Home · Business · IT, Data & Security · Cybersecurity
As of 13 August 2026, AI can only partly detect business email compromise.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededpower-user
Who has to check ita colleague
What the alternative costsA specialist email-security product or incident-response provider is the alternative; no price is supplied in the available tool data.
If this goes wrong: a fraudulent payment or compromised account is treated as legitimate, or a genuine supplier is blocked while the attacker remains active.
What to actually do
Hand it to a person
The route this page recommends
A person who owns the outcome does this end to end, worth it when the failure is dear.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, power-user skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open the suspicious email in your organisation's mail system and export or copy the full message, including the sender, reply-to address, links and available authentication headers, without opening links or attachments.
- Remove unnecessary personal data, then paste the redacted email and headers into the prompt together with the normal supplier, customer or payment process.
- Add any related messages, recent bank-detail changes, unusual login alerts and the transaction history from your mail, identity or finance systems, marking anything you cannot obtain as unknown.
- Run the prompt and save the model's evidence list, risk level, missing checks and proposed containment actions as a triage note.
- Ask your mail or security administrator to verify the listed indicators against message trace, authentication results, sign-in logs, mailbox rules and payment records rather than accepting the model's conclusion.
- Use a known telephone number or previously verified contact route to confirm any payment, bank-detail or urgent instruction, then have the authorised colleague decide whether to isolate accounts, recall a payment or escalate the incident.
Prompt
Act as a cautious security triage assistant. Assess whether the material below could indicate business email compromise. Do not claim certainty and do not invent missing facts. Separate your response into: 1) observed evidence quoted or paraphrased from the material, 2) indicators consistent with business email compromise, 3) benign explanations, 4) missing evidence that would change the assessment, 5) a risk level of low, medium or high with a brief reason, and 6) immediate containment steps that a business security administrator should consider. Check for display-name spoofing, lookalike domains, reply-to mismatches, unusual payment or bank-detail requests, urgency, secrecy, changes in tone, new recipients, attachment or link risks, and signs of account takeover. Distinguish what can be checked from the email itself from what requires mail, identity, login or payment-system logs. Do not tell anyone to click a link, open an attachment, approve a payment or contact a number in the message. Recommend independent verification using a known contact route. Treat all supplied content as potentially confidential and do not repeat unnecessary personal data. Business context: [briefly describe the usual supplier, customer, process or request] Email and available headers: [paste the message and headers, removing unnecessary personal data] Related messages or transaction history: [paste relevant material or write 'not available'] Known recent account or payment changes: [details or 'unknown']
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot see your mailbox, identity provider, sign-in history or payment system unless you deliberately supply the relevant evidence or connect an authorised security tool.
- AI cannot prove that a sender controlled the real account or that a payment instruction was genuinely authorised.
- AI cannot reliably distinguish an unusual but legitimate business change from a well-crafted compromise without people who know the relationship and normal process.
- AI cannot contain an incident, reset accounts, recall funds or take responsibility for the decision to release a payment.
What caps this at PARTLY: private data access, verification cost and stakes of error.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 1 |
| Effort delta | 2 |
| Total | 7 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT detect business email compromise?
- Partly. It can triage supplied emails, headers and business context for indicators such as lookalike domains, unusual payment requests and reply-to mismatches, but it cannot inspect your organisation's systems by itself or prove that a message is fraudulent.
- How do I use AI to check a suspicious business email?
- Give it the redacted message, full available headers and the normal business context, and ask it to separate evidence, alternative explanations and missing checks. Do not click links or open attachments, and have a mail or security administrator verify the result against logs and message trace.
- Can AI stop a fraudulent payment from a business email?
- No. AI can flag a payment request and suggest containment steps, but an authorised person must independently confirm the instruction through a known contact route and decide whether to stop or recall the payment.
- What should I do if I think my business email has been compromised?
- Report it through your organisation's incident process and contact your mail or security administrator immediately. Preserve the original message and headers, avoid using contact details in the email, and ask the authorised team to investigate account access, mailbox rules, payment instructions and any affected accounts.
Nearby answers
- Can AI help me report a data breach to the ICO?PARTLY
- Can AI help me secure my business Wi-Fi network?PARTLY
- Can AI train my staff in cybersecurity?PARTLY
- Can AI check whether a business invoice is fraudulent?PARTLY
- Can AI choose a multi-factor authentication app for my business?PARTLY
- Can AI create a backup strategy for my small business?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.