The Verification Habits I Rely On Whenever I Suspect an AI Scam
The Verification Habits I Rely On Whenever I Suspect an AI Scam
I used to think spotting an AI scam was mostly about noticing the right warning signs, a slightly off voice, a video that blinked strangely, a message that felt a bit too polished. I still watch for those things, but I've learned they're not enough on their own anymore. AI tools have gotten good enough that spotting something wrong by instinct alone is a coin flip at best. What actually protects me now isn't sharper instincts, it's a small set of verification habits I fall back on the moment something feels even slightly off, habits that don't depend on catching a technical flaw in whatever I'm looking at. These are the ones I actually use, in the order I actually reach for them.
Why Suspicion Alone Isn't Enough Anymore
For years the advice was to trust your gut, and for years that mostly worked, because faked audio and video used to carry obvious tells if you knew what to look for. That advantage has mostly disappeared. I've had a voice clone call almost catch me out despite knowing exactly what to listen for, because the tone, the pacing, even the small verbal habits were all convincingly right. That experience is what pushed me away from relying on instinct as my main defence. If something sounding or looking real can still be fake, then the only thing left that actually works is a verification step that doesn't depend on how convincing the fake is in the first place. That's the shift in thinking behind everything else here, treat suspicion as the trigger for a process, not as the judgement itself.

Calling Back on a Number I Already Trust
If a call, text, or voicemail claims to be from my bank, a supplier, or anyone else asking me to act, I don't call back on any number the message itself provides, ever. Scammers can spoof caller ID and hand you a "helpful" callback number that just connects you straight back to them. What I do instead is hang up and dial a number I already had saved before the call came in, from a bank statement, an old invoice, or the official website I typed in myself. This one habit alone closes off almost every version of this scam, because it removes the scammer's ability to control which number I end up calling. It costs me an extra thirty seconds and it's saved me more than once.
The Family Code Word That Beats Any Voice Clone
This is the habit I'm most glad I set up before I actually needed it. My close family and I agreed on a private code word, something unrelated to anything a scammer could guess or scrape from social media, that gets used specifically for any call claiming to be an emergency involving money or urgent help. A voice clone can copy tone and cadence almost perfectly, but it can't produce a piece of information that was never said out loud anywhere public. If a panicked call comes in asking for money and the code word doesn't come up correctly when I ask for it, that's the end of the conversation as far as I'm concerned, no matter how real the voice sounds. I'd genuinely recommend this to anyone with older relatives specifically, since they tend to be targeted with exactly this kind of urgent, emotional call.
Asking for Something Scripted Can't Predict
Beyond the code word, I've got a habit of asking for something in the moment that a scripted or cloned interaction can't anticipate, referencing a specific shared memory, asking an oddly specific follow-up question, or simply asking the person to do something live and unscripted rather than continuing to read from whatever they've prepared. This works because most AI-assisted scams, however good the voice or video quality, are still built around a script or a limited set of responses. Pushing the conversation somewhere the scammer didn't plan for tends to expose the gap fast, either the responses get vague and evasive, or the call ends abruptly. I've written separately about the specific AI scam techniques I think are actually getting harder to spot, which covers the technical side of why this gap still exists even as the audio and video quality keeps improving.
Checking Official Channels Directly Instead of Trusting the Message
For anything that claims to be from a bank, a government department, or a company I actually use, I go directly to their official app or a web address I typed myself, never a link or number provided in the message that raised my suspicion. This applies whether the message arrived as an email, a text, or something that looked like a genuine account notification. One thing that's made this easier day to day is that a password manager like NordPass will only auto-fill your login details on the actual domain it's saved against, so if I land on a convincing fake site and nothing auto-fills, that's an immediate and reliable signal that something's wrong, well before I'd have spotted it by eye. It's a small extra layer, but it catches the cases where everything else about the fake looked right.
None of these habits require any special technical skill, and none of them depend on me correctly spotting a flaw in whatever I'm looking at, which is exactly why I trust them more than instinct alone these days. A callback number I already had, a code word only my family would know, a question a script can't answer, and going to the source directly rather than trusting the message in front of me. Between them, they cover almost every AI-assisted scam I've come across so far, and they're simple enough that I've been able to get my own family using them too. If you want a second, independent source on the latest AI-driven scam patterns to watch for, the NCSC publishes ongoing guidance on deepfakes and AI-enabled fraud, and my free Safety Toolkit covers the rest of what I'd recommend if you want to get these habits properly in place.
