In mid-May, Abnormal AI launched Transforming in Public, a public gallery of internal AI workflows built by employees across sales, marketing, recruiting, and product. It reads as real internal AI adoption and a recruiting funnel at the same time, and both readings are correct. The wrinkle worth flagging: a company that sells behavioral AI to stop social engineering is now publishing a detailed map of its own tools, teams, and named builders, which is precisely the reconnaissance a targeted attacker wants. Expect other companies to copy the format; a few should think harder about what they’re giving away.
Most “we’re an AI-first company now” announcements are a LinkedIn post and a Copilot license. Abnormal AI did something stranger: it built a public website where you can watch individual employees rebuild their own jobs with AI, build by build, with names attached. abnormal.ai/transform went live in mid-May, roughly two months ago, alongside a manifesto blog post from CEO Evan Reiser. The framing is a dare: “Every company faces a choice: transform for real, or perform transformation theater.”
What they actually shipped
The site is a catalog of real internal tools, organized by function. A few from the current lineup:
- Map the Room: a “vibecoded” Cowork skill from an SDR-operations builder that drafts an account org chart on demand and sorts contacts by MEDDIC role, so a rep can see who they know and where the gaps are.
- CSM Meeting Digest: an AI PM rebuilt a meeting-prep bot into a daily digest that rolls every upcoming customer call into a single embedded Google Doc two days out.
- Plus Salesforce Pipeline Prediction, an AI Marketing Campaign series, an Account Prioritizer, and an Enterprise Context Layer from product development.
Reiser’s stated thesis is that Abnormal built its actual product on one contrarian idea eight years ago (learn what “normal” looks like inside an org, flag the abnormal) and is now pointing the same first-principles thinking at its own operations. Every employee, “regardless of role,” gets the best available AI tools plus enablement, which he calls the company’s highest-ROI investment. The people featured span every function, from recruiters to sales reps to product managers, and the site leans on that breadth.
The two reasons, and the real one
Abnormal gives two reasons for doing this in the open. The first is accountability: customers and employees are trusting the company’s AI competence, and publishing the work keeps it honest. The second is recruiting, and Reiser is refreshingly blunt about it. “The work is the pitch; Transforming in Public is the proof.” The closing line of the manifesto is a filter: “Abnormal isn’t for everyone. We’re not the place to come for a comfortable seat.”
Read the site for ten minutes and the weighting is obvious. This is a recruiting funnel wearing a transparency costume, and a good one. Most engineering-brand content is abstract (“we value builders”); this is concrete evidence that a recruiter or an SDR at this specific company shipped a working tool last week. For a candidate deciding between employers who all claim to be AI-native, a browsable proof-of-work gallery is a sharp differentiator. The company’s own CISO, Patricia Titus, amplified it on launch day.
There’s a mild irony in a page that declares war on “transformation theater” being, itself, a highly produced marketing artifact. But the builds look genuinely real, with named employees and specific tools, so the honest verdict is that it’s both: real adoption and a content engine built on top of it. That combination is the interesting part, and it’s why the format will spread.
The part the marketing page doesn’t mention
Here’s where a security blog has to raise its hand.
Abnormal sells behavioral AI that detects social engineering: business email compromise, account takeover, vendor fraud, the whole family of attacks that work by impersonating a trusted insider convincingly. Those attacks run on reconnaissance. An attacker’s hardest job is learning who does what, which tools a target uses, who talks to whom, and what an internal request is supposed to sound like.
Transforming in Public hands a lot of that over for free. It names employees and their functions. It says the sales org runs on MEDDIC and lists the tools they’ve wired together. It reveals that customer-success prep flows through a specific bot into Google Docs, that pipeline forecasting leans on a named Salesforce integration, and that reps use a Cowork skill to build org charts. Cross-reference the named builders with LinkedIn and you have a targeting graph with roles, workflows, and vocabulary attached.
A pretext like “hey, following up on the CSM Meeting Digest for the Acme call, can you re-share the doc?” lands very differently when the attacker already knows the tool exists, what it does, and who owns it. Detailed public documentation of internal workflows is an OSINT gift to exactly the impersonation attacks Abnormal’s own product is built to stop.
To be fair, none of this is a breach, and none of it is secret in the way credentials are. Determined attackers assemble this picture anyway from LinkedIn, conference talks, and job postings. Abnormal has just collapsed weeks of that work into one indexed, well-organized page. The company presumably decided the recruiting upside beats the recon downside, and given its own detection product sits in the inbox, that’s a defensible bet for this company. The concern is the imitators. Every org copying this format has the same attack surface and, in most cases, none of Abnormal’s detection layer watching the front door.
Why it matters
Publishing internal AI experiments as a live content stream is a genuinely new move, and it works because the raw material (people rebuilding their jobs with agents and skills) is finally interesting enough to watch. It’s a smarter version of the engineering blog, tuned for a moment when “how does your team actually use AI” is the question every builder is asking.
It’s also a small case study in a tension this blog keeps circling: the same transparency that builds trust and pulls in talent also feeds the reconnaissance layer of modern social engineering. Abnormal can probably run this play safely. If your company decides to copy it, put someone from security in the room before you publish the org chart.
Sources
- We’re Transforming in Public: Evan Reiser, Abnormal AI, May 14, 2026
- Transforming in Public gallery: Abnormal AI
- Abnormal Security Rebrands to Abnormal AI: press release, April 16, 2025
- Patricia Titus (CISO) on the launch: LinkedIn