Abnormal AI
Also known as: Abnormal Security, AI Security Mailbox, AI Phishing Coach, Attune
Behavioral AI email security with three named autonomous agents: a mailbox that triages user reports and explains itself to employees, a coach that trains at the point of error, and an analyst queried by email.
Abnormal AI, formerly Abnormal Security, built its business on a single architectural bet stated plainly in its own words: understanding normal behavior is a more durable defense than cataloging known threats, particularly against AI generated attacks designed to look different every time. In March 2026 it shipped Attune 1.0, its own behavioral AI foundation model.
The agent layer is named and distinct rather than a single assistant. AI Security Mailbox autonomously triages user reported emails around the clock, sorting them into malicious, spam, safe or phishing simulation, then replies to the employee with a detailed explanation and answers their follow up questions. AI Phishing Coach delivers a personalized micro lesson the moment someone interacts with a suspicious message, replacing annual training with instruction at the point of error. AI Data Analyst is queried by email in natural language and returns executive ready reports covering funnel metrics, attack vectors and detection performance.
Underneath sits a behavioral detection engine combining large language models with graph intelligence, evaluating sender history, content anomalies and relationship signals across tens of thousands of signals, plus identity baselines that surface account takeover. URL rewriting routes every click through real time analysis and revokes access if a page weaponizes after delivery. Deployment is API native, connecting to Microsoft 365 or Google Workspace in minutes.
The posture worth noting is autonomy: blocking and campaign wide remediation run autonomously by default, and security teams shape the agents through guardrails, policies and a preview mode rather than approving each action.
Vendor details
Canonical URL
https://abnormal.ai
Category
Security / SOC agent
Subcategory
Behavioral AI email and collaboration security
Funding status
Private. Over 4,500 customers including more than 25 percent of the Fortune 500. Named to the CNBC Disruptor 50 for a third consecutive year in May 2026.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
API native rather than inline: one click API connections to Microsoft 365 and Google Workspace deploy in minutes without infrastructure changes or mail flow disruption. Behavioral analysis extends beyond email across Slack, Teams and Zoom as a unified surface, and the platform reaches into identity threat protection and monitoring of third party AI usage.
In practice
An employee reports a suspicious email and receives an explained verdict within minutes rather than waiting for an analyst to reach the queue the next working day.
Someone clicks a link that was clean at delivery and weaponised afterwards, and access is revoked at click time rather than discovered later.
A security lead emails a natural language question to the AI Data Analyst and receives an executive ready report on attack vectors and detection performance without building it by hand.
Sources & related URLs
Research sources
Agentic Index coverage score
9.0 / 14 capabilities · 64%
| Integrations & Tool Calling | Full |
|---|---|
|
Fourteen named integrations span six classes: SIEM (Microsoft Sentinel, Splunk Enterprise Security, Rapid7 InsightConnect, QRadar), SOAR (Splunk SOAR, Cortex XSOAR, Revelstoke), IAM (Entra ID, Okta), ITSM (ServiceNow), SOC platform (Hunters, Google Chronicle), XDR (CrowdStrike Falcon Identity Protection) and Torq automation, all API based with no MX changes, alongside native Microsoft 365, Google Workspace, Slack and Teams connections. Sourceabnormal.ai/platform/technology-integrationsread 2026-09-29 |
|
| Workflow Orchestration | Full |
|
Named agents coordinate a multi step lifecycle rather than running as isolated point tools: AI Security Mailbox triages a reported message, classifies it, replies to the reporter, then autonomously locates and removes every related message from the same campaign across the tenant, with AI Phishing Coach and AI Data Analyst operating on the same platform. Sourceabnormal.ai/platform/ai-security-mailboxread 2026-09-29 |
|
| Knowledge Grounding & RAG | Full |
|
Attune, its own behavioral AI foundation model, underpins a detection engine that learns each organization's normal communication patterns from sender history, content anomalies and relationship signals, with identity baselines for account takeover; the product privacy guide confirms a federated model in which vendor and threat intelligence feeds are built from attacker signals de-identified before reuse. Sourceabnormal.ai/platform/attuneread 2026-09-29 |
|
| Human Oversight & Guardrails | Partial |
|
Security teams configure response tone, guardrails and policies through a conversational analyst and can preview exactly how it will interact with employees before it goes live, and the product documents handling for low confidence verdicts; but blocking and campaign wide remediation run autonomously by default and no per action approval gate is documented. Sourceabnormal.ai/platform/ai-security-mailboxread 2026-09-29 |
|
| Security, Identity & Governance | Full |
|
Abnormal publishes both attestations and customer-facing access controls. The trust center documents SOC 2 Type II audited annually and ISO 27001:2022, ISO 27701:2019 and ISO 42001:2023 certified by named auditor A-LIGN, alongside FedRAMP Moderate, GovRAMP, TX-RAMP, CMMC and CJIS, with a US penetration test report, CAIQ and SIG on the Security Hub. The Security Hub's Product Security section states the portal supports single sign-on via SAML (so customers can enforce their own MFA), that portal access is managed by customers who delegate it by role on least privilege, and that the portal tracks user activity with audit reports downloadable as CSV. Sourcesecurity.abnormal.ai and abnormal.ai/trust-centerread 2026-09-29 |
|
| Observability & Auditability | Partial |
|
AI Data Analyst returns reports on funnel metrics, attack vectors and detection performance, reported messages land in a normalized SOC ready queue exportable to SIEM and SOAR, and every reporter receives a conversational policy aligned explanation of the verdict. No per agent execution trace or audit log of agent actions is documented. Sourceabnormal.ai/platform/ai-security-mailboxread 2026-09-29 |
|
| Memory & State Persistence | Partial |
|
Per organization behavioral baselines and identity profiles persist and adapt continuously without manual tuning, and employees can ask follow up questions within a reporting thread, but this is a detection model plus conversation context rather than a documented agent memory or task state layer. Sourceabnormal.ai/platform/attuneread 2026-09-29 |
|
| Deployment & Data Residency | Partial |
|
The product privacy guide states customer data is transferred to infrastructure located in the United States or the EU depending on deployment, a documented region choice, and FedRAMP Moderate, GovRAMP, TX-RAMP and CJIS authorizations imply a separate US government environment; delivery is API native SaaS only with no self host, on premises, or customer VPC option. Sourceassets.contentstack.io/v3/assets/blt3a076cfd9753fa1f/bltcdc7e053ffc3f681/6a1f224cd0c4164e5bc5577d/abnormal-ai-product-privacy-guide.pdfread 2026-09-29 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Named prebuilt agents ship ready to run, AI Security Mailbox, AI Phishing Coach and AI Data Analyst, alongside packaged modules for inbound email security, account takeover protection, identity threat protection, posture management, messaging security, misdirected email, email DLP rules and AI governance, all activated through an API connection rather than assembled by the customer. Sourceabnormal.ai/platform/overviewread 2026-09-29 |
|
| Triggers & Channel Coverage | Full |
|
Invocation spans employee reports arriving through existing phishing report buttons, abuse mailboxes and Google Workspace alerts into one normalized queue, triaged around the clock; AI Phishing Coach fires on suspicious interaction, URL rewriting evaluates at click time rather than delivery, and behavioral coverage extends across Slack, Teams and Zoom. Sourceabnormal.ai/platform/ai-security-mailboxread 2026-09-29 |
|
| Model Flexibility & Routing | Not documented |
|
Runs its own Attune behavioral foundation model as core intellectual property alongside undisclosed large language models inside the detection engine; no provider is named, no routing is described, and no model selection or bring your own model capability exists. Sourceabnormal.ai/platform/attuneread 2026-09-29 |
|
| APIs, SDKs & MCP Extensibility | Partial |
|
A Platform REST API at api.abnormalplatform.com exposes threats, cases and abuse mailbox endpoints and is consumed by Splunk SOAR, Cortex XSOAR, Torq, Rapid7 and other third party integrations, but the API reference and credentials are provisioned through the customer portal rather than published, and no SDK, MCP server or native outbound webhooks are documented. Sourceabnormal.ai/platform/technology-integrationsread 2026-09-29 |
|
| Testing, Debugging & Optimization | Partial |
|
Security teams can preview exactly how the agent will interact with employees before it goes live, the platform distinguishes phishing simulations from real threats during triage, and detection performance is reported through AI Data Analyst; no customer facing evaluation harness, regression testing or agent scoring product is documented. Sourceabnormal.ai/platform/ai-security-mailboxread 2026-09-29 |
|
| Browser & Computer Use | Not documented |
|
Operates entirely through provider APIs into Microsoft 365, Google Workspace and the security stack with no agents and no MX changes; URL rewriting routes clicks through real time analysis, which is traffic interception rather than an agent operating a browser, and no computer use capability is documented. Sourceabnormal.ai/platform/technology-integrationsread 2026-09-29 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
AIDEN, a new AI detection engineer from Abnormal, takes misjudged emails a customer has confirmed, investigates them like an analyst, builds a detector for that customer, tests it on their own traffic and deploys it once it clears Abnormal's accuracy bar. A dashboard traces every deployed detector to the messages it caught and the false positives it suppressed, and it is live for all US and EU commercial customers.
Bears on: Agent capability
View sourceAbnormal AI launched AI Cloud Security, extending its behavioral AI engine to detect risky or malicious AI agent behavior in cloud environments. The new product utilizes OpenAI Daybreak models to power real-time anomaly detection and autonomous investigation.
Bears on: Security / enterprise
View sourcePricing
Contact sales
per user or per mailbox, not disclosed
Included quota
Not disclosed.
What is public
Nothing on price is published by the vendor; the pricing details here come from third party reporting.
Billing mechanics
Not publicly disclosed. Direct enterprise sales requiring a quote, with reported minimum seat counts and volume thresholds on enterprise contracts.
Cost watchouts
**THE AGENTS ARE THE UPSELL. Third party analysis reports AI Security Agents may sit behind add on licenses, which means the capability the product is marketed on may be a separate line from the platform. Establish explicitly which agents are included before comparing a quote to a rival.** Minimum seat counts and volume thresholds are also reported on enterprise contracts. The offsetting argument, also third party, is that behavioral AI may reduce total cost by decreasing SOC headcount - a real but hard to verify claim that should not be accepted without the customer's own baseline.
Variable cost rationale
Graded medium rather than high because the license base is per user or per mailbox, which is a stable and forecastable quantity that does not grow with agent activity, and Abnormal runs its own models so there is no pass through token consumption or agent consumption unit. The offsetting risk is the reported add on licensing for the AI agents themselves, which can move the real cost materially away from the platform quote.
Additional watchouts
Do not assume the named agents are included. Ask which of AI Security Mailbox, AI Phishing Coach and AI Data Analyst are in the base license before treating a quote as comparable.
Overage / add-ons
Not disclosed.
Sales call required
Yes, required for paid access
Free / trial
Demo on request
Commercial notes
Private company, named to the CNBC Disruptor 50 for a third consecutive year.
Key ambiguities
Which of the three named agents are included in a base platform license and which require add ons. That question decides what a quote actually covers, and public sources do not answer it.
Missing data
All pricing, and specifically which AI agents are bundled versus licensed separately.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
- Arctic Wolf — Managed detection and response rebuilt around agents: the Aurora…
Alternatives to Abnormal AI
The closest documented capability profiles to Abnormal AI among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Anvilogic8.5 / 14Fuller documented coverage on Human Oversight & Guardrails
- Magnitude8.5 / 14Fuller documented coverage on Observability & Auditability
- Snyk11.0 / 14Adds documented Model Flexibility & Routing
- Tuskira10.0 / 14Adds documented Model Flexibility & Routing
- 7AI8.5 / 14Fuller documented coverage on Human Oversight & Guardrails and Observability & Auditability
- Airrived8.5 / 14Adds documented Model Flexibility & Routing
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded