Summary
- Abnormal has launched products covering authenticated identity compromise, enterprise AI use, and potentially fraudulent job applicants.
- Its platform applies behavioural analysis beyond email, where valid credentials and authorised applications can conceal attacks.
- Recruitment screening and automated intervention introduce privacy, fairness, governance, and human review requirements alongside security benefits.
Cybersecurity suppliers are widening their view of identity beyond the moment a user signs in, responding to attacks that rely on valid credentials, legitimate sessions, authorised applications, and people who appear to belong inside the organisation.
Abnormal AI has expanded its behavioural security platform with three products covering identity compromise, enterprise AI governance, and suspected infiltration through recruitment. Identity Threat Protection, AI Governance, Infiltration Prevention, and a self-service AI App Store are due to become available on 3 August.
The company built its business around email security, using communication and identity signals to identify activity that differs from established behaviour. It now plans to apply the same model after authentication, across AI tools and agents, and before a new employee receives access.
Abnormal says it protects more than 4,500 organisations, including over a quarter of the Fortune 500. Those figures come from the company, while the new products are being introduced before extensive independent deployment evidence is available.
Authentication has become the start of the investigation
Identity Threat Protection combines email, software, and sign-in information to identify weaknesses and unusual activity inside sessions that have already passed authentication. It can surface accounts without multifactor authentication, excessive service account privileges, OAuth abuse, suspicious resets, and behaviour associated with compromised identities.
Criminal and state linked groups increasingly obtain session tokens, manipulate help desks, compromise authorised applications, or persuade users to approve access. Traditional controls may establish that a credential is valid without determining whether the person or process using it is acting normally.
Behavioural analysis can identify deviations, although a deviation does not prove compromise. Employees change roles, travel, work unusual hours, use new applications, and perform one-off tasks. Security teams need thresholds and investigation processes that separate useful signals from anomalies created by ordinary work.
AI Governance extends monitoring to sanctioned and unsanctioned AI applications, chats, and agents. Abnormal says the product discovers tools through existing email and identity signals, establishes behavioural baselines, and can enforce customer defined policies when an application gains unusual access or moves beyond its expected role.
Discovery provides an inventory, but governance still requires decisions about which data may enter a model, which suppliers are acceptable, how prompts and outputs are retained, what an agent may change, and who owns the resulting risk.
Recruitment security carries employment consequences
Infiltration Prevention is the most unusual addition. The product integrates with applicant tracking systems including Greenhouse and Workday, analysing signals such as internet phone numbers, masked locations, repeated identities, and links with known campaigns before an account is provisioned.
Fraudulent remote workers are a documented threat. Google’s Mandiant investigations have examined North Korean IT worker operations in which people use fabricated or borrowed identities to obtain employment, generate state revenue, steal information, or support later cyber activity.
Candidate screening can also influence access to employment and process sensitive personal information. The UK Information Commissioner’s Office has warned employers that buying an AI recruitment system does not transfer responsibility for fairness, accuracy, transparency, or data protection.
Within the EU, systems used in recruitment can fall within the AI Act’s high risk categories depending on their function. A tool that influences access to work carries different obligations from a security alert used only to support a documented human investigation.
Abnormal says the product generates evidence briefs for security teams rather than making the hiring decision itself. Customers will still need to determine whether reviewers can understand and challenge those signals, how false positives are corrected, and whether location or communications indicators disadvantage legitimate applicants.
The AI App Store allows customers to trial and activate Abnormal products from one interface. Faster activation may help teams respond to changing threats, although it also removes some of the friction that normally prompts procurement, privacy, and architecture reviews.
Combining email, identity, AI use, and recruitment reflects the way attackers cross organisational boundaries that security products have traditionally treated separately. It also gives the defensive platform a broad view of communications, applications, employees, and candidates, requiring controls that extend as far as its visibility.








