IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
Abnormal AI expands security with three new products

Abnormal AI expands security with three new products

Wed, 29th Jul 2026 (Yesterday)
Mark Tarre
MARK TARRE News Chief

Abnormal AI has expanded its security platform with three new products: Identity Threat Protection, AI Governance and Infiltration Prevention. The move extends its technology beyond email security into identity and AI security.

The new products apply the company's behavioural models to different parts of the modern identity attack surface. Abnormal AI also introduced an AI App Store inside its portal, designed to let customers activate products with a single click.

Abnormal AI has built its business around analysing user and system behaviour to identify activity that differs from normal patterns. The latest rollout extends that approach into areas where security teams are under pressure from the spread of AI tools, the growth of machine identities such as service accounts and software agents, and the risk of malicious actors gaining trusted access.

More than 4,500 organisations use the platform, including over 25% of the Fortune 500. With the expansion, Abnormal AI is seeking a larger role in corporate identity and access security as cyber attackers increasingly rely on valid credentials, compromised accounts and social engineering rather than more obvious break-in methods.

Three products

Identity Threat Protection targets attacks that occur after a user or system has already passed authentication. Abnormal AI said it highlights weaknesses such as accounts without multi-factor authentication and service accounts with broad privileges, then links those exposures to attack methods listed in a threat library.

The product also draws on identity, software-as-a-service and email signals to detect signs of compromise inside active sessions. Another feature is designed to protect IT help desks by challenging suspicious requests for password resets or multi-factor authentication resets, a common route for attackers seeking to take over accounts.

AI Governance focuses on oversight of AI tools, AI agents and related employee activity across an organisation. Abnormal AI said it is intended to give security teams visibility into both approved and unapproved tools as staff adopt AI services faster than internal controls can keep pace.

It is designed to discover AI tools across the environment, establish a baseline for how each tool or agent behaves, and flag unusual activity. The company gave the example of an agent gaining access beyond its expected role, with customer-set policies then applied automatically when activity appears risky.

Infiltration Prevention addresses a different part of the risk chain by focusing on hiring and onboarding. Abnormal AI said it integrates with applicant tracking systems including Greenhouse and Workday to identify patterns associated with fabricated or fraudulent job candidates before access is granted to enterprise systems.

Those patterns can include VoIP burner numbers, locations hidden behind VPNs and repeated links to the same actor in its threat intelligence. The tool is also designed to identify broader campaigns rather than isolated suspicious applicants, and to assemble evidence briefs for review by security teams.

Market pressure

The expansion reflects a broader shift in cybersecurity spending towards tools that monitor behaviour after login rather than relying only on perimeter controls or credential checks. As companies add more cloud software, automation and AI assistants, the number of non-human identities often exceeds the number of employees, creating a more complex access environment for defenders.

Many traditional controls are strongest at the point of authentication but offer less visibility once an account is accepted as legitimate. That gap has become more important as attackers use phishing, token theft, OAuth abuse and impersonation techniques that allow them to operate inside trusted sessions.

Abnormal AI argues that the common thread in these threats is behaviour rather than the specific technology involved. "Abnormal envisioned a future where behavioral AI could solve critical problems facing enterprises around the world," said Evan Reiser, Chief Executive Officer and Co-founder of Abnormal AI.

"Our customers are facing key challenges today: attackers who blend in instead of breaking in, AI adoption outpacing governance, and nation-state actors engineering fake identities to become insiders. Every one of those risks comes down to understanding identity and behavior. That's the lens that Abnormal brings to these problems," Reiser said.

The new products all sit on the same underlying model used in the company's existing business. That gives Abnormal AI a way to broaden its addressable market while keeping a single behavioural approach across email, identity, AI systems and employee onboarding.

Reiser framed the launch around the difficulty of spotting threats that appear legitimate on the surface. "The threats that matter most don't look like threats at all," he said.

"A trusted identity moves through a valid session like a real employee. A helpful AI agent codes its way into a sensitive database. A nation-state actor uses a synthetic persona to apply for a job. Each looks different, but each gives itself away the same way, through abnormal behavior," Reiser said.