India, Sept. 30 -- For years, phishing was something most employees were taught to recognise in an inbox.

A suspicious sender. A strange attachment. A link asking you to reset your password. A message that creates just enough urgency to make you act before you think.

That model is changing.

The next phishing attack may not arrive in an email at all. It may arrive as a phone call from someone who sounds exactly like your boss. It may be a video meeting with a familiar face. It may be a voice note from a vendor who knows the project, the people involved and the reason a payment is supposedly urgent.

The target, in such a case, is no longer the inbox.

It is trust.

This is the problem at the centre of the work of AI engineer Sahaj Gandh...