The Spear Phishing Agent is Hoxhunt's AI agent that automatically generates realistic, personalized phishing simulations using the same models that now beat human red teams at getting people to click. It trains employees against the AI-crafted attacks they actually face, delivering the right level of difficulty to keep engagement high and build lasting reporting habits.
For the past few years, we’ve been experimenting with AI’s and LLMs' abilities to create effective phishing emails.
We’ve investigated if AI can be a better social engineer than a professional human red team.
At first, while AI did fairly well, humans remained more effective at phishing.
Now, our new research showed that AI can beat humans at crafting phishing emails that get people to click. In our 2026 testing, Hoxhunt’s AI spear-phishing agents beat elite red teams at getting recipients to click (Hoxhunt Phishing Trends Report 2026).
AI is here to phish us
Social engineers are already using AI and LLMs to scale their phishing efforts. With AI’s clear status as an elite phishing operator, we need to ramp up phishing training to address this. We must ensure targeted humans stand as a resilient human firewall, reporting all and any suspicious messages.
That scaling is already visible in the wild: Hoxhunt’s 2026 data shows AI-generated phishing surged roughly 14× at the end of 2025, jumping from under 5% to 56% of detected attacks in a single month (Hoxhunt Phishing Trends Report 2026). When more than half of detected attacks are machine-crafted, training people against the same AI-created lures is no longer optional.
The best way to learn to become resilient against AI created attacks is to train with AI created attacks.
Spear Phishing Agent is here to train us
Our platform’s first official AI agent, the Spear Phishing Agent, is now available in Hoxhunt phishing training!
The Spear Phishing Agent uses the same AI models and techniques that beat human red teams to craft phishing simulations for training.
We’ve harnessed the evil AI for good, fighting AI with AI.
Users receiving these simulations are made aware of the dangers of AI as a phishing operator, and trained on the threats appearing in the messages.

The agent in Hoxhunt’s adaptive phishing training
The phishing emails created by the Spear Phishing Agent can be quite advanced attacks.
Our training philosophy is heavily based on training users at the right level of difficulty.
If training is too difficult, it’s frustrating.
If training is too easy, it’s boring.
The right amount of challenge helps maintain active participation and engagement in phishing training.
Engagement is crucial for maintaining muscle memory of what to do when encountering suspicious messages: report the messages.
The agent operates in our advanced training mode called “Spicy Mode”.
This mode delivers the most challenging simulations to users, using the most effective social engineering techniques and realistic scenarios.
How the agent generates attack variants at scale
Most phishing programs reuse a small library of templates, so motivated employees quickly learn to recognize the test rather than the threat. The Spear Phishing Agent works the opposite way. It builds each simulation from a unique combination of pretext, sender persona, lure and tone, then adapts the difficulty to the individual based on their training history. No two users see the same attack at the same moment, which is exactly how a real adversary operates.
Because the agent composes variants automatically, a security team can sustain a level of variety and volume that manual template-building never could. The model draws on the techniques that proved most effective against human targets in our research, so the simulations track the actual frontier of AI-assisted social engineering rather than last year’s playbook. As attacker tradecraft shifts, the agent shifts with it, which keeps the training honest and the difficulty calibrated.
This scale is what makes a program realistic rather than a once-a-quarter checkbox. Copart in the US delivered 963 unique simulation variants across 202,992 completed simulations, and Uber has run more than 100,000 simulations across 500+ scenarios with a two-person security team. In Europe, Ramboll has run over 100,000 simulations across 17,000 employees in 35 countries. That breadth is what an AI agent makes routine, and it is what turns a one-time test into continuous, attack-realistic practice.
Get the Spear Phishing Agent now
Already using Adaptive Phishing Training? Activate the Spear Phishing Agent in the admin portal’s new Agents section.
For more on choosing the right approach, compare the best phishing simulation tools, see why cyber security simulation training needs attack variety, and read how attackers personalize phishing campaigns.
- Subscribe to All Things Human Risk to get a monthly round up of our latest content
- Request a demo for a customized walkthrough of Hoxhunt



