Internal communications has an unusual problem among corporate functions. The work is highly visible when it goes wrong and nearly invisible when it goes right, and the thing it produces, trust in official messages, is the exact thing attackers are trying to borrow.
That second point is why this guide is not only about drafting tools. AI has genuinely improved how comms teams write, translate, target, and measure. It has also made convincing impersonation of your executives cheap, which means the channel your team owns is now an attack surface it partly controls.
Both halves matter, and most coverage only handles the first.
Where AI earns its place
Drafting and adaptation. The realistic gain is not writing announcements from nothing, it is adapting one message across formats. The same policy change becomes an email, a chat post, an intranet article, and a two line summary for a team meeting. That adaptation work is genuinely repetitive, and it is where comms teams lose hours.
Translation and localization. For companies with staff across regions this has moved from expensive and slow to fast and good enough for most internal content. The caution is that “good enough” does not extend to legal, safety, or HR policy content, where a subtle mistranslation carries real consequence and human review stays necessary.
Targeting and segmentation. Sending everything to everyone trains people to ignore you. Tools that segment by role, location, or relevance reduce volume per person, and that reduction is what restores attention. Read rates rise because the messages that arrive are more likely to matter.
Measurement. The genuinely useful shift. Traditional internal comms metrics were open rates, which measure delivery rather than understanding. Newer analytics identify which populations never engage, which messages generated follow up questions, and where a message landed but did not change behavior. That is the difference between reporting activity and reporting effect.
Summarization for leadership. Condensing feedback, survey responses, and channel sentiment into something an executive will actually read. Useful, with the standing caveat that summarization flattens outliers, and in employee feedback the outlier is often the signal.
The impersonation problem you now own
Here is the part that belongs in an internal comms plan rather than only a security one.
Attackers have always impersonated executives. What changed is quality and cost. Voice cloning from a few seconds of public audio, written messages matching an executive’s actual style because the model was given their published communications, and video convincing enough for a hurried person on a call. Your CEO’s speaking style is public. Your announcement formats are known to anyone who has worked there.
This lands on internal comms because the defense is largely a communications design problem, not a technical one.
Establish channel expectations and state them repeatedly. If financial requests never arrive by chat, say so, in the channel, more often than feels necessary. The value of a norm is that violating it is conspicuous.
Make verification socially acceptable. Most successful attacks exploit reluctance to question a senior person. That is culture, and comms shapes culture. An executive publicly saying they expect to be verified does more than a policy document.
Keep an out of band path. If your primary channel is compromised or spoofed, how does the company receive a trustworthy message? Firms that work this out during an incident do it badly.
Be careful what you publish about your own people. Detailed executive profiles, org charts, and audio content are all raw material. This is not an argument against publishing. It is an argument for knowing the tradeoff, which relates directly to how business email compromise actually succeeds: it works through familiarity, not technical sophistication.
The ways impersonation and phishing attacks evolve are worth tracking for a comms lead, because the trend directly shapes what your announcements should look like.
The tone problem nobody mentions
A practical risk with AI drafted internal communication, distinct from security.
Employees are getting good at recognizing generated text. Internal communication is one of the few places where the reader knows the sender personally, which makes generic phrasing conspicuous in a way it is not in marketing copy. A layoff announcement, a leadership change, or a response to a difficult quarter that reads as machine written does specific damage: it signals that the sender did not consider the message worth their own attention.
A workable line. Use AI freely for logistics, scheduling, process updates, and format adaptation. Write anything carrying emotional weight yourself, and use AI at most to check clarity. The messages that build or spend trust are the ones worth your own time, and they are a small fraction of total volume.
The channel sprawl problem AI makes worse
Most companies did not choose their internal communication channels. They accumulated them. Email, then a chat platform, then an intranet, then a separate app for frontline staff, then a video tool that grew its own announcement feature. Each arrived to solve a real problem and none of the earlier ones were retired.
AI tooling can make this worse before it makes it better, because publishing to every channel becomes nearly free. When distribution costs nothing, the discipline that used to force a choice disappears, and employees receive the same message four times in four formats. That is not better reach. It is the fastest way to teach people that official messages are noise.
Two things help. First, decide what each channel is actually for and enforce it, so employees learn where to look for what. Urgent and time critical in one place, reference material in another, discussion somewhere else. Second, use the targeting capability to send less rather than to send more. The temptation is to treat improved segmentation as permission to increase volume, when its real value is letting you cut volume without cutting reach.
There is also a security dimension to sprawl. Every additional channel is another surface an attacker can imitate, and the more channels carry official announcements, the harder it is for an employee to judge whether a given message arriving somewhere unusual is legitimate. A smaller, well understood set of channels is easier to defend and easier to trust, which is the same logic behind consolidating any other part of the estate. It also narrows the range of places a convincing phishing message can plausibly appear.
Measuring what actually matters
Four measures worth more than open rates:
Reach among the hard to reach. Frontline, deskless, and shift workers are usually the populations that miss messages, and averages conceal them. Segment your reporting or the gap stays invisible.
Question volume after an announcement. A well written message reduces follow up questions. Rising questions after a change means the message failed, regardless of how many people opened it.
Time to awareness. How long between publishing and the majority actually knowing. This is the number that matters in an incident.
Behavior change. The only real outcome. Did people do the thing.
During a security incident these stop being HR metrics and become operational ones, which is why comms belongs in business continuity planning rather than adjacent to it. The firms that handle an email compromise well are usually the ones who had already decided how they would tell everyone.
Practical guidance for rollout
Start with the highest volume, lowest stakes content. Process updates and format adaptation give quick returns and low risk. Establish a clear rule about which content categories are never fully AI drafted, and write it down before someone has to make that judgment under deadline pressure. Check what the tool does with your data, because internal communications contain organizational information you would not publish. And involve security early rather than late, since your channels are the ones attackers most want to borrow. Where employee awareness is part of the answer, security awareness training is more effective when comms and security deliver a consistent message rather than two competing ones, and running that training well is largely a communications problem in the first place.
Where Mindcore fits
Matt Rosenthal, Mindcore’s CEO, makes a point about impersonation that applies directly here: the attacks that succeed are almost never the technically clever ones. They are the ones that look normal, arriving through a channel people already trust, phrased the way that channel usually sounds.
That is why we treat internal communications as part of security posture rather than separate from it. Which platforms and drafting tools suit your organization is your call. What we contribute is the surrounding work: hardening the channels themselves, making sure an out of band path exists before it is needed, and helping your comms and security teams say the same thing about verification so employees are not choosing between two sets of instructions.
Frequently Asked Questions
Should we tell employees when a message was AI drafted?
There is no universal answer, but a consistent policy beats an ad hoc one. Many organizations settle on disclosing for routine operational content and never using AI drafting for messages carrying emotional weight, which sidesteps the question where it matters most.
How do we stop attackers impersonating our executives?
You cannot prevent the impersonation, so focus on making it ineffective. Establish clear channel norms for sensitive requests, make verification socially acceptable so junior staff feel able to check, maintain an out of band communication path, and be deliberate about how much executive audio and video you publish.
Will AI translation work for internal communications?
For routine content, generally yes, and it has become fast enough to change what is feasible. For HR policy, legal, and safety content, keep human review, because a subtle mistranslation in those categories carries consequences that outweigh the time saved.
What should we measure instead of open rates?
Reach among hard to reach populations, follow up question volume after an announcement, time to awareness, and actual behavior change. Open rates measure delivery, which is the least interesting thing about a message.
Does internal comms belong in our incident response plan?
Yes, and it is commonly missing. During an incident, how quickly and reliably you can reach everyone becomes an operational capability. That includes deciding in advance how you communicate if your primary channel is the thing that is compromised.
Ready to check whether your channels can be trusted?
Most organizations have never tested what happens if their main internal channel is spoofed or unavailable, and the answer matters most on the day it is least convenient to work out.
If you want a review of your communication channels and the verification norms around them, book a free strategy call with our team.

