Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • AI

Abnormal AI Launches Attune 1.0 Behavioral Foundation Model


Abnormal AI Launches Attune 1.0 Behavioral Foundation Model
  • by: Source Logo
  • |
  • March 18, 2026

Abnormal AI has launched Attune 1.0, a behavioral foundation model designed specifically to counter the era of AI-driven, highly personalized attacks that weaponize trusted communication patterns. Trained on more than one billion derived behavioral signals, Attune unifies identity, context, and content analysis into a single multimodal architecture, powering approximately 85% of detections across the Abnormal Behavior Platform.

Quick Intel

  • Attune 1.0 delivers 50% higher precision and detects roughly 150,000 additional attack campaigns weekly compared to prior systems by learning jointly across behavioral modalities.
  • Identifies and blocks novel threats early, including a Microsoft Teams OAuth phishing campaign two months before public disclosure.
  • Establishes a shared intelligence layer that strengthens email, identity, and account takeover protection while reducing false positives platform-wide.
  • Enables Detection 360 Insights (GA) for transparent behavioral reasoning behind every AI-flagged message and Custom AI Models (early access) for environment-specific fine-tuning via natural language.
  • Enhances human risk management with Phishing Risk Scoring (GA), BEC/VEC simulations using real relationship graph data, and personalized AI Phishing Coach for targeted employee training.
  • Shifts from static rules and threat feeds to autonomous, adaptive detection that assumes every attack is novel and focuses on deviations from learned normal organizational behavior.

Attackers increasingly use AI to craft convincing, target-specific campaigns that imitate legitimate communication, rendering traditional rule-based and static-intelligence tools ineffective. As every interaction becomes a potential vector, defenders must baseline normal behavior at scale and detect anomalies in real time.

Attune 1.0 addresses this by integrating eight years of Abnormal’s behavioral expertise into a unified model. Unlike siloed approaches that treat identity, behavior, and content separately, Attune learns these signals jointly, revealing hidden attacker patterns through cross-modal reinforcement and contradiction analysis.

Platform-Wide Impact and Efficacy Gains

Attune already drives the majority of malicious detections across the Abnormal Behavior Platform, delivering higher accuracy, fewer false positives, and broader coverage against lateral attacks throughout the employee lifecycle. This shared foundation enhances protection across cloud email, identity threats, and account compromise scenarios.

Enhanced Visibility, Control, and Human Risk Tools

Detection 360 Insights provides full transparency into AI decision-making, allowing analysts to understand behavioral reasoning for every flag. Custom AI Models empower security teams to define and influence detection logic using natural language tailored to their unique environment.

For human-centric security, AI Phishing Coach evolves with Attune’s improvements, replacing generic training with personalized coaching derived from real interactions. New Phishing Risk Scoring offers a dynamic readiness metric, while BEC and VEC simulations leverage the Abnormal relationship graph to replicate authentic manager, colleague, and vendor scenarios.

"Attackers are leveraging AI to imitate trusted behavior so convincingly that static rules and threat feeds struggle in the era of AI-driven attacks," said Evan Reiser, CEO and Co-Founder of Abnormal AI. "Attune 1.0 is how we close that gap—with a behavioral foundation model that understands normal organizational communication patterns. It gives customers a single intelligence layer that understands known good behavior, catches what isn’t, and strengthens every product we ship as part of the Abnormal Behavior Platform.”

 

About Abnormal AI

Abnormal AI is the leading AI-native human behavior security platform, leveraging machine learning to stop sophisticated attacks and detect compromised accounts across email and connected applications. Our anomaly detection engine leverages identity and context to analyze normal behavior and assess the risk of every cloud email event—detecting and stopping sophisticated, socially-engineered attacks that target your organization's most valuable cybersecurity asset: your people.

  • AI AgentsCybersecurityThreat DetectionEmail Security
News Disclaimer
  • Share