Archive for July 30, 2026

NCSC urges network device makers to improve forensic capabilities 

Posted in Commentary with tags on July 30, 2026 by itnerd

The UK’s National Cyber Security Centre (NCSC) is urging network device manufacturers to embed stronger “forensic observability” into their products to help organizations detect, investigate and respond to cyberattacks. 

New guidance, developed with international partners, calls on vendors to improve the collection and preservation of forensic data to support incident response and recovery. 

The guidance outlines 31 recommendations across areas including logging, time synchronization, event recording, forensic data collection and secure storage. NCSC said network devices are increasingly targeted by sophisticated threat actors, making it critical for organizations to have sufficient forensic evidence to determine how a compromise occurred and what systems were affected. 

Donald McFarlane, Advisory Board Member, Xcape, Inc Had this comment: 

“Government guidance is increasingly acknowledging that cybersecurity is about more than prevention, and that it requires enabling rapid investigation, containment, and recovery for when prevention fails. Forensic observability should be viewed as a core design requirement for network infrastructure, not an optional feature. 
 
“Network devices have historically prioritized forwarding packets over recording evidence. Today, defenders need trustworthy, tamper-resistant forensic data to determinewhat happened, what was affected, and how to recover. You can’t investigate what you didn’t record. 
 
“It’s also worth viewing this alongside the recent Five Eyes guidance on preparing critical infrastructure to operate while intentionally isolated from external dependencies during a major cyber incident. Those recommendations aren’t in tension: organizations must be prepared to operate independently during a crisis, but collective defense still depends on sharing high-quality telemetry, forensic evidence, and threat intelligence before and after an incident. Resilience requires both the ability to stand alone and the ability to learn together.” 

Denis Calderone, CTO, Suzu Labs follows with this: 

“We generally love the direction this guidance is heading. What the NCSC is really asking for is EDR-level telemetry on network devices, and I’d argue that it’s long overdue. This incorporates devices that sit on the perimeter.  These devices are the way into the target, the way attackers exfiltrate data out of the targets and are often the internal boundary that must be traversed while moving from zone to zone and internal network to network.  In short, they see an awful lot, and that’s the data you need when working a real incident. The telemetry they could be providing about attacker movement, tooling, and data flows between environments is invaluable for an investigation. During incident response it’s not uncommon for the handlers to request log data, only to find that it falls short of their needs. 

“If I had a nickel for every time I’d heard “oh, we weren’t collecting that log data”, or “it only goes back 2 days”, well, I’d have a lot of nickels. This could allow us to maybefinally see the early promises of SIEM come true, where all events were going to be perfectly correlated across all layers of the stack. If vendors actually deliver on this guidance, we may end up with meaningful telemetry from the network infrastructure flowing into the same correlation engines that are already processing endpoint and cloud data. You could trace lateral movement across zone boundaries, identify what tools the attacker used, and quantify how much data moved between segments. That changes the quality of an investigation completely.  

“There’s a lot in this, but one thing I really do like is the emphasis on log shipping and the recommendation that devices should alert administrators when remote logging is disabled or misconfigured. That’s a simple thing that would catch a lot of problems early, including attackers who disable logging as one of their first moves after compromise. It would be great to correlate all the data in an intelligent way, but just having the data there at all is a huge plus over what we often find during actual incidents. 

“It’s also worth noting that this isn’t just a UK initiative. CISA, the FBI, and the Australian, Canadian, and New Zealand equivalents all co-authored the underlying guidance back in February 2025, and NIST currently has nothing this specific for network devices. This is currently the most detailed framework out there for what manufacturers should be building, and it has Five Eyes backing.  

“The one concern I’d flag is telemetry overload, particularly around capturing all DNS queries on a busy network device. That’s a lot of data, and organizations that are already managing high SIEM costs and alert fatigue need to think carefully about how they consume and operationalize this without drowning in it. That said, the volatile data collection recommendations are excellent. Capturing the running state of a device during an incident, process trees, memory maps, network connections, and particularly the CAM tables and DHCP lease tables, that’s the kind of data that can completely change an investigation. Knowing which MAC addresses were on which switch ports and which IPs were leased at the time of compromise could be a real game changer during an actual incident.” 

Josh Marpet, Senior Product Security ConsultantFinite State: 

“The NCSC has put out a security posture recommendation. Network devices should be able to log, secure, and be forensically available for examination, for both volatile and static data. 

“Why? Because for so long, network device manufacturers built the cheapest hardware they could, to be competitive in price. But that means that firmware is squeezed into flash too small to back itself up, hardware doesn’t have the space to store logs, or have the capability to be attached to a forensic duplicator. 

“The NCSC is asking manufacturers to make sure that network devices, long the target of cybercriminals and rogue nation-states, can perform basic security hygiene and has the basic security and compliance capabilities to make it simpler and faster for enterprises to perform incident response, disaster recovery, and be a modern mature workplace. 

“None of it is extraordinary, most of it is fundamental steps. Rich log data, solid logs of all major events, protection of keys, physical protection of protected hardware modules (TPM, HSM, etc), and the ability to do remote logging and maybe even local logging. 

“Again, nothing crazy. Fundamental security, especially for a device that traffics all of the data from the enterprise. Good ideas. Solid guidance. Manufacturers! Follow it!!!” 

Basic logging and a basic security posture… Sounds like a very good idea to me. This should be copied elsewhere as the UK seems to have a few good ideas.

White House cites quantum supply chain as major challenge 

Posted in Commentary with tags on July 30, 2026 by itnerd

A White House official said fragmented and underfunded supply chains remain one of the biggest obstacles to advancing U.S. quantum technologies. 

Speaking during an industry webinar, Brad Blakestad, director of the National Quantum Coordination Office, said quantum computing, sensing and networking each rely on different hardware platforms and components, creating multiple interconnected supply chains that are difficult to secure and scale. 

Blakestad said the quantum industry is nearing broader commercialization but lacks sufficient private-sector funding to build resilient supply chains. He pointed to the Trump administration’s recent quantum executive order, which calls for strengthening domestic quantum supply chains through research, manufacturing and private-sector collaboration, while warning that securing future quantum encryption capabilities remains another key challenge. 

Donald McFarlane, Advisory Board Member, Xcape, Inc. had this comment: 

“The national security implications extend well beyond today’s research pipeline. If a cryptographically relevant quantum computer becomes practical, strategicadvantage won’t come from building the first one: it will come from being able to manufacture, deploy, sustain, and improve them at scale. This is as much about surge capacity as it is about supply chains. 

“The administration’s emphasis on domestic quantum manufacturing reflects that reality. The United States has long excelled at fundamental research, but technological leadership ultimately depends on the ability to translate breakthroughs into resilient domestic production. The relevant question isn’t simply whether we can build a sufficiently capable quantum computer, it’s whether we can rapidly build many of them, along with the cryogenic infrastructure, control electronics, specialized manufacturing, and skilled workforce needed to support them. 

This planning should already be well under way. Building surge capacity for quantum technologies can’t begin after a breakthrough has occurred. The industrial base, manufacturing capability, and supporting infrastructure must be developed in parallel so they are ready when they’re needed, not years later. 

“Leadership in quantum won’t be determined solely by scientific discovery; it will also be determined by who can industrialize, scale production, and sustain operational capability when national security demands it. 

Aaron Colclough, VP of Operations, Suzu Labs adds this comment: 

“Blakestad’s right that this isn’t one supply chain. Computing, sensing, and networking pull different parts, and even within computing the machines are built different ways, with different parts. That means several intertwined bills of materials to secure and scale, not a single national stack. 

 “The June order tries to fix that by mapping the supply chains, cutting manufacturing friction, and incentivizing the buying of parts. But that only works if there’s money and the order doesn’t invent a budget by itself. 

“Encryption is the part most companies can act on now. You don’t need a working quantum computer to start swapping out today’s public-key crypto for NIST’s post-quantum algorithms. Find where you encrypt and sign today, then plan the cutover. Waiting for “Q-day” is how you leave old traffic sitting around for someone to decrypt later.” 

Resilient supply chains are a today problem. Thus every organization needs to treat them as such today.

Claude Was Down But It Is Back Up At The Moment

Posted in Commentary with tags on July 30, 2026 by itnerd

Claude was down yesterday for some users, with Anthropic confirming elevated errors across multiple AI models. The disruption is causing requests to fail with a “529 Overloaded” message, including in Claude and tools that rely on its API. It is currently up according to this:

Claude Status

But you should check to see if it is up for you. There’s also a story on this here:

Claude AI Recovering After Widespread Outage on Wednesday – CNET

Commenting on this story is Jamie Beckland, CPO at APIContext:

“AI has gone from an experimental productivity tool to an essential part of the working day with remarkable speed. When Claude fails, it no longer means someone cannot play with a chatbot—it can stop developers writing code, support teams answering customers and automated workflows completing critical tasks.

That makes Anthropic’s repeated availability problems over recent months increasingly consequential. Persistent outages risk weakening Anthropic’s position in those enterprise architecture decisions.

By observing our public monitoring, it becomes clear that this is not solely an Anthropic problem. No AI provider is perfectly reliable when subjected to today’s extraordinary and unpredictable demand. Enterprises therefore need to treat AI services like any other critical third-party infrastructure: monitor them independently, understand their real-world performance, and build fallbacks so the failure of one model does not bring an entire workflow to a halt.”

If AI is part of your workflow, you should take outages into account. Otherwise you might find yourself high and dry so to speak.

iOMedia Group and Tumeryk Partner to Advance Human-Controlled AI for Ethical Journalism

Posted in Commentary with tags on July 30, 2026 by itnerd

iOMedia Group Ltd today announced a strategic partnership with Tumeryk, bringing together two organisations committed to ensuring that artificial intelligence is deployed responsibly, transparently and under meaningful human control within professional news organisations.

The partnership combines iOMedia Group’s AΩχ (Alpha Omega Chi) governance platform for journalism with Tumeryk’s expertise in AI security, governance and operational oversight, creating a powerful framework for trusted AI in editorial environments.

As news organisations worldwide seek to harness artificial intelligence while protecting editorial standards, legal compliance and public trust, the collaboration aims to demonstrate that AI should enhance journalists – not replace them.

AΩχ has been developed by iOMedia Group with the backing of Innovate UK and with assistance from The Alan Turing Institute. Rather than allowing AI to operate autonomously, AΩχ places editorial governance at every stage of the newsroom workflow, ensuring that journalists remain responsible for editorial decisions while benefiting from AI’s speed and productivity.

Under the partnership, Tumeryk’s AI governance and assurance capabilities will complement AΩχ’s newsroom workflow, helping publishers gain greater visibility, control and confidence over how AI systems operate in live editorial environments.

The partnership reflects a shared belief that trust in journalism can no longer depend solely on the reputation of a publisher. In an AI-powered world, trust must also be earned through transparent processes, accountable decision-making and continuous human oversight.

By combining editorial workflow governance with AI assurance, iOMedia Group and Tumeryk intend to provide publishers with an integrated approach that supports innovation while meeting the highest standards of ethics, compliance and operational resilience.

The collaboration will focus on helping broadcasters, publishers and digital news organisations deploy AI safely across news gathering, production, publishing and multi-platform distribution without compromising editorial independence or accountability.

As AI rapidly transforms media worldwide, the companies believe governance will become as important as the technology itself. Their shared vision is a future in which every AI-assisted story can be produced with clear accountability, transparent oversight and human editorial control.

Why governance matters now

The need for governance has been underscored by the security incident disclosed by OpenAI and Hugging Face on 21 July 2026. During an internal cyber-capability evaluation, OpenAI models operating with reduced cyber refusals were involved in a compromise of Hugging Face infrastructure. OpenAI said the incident combined state-of-the-art cyber capabilities and warranted a joint investigation and stronger defensive safeguards.

AI does not become trustworthy simply because it is instructed to “do the right thing”. The incident illustrates a wider issue: as AI systems become more capable, persistent and agentic, instructions alone cannot provide sufficient assurance that they will remain within their intended boundaries.

The answer is not to limit innovation. It is to build safeguards that make AI accountable, transparent and subject to meaningful human control. This is the principle behind AΩχ.

By embedding governance, oversight, auditability and human accountability into AI-assisted workflows, AΩχ is designed to support human decision-making rather than permit technology to operate beyond it. In journalism, where trust is fundamental to democracy, governance must become part of the technology itself – not an afterthought.

AI wrote exploit scripts against 12,500 domains and found live targets

Posted in Commentary with tags on July 30, 2026 by itnerd

Security firm Silent Push used Claude Opus 5 to write exploitation scripts against 12,500 domains, then filtered the results down to several hundred genuinely exploitable dangling DNS records. It’s a known bug class, a DNS record still pointing at a cloud resource that’s since been deleted, letting an attacker reclaim it, but Silent Push demonstrated it against real, named organizations.

You can read more here: Welcome to Danglegeddon – Silent Push

John Watters, Chairman & CEO, iCOUNTER had this to say:

“Silent Push used Claude Opus 5 to write exploitation scripts against 12,500 domains and came back with several hundred workable targets. These are real organizations, not lab conditions: a dangling Azure blob storage record tied to U.S. government infrastructure that could bypass .gov trust filters, an unassigned Société Générale Azure resource, exposed developer credentials and API keys at Ford, and a stale record at Eli Lilly. Silent Push projects losses in the hundreds of billions across pharmaceutical companies alone if this class of vulnerability gets weaponized at scale.

Security teams need to treat domain inventory as something that gets maintained continuously, not set up once and forgotten. That means tracking every DNS record they’ve created, including the orphaned ones pointing at cloud resources that were deleted months or years ago and never cleaned up. Most organizations have no idea how many of those records exist in their own environment, and Silent Push just showed exactly what an attacker can do with the ones they find.

What used to take a nation-state’s intelligence apparatus, mapping thousands of domains, cross-referencing DNS history, and building exploitation infrastructure by hand, now runs as an automated pipeline. An AI model did the reconnaissance, filtered the noise, and handed back a ranked target list touching banking, government, manufacturing, and pharma in a single pass. The skill and headcount required to run a globally coordinated infrastructure attack just dropped by an order of magnitude.”

If you haven’t been attacked by AI, you’re going to be. Of that there is no doubt. The question is will you be ready to defend against an AI attack.

EY Canada makes leading investment in Quantum Computing

Posted in Commentary with tags on July 30, 2026 by itnerd

EY Canada today announced the expansion of its quantum computing capabilities to help clients solve increasingly complex business challenges in areas of optimization, fraud detection and large-scale risk management. The investment in an on-site quantum computer further enables the processing of highly sensitive workloads within Canadian borders, helping organizations meet growing security, privacy and regulatory requirements.

Moving from experimentation to real-world application

EY is continuing its Client Zero approach, developing and testing quantum-enabled solutions within its own environment to help move visionary ideas toward practical use for clients. Owning the system in-house helps organizations meet stringent regulatory, privacy and industry requirements that cloud-based alternatives cannot always address.

The new capability provides dedicated access and greater control over the development of new applications, including where data resides, how it is managed and who can access it. This includes enhancing the testing, refinement and validation of quantum-enabled solutions in areas such as financial optimization, advanced fraud detection, data protection and large-scale system planning. These applications span financial services, energy, supply chain and government, where organizations increasingly need to balance operational complexity with data sovereignty, privacy and regulatory requirements.

This investment builds on EY’s recent quantum patent and strengthens the ability to help clients identify where quantum can deliver measurable value while advancing Canada’s position in the global quantum tech ecosystem through local innovation.

Driving global innovation forward

The new quantum capability is part of EY’s global investment of more than US$3 billion in AI and next-generation technologies, helping clients move beyond experimentation to unlock new opportunities in forecasting, optimization, decision intelligence and risk management. The investment also aligns with ey.ai The Reimagination Engine, EY’s AI-led technology system designed to help organizations transform with confidence.

Check Point Revolutionizes the Firewall Market: New AI Network Firewall Closes the Network’s AI Blind Spot — Everywhere 

Posted in Commentary with tags on July 30, 2026 by itnerd

Check Point Software Technologies Ltd. (NASDAQ: CHKP), a pioneer and global leader of cyber security solutions, today announced the Check Point AI Network Firewall, delivered as part of Check Point firewall software release R82.20. AI has introduced a new class of network traffic — prompts, autonomous agent actions, and sensitive business context — that traditional firewalls were never designed to see or secure. The AI Network Firewall closes that gap from the Check Point firewall organizations already run, delivered through Check Point’s AI Defense Plane with no new infrastructure and no rearchitecting. 

The exposure is already universal. Check Point Research’s AI Security Report 2026 found that between 87% and 93% of organizations experience at least one high-risk generative-AI interaction every month and the share of prompts carrying sensitive corporate, personal, or regulated data doubled in a year to one in every 25 interactions. Organizations are adopting AI faster than they can govern it, and the activity that needs governing is already moving across the network. 

Turning existing firewalls into immediate AI protection 

Unlike alternatives that require a separate virtual firewall deployed alongside existing infrastructure, Check Point delivers this protection directly from the physical or virtual firewalls customers already operate and scales across branches, data centers, cloud, and multi-cloud environments. For Check Point firewall customers, the AI Network Firewall turns existing firewall investments into immediate AI protection across three domains: 

  • Employee AI use: Discover AI apps, agents, and tools in use — both shadow and sanctioned — gain visibility into how AI is being used and prompt use-cases and intents, govern access to safe and sanctioned tools, and stop sensitive data from leaving the network based on the prompt’s use case. Check Point Research found organizations now run an average of ten AI applications per month, many outside any formal process 
  • AI Tools (MCP): Discover Model Context Protocol (MCP) communication, gain full visibility into servers and used tools, and enforce policies to control access across every interaction. Check Point Research found security weaknesses in 40% of 10,000 MCP servers reviewed 
  • AI Application and LLM: Prevent prompt injection and adversarial inputs, blocking malicious prompts before they reach the LLM. This happens inline, with no application changes required. Check Point Research identified 15,300 indirect-injection payloads planted in public web pages, roughly 70% of them hidden in parts of the page no human ever sees 

Part of the AI Defense Plane: one architecture across the enterprise 

The AI Network Firewall becomes part of Check Point’s AI Defense Plane, a unified control plane for discovering, governing, and protecting AI across the network, endpoints, cloud, applications, and APIs. Together, the AI Defense Plane delivers: 

  • Discovery, governance, and protection for AI across web, desktop, coding assistants, and AI agents 
  • Local AI agent discovery and control 
  • SaaS AI agent discovery and control 
  • Runtime protection and governance for AI applications 
  • Risk detection and guardrails to protect homegrown and deployed AI 

Additional enforcement points across the AI Defense Plane span standalone API for self-managed applications, endpoint for employees, containerized firewall for AI data centers, and WAF – giving organizations consistent AI security across public and private clouds, branch offices, remote users, and data centers. 

Unified, agentic management across a hybrid, multi-vendor environment 

Following the recent announcement of its agentic network security orchestration platform, Check Point is also extending central policy management to Check Point SASE and SD-WAN, with dynamic, always-accurate zero-trust policy enforcement across IT, OT, and micro-segmentation tools including Illumio and others: 

  • One console manages on-premises firewalls, cloud firewalls, AWS native firewalls, SD-WAN, and SASE with consistent policy and a unified audit trail across every environment 
  • SD-WAN connectivity and security policy are managed together, ending the operational split that forces teams to juggle separate tools 
  • Open-platform integrations keep firewall rules current as the environment changes, without manual reconciliation  

Check Point AI Network Firewall is available now. Learn more here

BreachLock Publishes 5th Annual Penetration Testing Intelligence Report Mapping Critical Attack Paths and Actionable Cyber Resilience Strategies

Posted in Commentary with tags on July 30, 2026 by itnerd

BreachLock, the only offensive security platform combining agentic AI-powered autonomous penetration testing, expert-led, agentic AI-accelerated penetration testing services, and continuous Attack Surface Management (ASM), today announced the release of its 2026 Penetration Testing Intelligence Report, the company’s fifth annual analysis of real-world security findings across global organizations. Based on data from 4,970 penetration tests and 531,770 individual security findings, the report provides a comprehensive analysis of the vulnerabilities, attack patterns, and emerging risks shaping the cybersecurity landscape in 2026 and beyond.

Among the report’s most significant findings is the emergence of AI as a major enterprise attack surface. BreachLock’s inaugural AI penetration testing dataset found that 100% of AI applications tested contained vulnerabilities aligned with the OWASP Top 10 for LLMs. Prompt injection (LLM01) was the most prevalent and impactful finding in the dataset, present in 28% of tested applications.

The report also identifies a sharp shift in how attackers are targeting web applications. Insecure Design and business logic flaws (OWASP A04) rose from 8% to 16% of findings year over year, a trend-defining increase in the 2026 web application dataset. Testers observed attackers exploiting race conditions in checkout flows, escalating privileges through parameter manipulation, and bypassing approval workflows outright. These issues do not appear on automated scanner reports. Finding them requires testers who understand how an application is supposed to behave and can reason through how that logic can be subverted.

Cloud environments produced the highest concentration of severe risk in the dataset. Cloud security audits carried a Critical finding rate of 1.34%, thirteen times higher than the rate found in web application testing, driven largely by exposed S3 buckets, leaking Lambda functions, and disabled GuardDuty monitoring.

Mobile applications showed a similarly narrow but severe risk profile. Hardcoded credentials in iOS applications accounted for 97% of all Critical mobile findings this year. These credentials can be extracted with free, publicly available tools in minutes, and credential-related vulnerabilities continue to be a top attack vector in headlines this year.

The report also highlights industry-specific risk trends across manufacturing, telecommunications, financial services, healthcare, retail, and technology organizations.

BreachLock’s 2026 report is designed to help security leaders benchmark their programs against real-world offensive security data while providing actionable recommendations for reducing exposure through continuous testing, adversarial validation, cloud governance, mobile application security, and AI security assessments.

Download the BreachLock 2026 Penetration Testing Intelligence Report or read the blog for highlights.

Cinchy Joins AI Partnerships Partner Network to Help Enterprises Accelerate Trusted AI Adoption

Posted in Commentary with tags on July 30, 2026 by itnerd

As enterprises race to deploy artificial intelligence across every part of the business, one reality is becoming increasingly clear: successful AI adoption requires more than powerful models. It requires a trusted ecosystem of strategy, implementation, governance and security working together to help organizations deploy AI with confidence.

Today, Cinchy announced it has joined the AI Partnerships (AIP) network, expanding access to PeriMind through a growing ecosystem dedicated to helping enterprises accelerate trusted AI adoption.

PeriMind is Cinchy’s AI Action Governance platform. AI Action Governance is an emerging layer of enterprise AI infrastructure that provides runtime governance, policy enforcement and operational oversight for AI systems as they interact with enterprise data, applications and business processes. By helping organizations understand, control and audit every AI action, PeriMind enables enterprises to move AI from experimentation into trusted business operations.

The partnership reflects an important shift in the enterprise AI market. Organizations have largely moved beyond asking whether AI can create business value. Instead, they are focused on how to deploy AI securely, govern AI actions across the enterprise and build the operational trust required to move from isolated pilots to production-scale AI.

Through its AI Action Governance, PeriMind offers a new operational layer that provides visibility, policy enforcement, runtime controls and complete auditability for AI systems operating across enterprise data, applications and business processes.

Enterprise AI is becoming too complex for any single vendor to solve alone. Organizations increasingly need strategic advisors, implementation specialists, governance platforms, security technologies and integration partners working together to support successful AI adoption. The AI Partnerships partner network brings together complementary expertise that helps customers move more quickly (and more safely) from experimentation to enterprise-wide deployment.

Through the partnership, organizations working with AI Partnerships will have access to PeriMind’s AI Action Governance capabilities, including:

  • Runtime governance for AI systems and autonomous agents
  • Secure connectivity between AI and enterprise data and applications
  • Continuous visibility into AI actions and interactions
  • Policy enforcement and human oversight
  • Comprehensive audit trails supporting compliance, accountability and operational trust

Together, Cinchy and AI Partnerships will help enterprises address one of AI’s biggest adoption challenges: ensuring AI remains secure, governed and accountable as it begins making recommendations, initiating workflows and taking actions across critical business systems.

For Cinchy, the partnership represents another step in advancing its vision of trusted AI adoption, helping organizations bridge the gap between AI innovation and enterprise operations through governance that enables, rather than slows, AI transformation.

AI Is Creating a Trust Gap in Business Email, Exclaimer Research Finds

Posted in Commentary with tags on July 30, 2026 by itnerd

Exclaimer has released research showing that AI is weakening a basic assumption of business communication: that a polished, professional email reflects the authority and identity of the person who sent it.

The nationally representative OnePoll study of 1,000 US adults found that 65% now use AI in some aspect of their communications. At the same time, 36% have questioned whether a message they received was genuine, while 14% say they do not trust emails from external companies at all. The findings point to a growing gap between how credible an email appears and how confidently recipients can verify who is behind it.

AI is in the inbox and not just for productivity

AI has quickly become a routine part of how Americans communicate. Nearly two-thirds (65%) now use AI in some aspect of their communications, most commonly to improve grammar and spelling (20%) or make their writing sound more professional (19%).

But the research suggests AI is doing more than helping people write better. It is increasingly shaping how they present themselves. Sixteen percent use AI to sound more confident in their communications, 12% use it to soften difficult messages, 10% use it to avoid awkward conversations, and 9% use it to hide uncertainty. That means the tone of an email may no longer reliably reflect the sender’s own judgment or authority.

The more professional the email looks, the easier it is to trust

Trust in company email is already under pressure. More than a third (36%) say they have questioned whether a message they received was genuine, while 14% do not trust emails from external companies at all.

That uncertainty is changing what we look for when deciding whether to believe an email. Rather than relying solely on the quality of the writing, recipients increasingly judge the sender. Full contact details (40%), a professional email address on a company domain (35%), and a clear sender name (30%) are the strongest trust signals.

One finding stands out. Nearly one in four (23%) say a professional, branded email signature makes a company email feel more trustworthy. They ranked it ahead of legal disclaimers (17%) and consistent formatting (16%), suggesting that recipients see the signature as more than a visual flourish.

A verified company domain, a named individual, and a consistent branded signature help recipients distinguish between a message that simply looks convincing and one that comes from a real, identifiable, and accountable person.

Email continues to carry some of the most important communications between organizations and the employees and customers they serve. It is the preferred channel for employer updates (35%), formal complaints to a company (33%), and healthcare information (27%). Its value also lies in permanence. When employees need information they can keep or refer back to, 43% choose email, more than twice the proportion who select any other platform. A further 33% have deliberately used email instead of another channel because they wanted a permanent record.

When recipients cannot tell whether a message is genuine or identify the person responsible for sending it, the reliability of that communication begins to break down.

Sender identity is becoming business infrastructure

The platform carrying a message already influences how people receive it. Forty-three percent say the channel affects how trustworthy a communication feels, while 39% say it shapes their view of its professionalism and authenticity.

For businesses, securing the domain is no longer enough. Organizations also need consistent control over how sender identity is presented in every email, including the name, contact details, company information, and the attached signature. As AI makes professional communication easier to produce at scale, governance must ensure that every message can still be traced to a real person, a legitimate organization, and an accountable source.

Access Exclaimer’s full When it Matters: How People Really Communicate study.

Read the blog here.