Behavioral AI automatic post-delivery remediation
Abnormal's pure-API email-security architecture can analyse email after technical delivery using Behavioral AI and subsequently remediate qualifying detected threats through cloud-email APIs. A documented quishing path shows post-delivery removal across affected mailboxes without analyst action. However, Abnormal also documents human-review escalation in its wider remediation architecture, so runtime human confirmation is conditional rather than universally absent. This is not arbitrary email administration.
Recorded characteristics
- Function
- Abnormal's pure-API email-security architecture operates post-delivery. Abnormal states: "Operating post-delivery means messages briefly exist in the mailstore before remediation—typically measured in seconds. A brief processing interval provides AI models the computational window to run complex behavioral analysis—natural language processing for tone shifts, graph neural networks for relationship mapping, anomaly detection across communication patterns—then conduct API calls that redirect messages and remediate threats." Messages can therefore briefly exist in the Microsoft 365 or Google Workspace mailstore while AI models perform behavioural analysis, after which API remediation can redirect or remove detected threats. Technical delivery and user interaction are distinct: the message is technically delivered to the mailstore first; product wording such as "before users can interact with them" or "before they reach the inbox" refers to user engagement and is not evidence of pre-delivery interception. Recorded chain: delivered email → identity / behavioural / content-context signals → Behavioral AI / model analysis → malicious/threat determination → remediation treatment → cloud-email API action → mailbox state changed. The AI is materially involved in the threat determination; the deterministic API execution layer performs the resulting mailbox operation. Documented quishing path: "When a quishing email is detected post-delivery, Abnormal removes it from every mailbox it touched and locks any account that scanned — no analyst action required." (The account-locking half of that sentence is account-takeover functionality and is outside this capability.) Product page: Attack Remediation "Automatically removes malicious messages from inboxes before users can interact with them". Qualifying remediation can alter the state/location of already-delivered malicious email and remove or redirect detected messages, including from multiple mailboxes a detected message reached where evidenced (the quishing path). Not every malicious verdict necessarily produces the same mailbox operation, and Microsoft 365 and Google Workspace mechanics are not claimed to be identical.
- Data access
- Abnormal states it analyses "behavioral, identity, and historical context across mailboxes" and that it "reads authentication events, calendar activity, and internal threads". Attune 1.0 "builds a behavioral baseline for every employee and vendor, then catches anything that deviates." Integration is with Microsoft 365 and Google Workspace via API ("Deploy in 60 seconds via API. No MX changes.").
- Actions
- Can take actions
- External actions
- Yes
- Human confirmation
- Conditional
- Permission basis
- Not established
- Administrative control
- Human confirmation (conditional): runtime human confirmation is conditional. Abnormal documents qualifying remediation that executes without analyst action (the quishing path: "no analyst action required"), while its wider remediation architecture also supports confidence-based escalation for human review. Abnormal's Learning / Incident Response article "AI-Driven Auto Remediation" (13 January 2026) — general guidance material, not a narrow Inbound Email Security administration specification — states that "Confidence thresholds let security teams define when automation acts independently versus escalating for human review" and "Below threshold, the system generates recommendations for analyst approval rather than acting independently." Human confirmation is neither always required nor never required. Permission basis (not_established): evidence establishes native API integration with Microsoft 365 and Google Workspace and API-driven remediation, but the reviewed public evidence does not establish whose runtime authority performs the qualifying mailbox remediation under the Registry taxonomy. "Uses an API" is not a permission-basis classification; no Microsoft Graph permissions, service principals, Google OAuth scopes, service accounts or domain-wide delegation are claimed. Adjacent controls (not the qualifying path): Search & Respond lets analysts "remediate individually or in bulk"; Quarantine Release lets teams "Review and release quarantined" messages; Threat Log shows "Every message Abnormal has evaluated, flagged, or actioned"; Abnormal states "Every detection includes in-depth explanations: which signals fired, what the baseline was, why it's anomalous."
- Default state
- Not established
- Availability
- Public evidence establishes that read-only evaluation and subsequent remediation activation are supported ("A 7-day read-only evaluation scans historical email for undetected threats before enabling full remediation"; "This runs the platform in read-only mode, analyzing email..."), but does not establish the universal default state of consequential automatic remediation in production deployments. The Registry does not claim that remediation is disabled by default for every customer, nor that it is enabled by default.
- Licensing
- Licensing and packaging are not recorded here.
- External model or provider
- Abnormal's own Behavioral AI (Attune 1.0). The architecture article names natural language processing, graph neural networks and anomaly detection. No external model provider is documented for this path. The Registry does not claim that a language model independently decides every remediation, that every Abnormal verdict comes exclusively from Behavioral AI, or that AI generates arbitrary remediation actions or directly manipulates mailbox storage.
- Limitations and uncertainty
- Boundary and exclusions: Custom Rules ("familiar rule logic") are deterministic and are a negative control — not evidence that Behavioral AI caused a remediation; not every automatically remediated message is necessarily evidence of the #160 Behavioral-AI path. Custom AI Models coexist with core detection but are not part of this record. Search & Respond (analyst-triggered manual/bulk remediation) is adjacent and does not establish the automatic path. AI Security Mailbox (user-reported-message analysis and campaign remediation) is outside this capability. Auto-Forwarding & Google Groups Protection for Google Workspace documents "pre-delivery scanning and remediation" for specific auto-forwarding / Google Groups scenarios; it is a separate architecture, excluded from #160, and shows Abnormal supports more than one email-processing architecture — not all Abnormal email processing is post-delivery. The quishing example's exact behaviour is not generalised to every threat type. The record does not claim: all Abnormal remediation is AI-derived; every AI verdict causes remediation; every remediation runs without human review; remediation is enabled by default; the universal default state or the runtime permission basis is known; arbitrary mailbox authority or arbitrary email deletion; that messages are always permanently deleted; identical Microsoft 365 and Google mechanics; that maximum blast radius is known; transactional or exactly-once remediation; automatic restoration of false positives; or that complete model reasoning is exposed. Reversibility: Quarantine Release exists for quarantined messages; Google purge/restoration mechanics and remediation-settings documentation were not retained as evidence. Maximum automatic-remediation blast radius: Not Publicly Established. Not publicly established: exact Attune model architecture; exact model version for every verdict; training corpus; complete feature weighting; universal confidence threshold; exact score-to-verdict mechanism; exact Microsoft Graph remediation permissions; Microsoft runtime service principal; exact Google OAuth/service-account scopes; Google runtime execution principal; universal production default state; universal remediation destination; universal maximum blast radius; batch limits; exactly-once semantics; duplicate-action suppression; retry policy and backoff; partial multi-mailbox remediation recovery; multi-mailbox transactionality; atomic campaign remediation; universal eventual-consistency guarantees; universal retention period; universal restoration; exact restoration to original folder/state; automatic AI restoration; complete model provenance; complete API-action provenance; complete internal feature values, model weights or low-level API request/response history; universal execution-principal attribution. Monitoring note: the product page declares a www canonical although the www address redirects to abnormal.ai; the monitor uses the non-redirecting address.
Evidence
- Inbound Email Security | Stop BEC & Phishing | Abnormal AI
Supports: Function · Actions · Admin controls · External model · Limitations · Availability · Primary source
Attune 1.0 builds a behavioural baseline for every employee and vendor and catches deviations.
Attack Remediation "Automatically removes malicious messages from inboxes before users can interact with them".
Threat Log, Search & Respond (manual/bulk), Quarantine Release; detections explain signals and baseline.
Powered by Attune 1.0 behavioural AI.
Custom Rules use "familiar rule logic" (deterministic negative control); Custom AI Models are separate.
Current product, deployed via API with no MX changes.
- How Email Security Architecture Shapes Detection and Response | Abnormal AI
Supports: Function · External actions · External model · Data access · Primary source
"Operating post-delivery means messages briefly exist in the mailstore before remediation".
AI models analyse, "then conduct API calls that redirect messages and remediate threats".
NLP, graph neural networks and anomaly detection run during the processing interval.
Analyses behavioural, identity and historical context across Microsoft 365 / Google Workspace mailboxes.
- Detect QR Code Attacks | Abnormal AI
Supports: Actions · Human confirmation · Primary source
Quishing email detected post-delivery is removed "from every mailbox it touched".
"no analyst action required" for the documented quishing path.
- The Must-Have Email Security Features in Modern Solutions | Abnormal AI
Supports: Default state · Primary source
"A 7-day read-only evaluation ... before enabling full remediation"; no universal default established.
- AI-Driven Auto Remediation | Abnormal AI
Supports: Human confirmation · Primary source
Confidence thresholds decide when automation acts independently versus escalating for human review.
- Auto-Forwarding & Google Groups Protection for Google Workspace | What's New | Abnormal AI
Supports: Limitations · Primary source
Negative control: "pre-delivery scanning and remediation" for auto-forwarding / Google Groups; excluded from #160.