormal is a Gartner Magic Quadrant Leader selling to large regulated enterprises, so attestations certainly exist, but none were retrieved in this pass. EIGHTH instance of the Sec paradox. Check abnormal.ai trust or compliance pages and correct. Abnormal AI public sources 2026-08-08 | Partial |
| Observability & AuditabilityAI Data Analyst generates executive ready reports on demand covering funnel metrics, top attack vectors and detection performance, while AI Security Mailbox returns a detailed written explanation of every verdict to the reporting employee - so reasoning is exposed to both the security team and the end user, which is unusual. Abnormal AI trends and autonomous agents pages 2026-08-08 | Full |
| Memory & State PersistenceBehavioural baselines and identity profiles persist per organisation and adapt continuously without manual tuning, which is durable learned state, but it is a DETECTION MODEL rather than agent memory and is graded the same way as darktrace. No conversation or task context persistence is documented. Abnormal AI platform description 2026-08-08 | Partial |
| Deployment & Data ResidencyAPI native SaaS only, connecting to Microsoft 365 or Google Workspace without infrastructure changes - which is a genuine deployment advantage in speed but offers no self hosting, and no regional residency matrix was retrieved in this pass. Abnormal AI platform description 2026-08-08 | Partial |
| Prebuilt Agents, Templates & PacksThree NAMED prebuilt agents ship ready to run - AI Security Mailbox, AI Phishing Coach and AI Data Analyst - alongside packaged inbound email security, account takeover protection and identity threat protection, all activated through a one click connection rather than assembled by the customer. Abnormal AI autonomous agents page and independent review 2026-08-08 | Full |
| Triggers & Channel CoverageAI Security Mailbox triages user reported email 24/7 rather than in business hours, AI Phishing Coach fires INSTANTLY after a suspicious email interaction, URL rewriting evaluates at click time rather than delivery time, and AI Data Analyst is invoked BY EMAIL in natural language - an unusual agent interface worth noting. Abnormal AI autonomous agents and trends pages 2026-08-08 | Full |
| Model Flexibility & RoutingRuns its own ATTUNE 1.0 behavioural foundation model as the core intellectual property alongside large language models inside the detection engine; no model selection, provider choice or bring your own model capability exists or would be architecturally coherent. Honest absence by design, same reasoning as darktrace. Abnormal AI product materials 2026-08-08 | Unable to verify |
| APIs, SDKs & MCP ExtensibilityThe platform is API native by architecture and integrates across email, collaboration and identity surfaces, which implies a substantial programmable surface, but no public API reference, SDK family, developer portal or MCP support was retrieved in this pass. Abnormal AI public sources 2026-08-08 | Partial |
| Testing, Debugging & OptimizationDetection performance is reported as a first class metric through AI Data Analyst, and the platform distinguishes phishing simulations from real threats during triage which is a form of continuous calibration, but no customer facing evaluation harness, simulation mode or regression testing of agent behaviour was documented. Abnormal AI trends page 2026-08-08 | Partial |
| Browser & Computer UseOperates on email, collaboration and identity telemetry through APIs; URL rewriting routes clicks through analysis but that is traffic interception rather than an agent operating a browser. No computer use capability is documented. Abnormal AI product documentation 2026-08-08 | Unable to verify |
The Agentic Index coverage score grades every vendor Full, Partial or Unable to verify against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Contact sales
per user or per mailbox, not disclosed
Included quota
Not disclosed.
What is public
Nothing on price. Everything in this record is third party reported and flagged.
Billing mechanics
Not publicly disclosed. Direct enterprise sales requiring a quote, with reported minimum seat counts and volume thresholds on enterprise contracts.
Cost watchouts
**THE AGENTS ARE THE UPSELL. Third party analysis reports AI Security Agents may sit behind add on licences, which means the capability the product is marketed on may be a separate line from the platform. Establish explicitly which agents are included before comparing a quote to a rival.** Minimum seat counts and volume thresholds are also reported on enterprise contracts. The offsetting argument, also third party, is that behavioural AI may reduce total cost by decreasing SOC headcount - a real but hard to verify claim that should not be accepted without the customer's own baseline.
Variable cost rationale
Graded medium rather than high because the licence base is per user or per mailbox, which is a stable and forecastable quantity that does not grow with agent activity, and Abnormal runs its own models so there is no pass through token consumption or agent consumption unit. The offsetting risk is the reported add on licensing for the AI agents themselves, which can move the real cost materially away from the platform quote.
Additional watchouts
Do not assume the named agents are included. Ask which of AI Security Mailbox, AI Phishing Coach and AI Data Analyst are in the base licence before treating a quote as comparable.
Overage / add-ons
Not disclosed.
Sales call required
Yes, required for paid access
Free / trial
Demo on request
Commercial notes
Private company, CNBC Disruptor 50 for a third consecutive year and a Gartner Magic Quadrant Leader for Email Security Platforms. **CATEGORY CONTEXT WORTH KEEPING: the email security market was valued at roughly 5.17 billion USD in 2024 and is projected to reach 13.22 billion by 2032, a CAGR near 12.5 percent. Competitors Mimecast and Proofpoint are equally opaque on price; IRONSCALES is cited as the transparent per user alternative for smaller teams.**
Key ambiguities
Which of the three named agents are included in a base platform licence and which require add ons. That single question determines whether a quote is comparable to any competitor, and it is not answerable from public sources.
Missing data
All pricing, and specifically which AI agents are bundled versus licensed separately.
Related vendors
- 7AI — Swarming agentic SOC from the Cybereason founders: sixty plus domain…
- AirMDR — AI-native MDR built around a Virtual Analyst that triages 95% of…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Bionic SOC: a human-AI collaboration platform that automates triage,…
- Anvilogic — Agentic security operations platform that decouples detection from…
- Arctic Wolf — MDR incumbent rebuilt around agents: the Aurora Agentic SOC…
Alternatives to Abnormal AI
The closest documented capability profiles to Abnormal AI among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Darktrace9.0 / 14Matches Abnormal AI across all 14 documented capabilities
- Vanta8.5 / 14A lighter documented profile than Abnormal AI
- Arctic Wolf9.0 / 14Fuller documented coverage on Human Oversight & Guardrails
- Crogl10.0 / 14Fuller documented coverage on Human Oversight & Guardrails and Deployment & Data Residency
- Magnitude9.0 / 14Fuller documented coverage on Security, Identity & Governance
- Mycroft9.0 / 14Fuller documented coverage on Security, Identity & Governance
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded