All Posts
Email Security
AI
Announcements

Why Aegis

Why We Started AegisAI
Written by
Cy Khormaee
Ryan Luo
Published on
September 8, 2025

Why We Started AegisAI

Email has been around for over 50 years—and for just as long, it’s been a security problem no one has truly solved. Despite all the advances in cybersecurity, email remains the single most common entry point for attackers. It's the front door to the enterprise—and it's still wide open.

Over the past few years, we’ve watched the threat landscape shift dramatically. Social engineering attacks are no longer crude or obvious. They’re sophisticated, personalized, and increasingly automated. Business Email Compromise (BEC) has exploded—and now, with generative AI in the mix, attackers are moving faster and scaling smarter than ever before.

We saw what was coming—and we didn’t see the right defenses being built.

That’s why we started AegisAI.

We believe the only way to combat AI-native threats is with AI-native defense. In the early days of our work, we saw just how powerful large language models could be—not just for generating language, but for understanding context, intent, and deception in ways traditional rule-based systems never could. We realized that this wasn’t just an incremental improvement—it was a step-function change in how security could be done.

The mission ahead isn’t easy. But it’s clear: to build intelligent, adaptive systems that can learn and evolve just as fast as the threats they’re facing. It means customizing language models to detect and respond to the full spectrum of known and emerging email threats—from zero-day phishing to highly targeted social engineering. It means treating every inbox like a dynamic, high-value environment that deserves real-time, AI-powered protection.

Our team brings together over 25 years of combined experience working on email security at Google. We’ve lived in the trenches of this problem, and we’ve seen what works—and what doesn’t. We’re builders, researchers, defenders. And above all, we’re mission-driven.

Defending the internet has been the through line of our careers. AegisAI is the next evolution of that mission—reimagining email security from the ground up with AI at its core.

This isn’t just about stopping today’s attacks. It’s about building a future where communication is safe by default and trust can scale. 

That’s the promise of AegisAI.

Email secured.

Cy & Ryan

Don’t Miss the Next Big Threat
Subscribe today to receive updates on the newest cyberattacks, product innovations, and best practices for protecting your organization.

Subscribe

Success! We’ll be in touch soon.
Something went wrong while submitting.
Related topic articles
Read All Articles
A wire-request email with no link and no file passes reputation, signature and URL-list gates untouched and lands in the finance inbox, while an AI agent reads the request and holds it: first wire ask, new payee.
Technical Guides
How AI-Powered Email Security Works (and Where It Beats Traditional Filters)
How AI-native email security detects phishing, BEC, AiTM and zero-day attacks that rule-based filters miss, plus a checklist for verifying vendor claims.
September 14, 2026
How AI-Powered Email Security Works (and Where It Beats Traditional Filters)
Diagram showing an AI agent registering domains and rebuilding malware on a loop, a victim entering a device code at a genuine Microsoft sign-in, and the resulting access and refresh token landing with the attacker
Threat Research
AI
Midnight Blizzard-Linked Actor GTG-20006 Automated Device Code Phishing With AI
Anthropic says GTG-20006, a Midnight Blizzard-linked actor, used AI to automate device code phishing against 20+ government and defense organizations.
September 11, 2026
Midnight Blizzard-Linked Actor GTG-20006 Automated Device Code Phishing With AI
Vendor email compromise diagram. Three real messages in a vendor thread are followed by one attacker-sent message changing bank details, which passes SPF, DKIM and DMARC, reaches finance, and diverts the wire to the attacker's account. An agent flags it as the first bank change in the thread and holds it.
Technical Guides
How to Prevent Business Email Compromise: BEC Protection That Works
How BEC attacks work, why they pass SEGs and DMARC, spoofed vs compromised senders, what detection must analyze, and the controls that stop invoice fraud.
September 10, 2026
How to Prevent Business Email Compromise: BEC Protection That Works