The phish was written on your own AI.
Someone inside your organisation opens a sanctioned assistant and asks it to draft an urgent, strictly confidential email from the CFO to finance: same-day wire, new vendor, invoice attached, and a closing line discouraging verification. There is no malware to detonate, no external sender to flag, and no link to detonate in a sandbox — only an authorised employee using an approved tool to write a far better phish than they could have written themselves. The request is the attack, so the request is what gets read.