AI news story

Don't let an AI chatbot pick your password, ever

Are AI-generated passwords truly random? Research suggests AI passwords are far less secure than you might think.

  • LLMs
  • Source: ZDNet
  • Published: 2026-07-14

Editor's take

Recent research indicates that passwords generated by popular large language models (LLMs) like GPT-3.5, GPT-4, and Claude 2 exhibit predictable patterns that compromise their security. These models, when prompted to create passwords, frequently rely on common sequences, dictionary words, and easily calculable substitutions rather than true randomness.

This finding is significant because it directly impacts the security posture of individuals and organizations relying on AI tools for password generation. The widespread adoption of LLMs for even mundane tasks like password creation means a large attack surface could be inadvertently weakened, making brute-force or dictionary attacks more effective against these seemingly complex, yet predictable, credentials.

Future investigations should focus on whether specific LLM architectures or fine-tuning techniques can mitigate this predictability. It will also be crucial to observe if security advisories are issued by LLM providers or cybersecurity firms, and if password generation best practices are updated to explicitly warn against using current AI chatbots for this purpose.