All Posts
Announcements

A Spam Filter for the AI Era

Your most important email shouldn't be in junk. We are taking the exact same agentic reasoning that stops advanced phishing and malware, and applying it to the rest of your mail.
Written by
Badr Salmi
Published on
June 17, 2026

Your most important email shouldn't be in junk. We are taking the exact same agentic reasoning that stops advanced phishing and malware, and applying it to the rest of your mail.

Why does spam still plague every inbox? It is an age-old problem we have fought for more than a decade, first as part of Gmail's defenses, Google Search and now at AegisAI. The tools kept changing, but one limitation never did: a filter had to guess what mattered to each person. That is finally changing. LLMs and AI agents can now understand what a message actually says, and deliver protection personalized to each individual's preferences.

Everyone worries about the spam that slips through. It's annoying, but you delete it and move on. The truly expensive failure is the reverse: the critical message that never reaches you. A signed contract, a candidate who finally replied, or a customer escalation sitting in a spam folder no one opens.

Traditional filters were never built to catch that kind of failure. So, we built an agentic spam filter that does.

The Problem: Surface Filters Are Guessing

Legacy filters classify emails based on surface signals: sender reputation, bulk-send patterns, keywords, and authentication. In today's landscape, that leaves every inbox with a hard trade-off. Tighten the dial and you bury real mail. Loosen it and the noise floods back.

The numbers show just how often these legacy rules fail:

  • The False Positive Cost: In 2024, Microsoft's native filtering pushed 14.6% of legitimate commercial mail to junk. At scale, that means your team is missing vital communications.
  • The AI Blindspot: Today, LLM-generated spam can erase traditional "tells" on demand. When tested, traditional content filters misclassified up to 73.7% of LLM-rewritten spam as legitimate.

A filter reading only surface signals can't reliably tell wanted from unwanted, so it guesses.

A New Approach: Reasoning, Not Rules

We don't classify. We reason.

Our new agentic spam filter looks at each message the exact same way your own analysts would. We leverage the identical reasoning engine that already protects your environment from sophisticated attacks hiding behind clean reputations.

Feature
Legacy Spam Filters
AegisAI Agentic Filter
Detection Method
Rigid rules, keywords, and surface signatures.
Contextual reasoning based on user behavior and relationships.
Adaptability
Requires manual dial adjustments by IT.
Learns automatically from replies, rescues, and deletions.
Personalization
One-size-fits-all thresholds applied to everyone.
Tuned to each person: the senders, threads, and preferences unique to them.
Transparency
Black-box verdicts (Pass/Fail).
Clear, readable reasoning for every single decision.

Without anyone setting a rule, our agents pick up on what each person treats as a signal: the senders they reply to, the messages they rescue from spam, and the ones they banish there themselves. People are different, and their inboxes should be too.

The Core Benefits

Because the agents already read every message to stop malware and phishing attacks, this works instantly with the access you've already granted.

1. A Drastic Drop in False Positives

Your most important mail reaches the inbox where your team can actually act on it. By reasoning through context rather than tripping over keywords, the same agents that cut false positives on security threats by up to 90% now bring that exact same accuracy to the rest of your mail. Your IT team fields fewer "where's my email?" tickets, and your people stop digging through quarantine for emails they were expecting.

2. A Hyper-Focused Inbox

As AI-generated spam floods the system, your inbox automatically adapts to filter out the noise. Over time, each inbox learns to perfectly fit the person who uses it, prioritizing signal over spam and keeping your team focused on the work that actually matters.

Why AegisAI?

AegisAI comes from the team that built Gmail's defenses and scaled Google Web Risk, protecting email at a massive scale. It's why forward-thinking teams like Notion and LangChain trust us with the inboxes that run their businesses.

For decades, filters have tried to solve spam by classifying it. The real missing piece was judgment. We built agents that can make that judgment to stop attacks. Now, they make it on the mail that reaches your team.

Don’t Miss the Next Big Threat
Subscribe today to receive updates on the newest cyberattacks, product innovations, and best practices for protecting your organization.

Subscribe

Success! We’ll be in touch soon.
Something went wrong while submitting.
Related topic articles
Read All Articles
Diagram showing an AI agent registering domains and rebuilding malware on a loop, a victim entering a device code at a genuine Microsoft sign-in, and the resulting access and refresh token landing with the attacker
Threat Research
AI
Midnight Blizzard-Linked Actor GTG-20006 Automated Device Code Phishing With AI
Anthropic says GTG-20006, a Midnight Blizzard-linked actor, used AI to automate device code phishing against 20+ government and defense organizations.
September 11, 2026
Midnight Blizzard-Linked Actor GTG-20006 Automated Device Code Phishing With AI
Vendor email compromise diagram. Three real messages in a vendor thread are followed by one attacker-sent message changing bank details, which passes SPF, DKIM and DMARC, reaches finance, and diverts the wire to the attacker's account. An agent flags it as the first bank change in the thread and holds it.
Technical Guides
How to Prevent Business Email Compromise: BEC Protection That Works
How BEC attacks work, why they pass SEGs and DMARC, spoofed vs compromised senders, what detection must analyze, and the controls that stop invoice fraud.
September 10, 2026
How to Prevent Business Email Compromise: BEC Protection That Works
A legitimate supplier invoice collects three weak risk signals, new domain, urgent tone, locked PDF, whose score crosses the filter threshold and gets quarantined. A dashed path shows an agent reading the whole message and delivering it.
Technical Guides
Why Email Security False Positives Happen and How to Fix the Root Cause
Why signal-stacking email filters block legitimate mail, how to measure precision, recall and false-positive rate, and how reasoning-based detection cuts both error types at once.
September 9, 2026
Why Email Security False Positives Happen and How to Fix the Root Cause