Need a strong password? Asking ChatGPT, Copilot, or another AI tool to generate one may seem convenient.
These tools can draft reports, summarize meetings, write emails, and produce code. Requesting a 16-character password with uppercase letters, numbers, and symbols feels like another useful shortcut.
The problem is that a password can look complex without being truly unpredictable.
Researchers testing AI-generated passwords found that many appeared strong at first. They were long, included varied characters, and earned high scores from common password-checking tools.
A deeper analysis revealed repeated structures, similar formats, and even duplicate results.
The reason comes down to how generative AI works.
Large language models predict likely sequences based on patterns in their training data. They are designed to produce plausible output, not cryptographically random output.
Secure password generation requires randomness.
One unusual finding was that the AI-generated passwords did not include repeated characters. That may sound safer, but genuine randomness can include repetition. Consistently avoiding it suggests the system is following learned patterns.
Researchers also assessed password entropy, which measures unpredictability. The AI-generated passwords scored lower than properly randomized 16-character passwords.
That can make them more vulnerable to brute-force attacks, where criminals test large numbers of possible combinations.
Standard password-strength meters may miss this weakness. They often assess visible features such as length, symbols, and numbers, but do not recognize the underlying patterns produced by an AI model.
Some newer AI tools now warn users not to rely on chat-generated passwords for sensitive accounts.
For stronger protection, use the generator built into a reputable password manager. These tools use cryptographic methods designed to produce unpredictable credentials.
AI can support many business tasks. Password creation should not be one of them.
Need help selecting and deploying a password manager for your team? We can help.