AegisAI launches Proteus, the first foundational model for email security that investigates every email like a security analyst, before it reaches the inbox
NEW YORK, Oct. 8, 2026
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
AegisAI launches Proteus, the first foundational model for email security that investigates every email like a security analyst, before it reaches the inbox
PR Newswire
NEW YORK, Oct. 8, 2026
AI-generated attacks now change faster than rule-based and behavioral systems can update. Catching them takes purpose-built AI that investigates every message without relying on known patterns. In a benchmark of 3,020 real phishing attacks, Proteus caught more than 99% and missed roughly 30 times fewer attacks than leading general-purpose AI models, while returning verdicts up to 7.2 times faster.
NEW YORK, Oct. 8, 2026 /PRNewswire/ — AegisAI has released Proteus, the foundational model from the AegisAI Lab that does a full SOC-style investigation of each email. Alongside the launch, the company published benchmark results showing Proteus identified more than 99% of 3,020 human-reviewed phishing attacks, compared with 81% for a leading closed-source general-purpose model and 80% for a widely used open-weight model.

Rather than matching messages against rules or behavioral patterns, Proteus investigates every email that hits your inbox. It checks who sent it, where its links lead, and what it’s really asking for. No prior behavior or pattern matching is required – enabling Proteus to catch novel attacks.
The launch comes as generative AI makes tailored, convincing phishing cheap to produce at scale, eroding the advantage defenders once had from seeing an attack once and blocking it everywhere else.
Beyond pattern matching: Proteus investigates email risk
While traditional email security relies on historical attack signatures, Proteus acts as an autonomous security analyst auditing the authenticity and contextual integrity of every incoming message.
Every phishing email depends on assertions about who sent it, whether a relationship already exists, where a link goes and what business process it belongs to. Proteus verifies those assertions using signals outside the attacker’s control, such as a link’s true destination, the correspondence history between sender and recipient, routing and header data, and how the sending infrastructure has behaved elsewhere. Because none of these checks relies on having seen the attack before, Proteus can catch attacks that are brand new.
Security analysts have long confirmed attacks this way, but investigating by hand doesn’t scale beyond a few messages a day. As a result, most security stacks score everything on similarity and investigate only the flagged messages, often after delivery. AegisAI said Proteus closes that gap by investigating every message as it arrives.
The team first saw the problem while at Google, where the variety of attacks arriving each day was outgrowing what detection rules and behavioral models could cover. Over the past year, AegisAI moved from prompting frontier models to fine-tuning and then training open-weight models. Each approach improved results, but none was specialized enough to counter attackers who also use generative AI. That led the lab to build its own model from scratch.
Proteus doesn’t read an email as raw text. It processes each one as a structured object that combines the message content, headers, sender and recipient history, sanitized link and attachment data, and threat intelligence, with a custom tokenizer built around it. According to AegisAI, this cuts token costs and improves accuracy.
Attacks written by machines
AegisAI said generative AI has removed the economics that once forced attackers to reuse campaigns. “What was once the purview of nation states is now freely available to the cybercriminal community at large,” said Cy Khormaee, Founder and CEO of AegisAI. Over 2025, AI-generated spear phishing rose from under 1% to more than a fifth of the phishing the company tracked. At its current pace, it will make up most attacks by 2028.
These messages also work. A controlled study found that fully automated, AI-written spear phishing achieved a 54% click-through rate. That matched messages written by human experts and was more than four times the 12% rate for generic phishing. With personalized attacks now nearly free to produce, each one arrives as something defenders have never seen.
AegisAI pointed to a recent customer incident. Attackers used a malicious OAuth grant to take over a Google Workspace account, then used it to send bid invitations to the customer’s suppliers. Because the messages really did come from the compromised account, every one passed SPF, DKIM and DMARC checks. AegisAI flagged the first message 89 minutes before the account-takeover alert went off.
According to AegisAI, the three families of methods that make up production email security each fail on cases like this for structural reasons. Rules and signatures only recognize attacks already seen. Anomaly detection learns a sender’s normal behavior, so a hijacked mailbox writes from inside its own baseline and a first contact has no baseline at all. Supervised classifiers depend on hand-built features that go stale as attacks change.
The company also cautioned against relying on general-purpose frontier models for email defense. These models are built to follow the instructions in front of them, a tendency phishing emails are designed to exploit. Publicly available models can also be tested privately and repeatedly by attackers, who can refine a message until it slips through.
Benchmark results
The evaluation used 3,020 human-verified phishing attacks from a single week of AegisAI’s production traffic, none of which appeared in Proteus’s training data. All three models scored the same set under the same conditions. Any result other than a phishing verdict, including a spam label, counted as a miss.
Proteus identified more than 99% of the attacks. The leading closed-source model missed 565 and the open-weight model missed 604, around 30 times as many as Proteus.
Proteus’s lead was largest on attacks designed to look legitimate. For credential theft, it follows each link to its real destination, which is where the deception is. For business email compromise, it looks at the relationship between the two parties: whether they’ve written to each other before and whether the request fits that history. Proteus also catches reconnaissance emails, which have no links or attachments and just try to get a reply, so traditional content filters have nothing to analyze.
Speed is critical because email security runs inline, holding each message until a verdict is reached. Proteus was 7.2 times faster than the closed-source model at the median and 26 times faster on the slowest 5% of verdicts. AegisAI credited the gains to a model built for a three-way decision, a single inference pass without sampling, and self-hosted infrastructure that gives it control over worst-case delays.
An ablation test isolated the value of investigation: the same model supplied with evidence at inference identified 8.4% more phishing than without it. AegisAI also calibrates Proteus by examining internal activations against ground-truth outcomes, placing 82% of scored messages in a usable confidence band with an expected calibration error of 0.037 before any post-hoc fitting.
The benchmark counts only missed detections. AegisAI said it will publish false-positive data once Proteus has more time in production. The general-purpose models received only the message and a plain classification instruction, reflecting out-of-the-box use rather than their optimized ceiling. The sample also covers one week of traffic from AegisAI’s own customers.
Continuous release and the defender’s window
Since attackers adapt and detection weakens over time, AegisAI said how it updates Proteus matters as much as launch-day results. Proteus is retrained on an ongoing basis. Each new version must pass adversarial testing across nine attack families, then run side by side with the current version on live traffic. It replaces the current version only if it does better.
The company placed the release within a wider industry argument. OpenAI has warned of a “defender’s window,” a limited period when defenders have the same AI capabilities as attackers, which closes as attackers scale up their use of AI. Anthropic has added cybersecurity safeguards to its most capable models and offers vetted security teams tiered access through its Cyber Verification Program.
In AegisAI’s view, a capable general-purpose model is a starting point for modern defense, not a defense on its own, and models built for a specialized adversarial problem will beat general ones at it. Email, the company said, is still the most common way attackers break into enterprises, and it’s the one channel every employee has to leave open.
Proteus is the first in a planned family of AegisAI Lab models, along with investigation tools built around them. The company’s goal is for every email that reaches an employee to be judged on the evidence behind it, not on how closely it resembles past attacks.
About AegisAI
AegisAI is the first AI lab for email security. Founded by a security team from Google, the company builds models that investigate every email before it reaches a person, checking each message’s claims against evidence the sender does not control. Its research team includes former leaders of Chrome Enterprise Security, Google Ads Security, GCP AI Platform Security and Google reCAPTCHA/Safe Browsing. Proteus is the first model released by the AegisAI Lab.
Daniel Henderson: Daniel@aegisai.ai
View original content to download multimedia:https://www.prnewswire.com/news-releases/aegisai-launches-proteus-the-first-foundational-model-for-email-security-that-investigates-every-email-like-a-security-analyst-before-it-reaches-the-inbox-302901929.html
SOURCE Aegis AI Security

