Introduction Phishing attacks have evolved rapidly with the integration of artificial intelligence, posing serious threats to digital trust and cybersecurity. Traditional and AI-assisted phishing techniques still rely on partial human intervention, limiting their adaptability and scalability. Recent advances in agentic artificial intelligence have enabled fully autonomous, goal-driven phishing campaigns capable of planning, personalizing, and executing attacks across multiple communication channels. Methods This study investigates the capabilities of agentic AI–enabled phishing by examining its core functional components and operational characteristics. A conceptual architectural perspective is presented to illustrate how autonomous planning, contextual intelligence, multi-modal content generation, and adaptive feedback mechanisms interact to support automated phishing campaigns. Results The analysis demonstrates that agentic AI significantly enhances phishing capabilities by enabling continuous optimization, contextual personalization, and adaptive decision-making during attack execution. The interaction of these architectural components allows phishing systems to dynamically refine strategies and potentially evade conventional detection mechanisms. Discussion The study highlights the increasing detection challenges posed by agentic AI–driven phishing systems and examines the associated technical, organizational, and societal risks. Emerging defense strategies and future research directions are discussed to address the evolving threat landscape. Overall, the findings emphasize the urgent need for adaptive and AI-driven countermeasures to effectively mitigate next-generation phishing attacks.
Chandre et al. (Wed,) studied this question.