The internet now mixes human voices with AI voices so well that a quick ’that sounds real’ is no longer enough. Scammers use AI voice cloning, deepfake video, and chatbot scripts to impersonate loved ones, bank staff, government workers, and romantic partners. These attacks have moved from theory to everyday threat. Learning how to verify AI vs human online before you act cuts off many scams at the start. Urgency is the enemy of verification. This guide gives you concrete checks.
The financial damage is increasing. The FBI Internet Crime Complaint Center receives tens of thousands of reports each year involving impersonation, romance fraud, and business email compromise. Many of those reports now include synthetic media. Official agencies recommend treating any unsolicited contact as unverified until you prove otherwise. The FTC says scammers want you to move fast and stay quiet. That pressure alone is a warning sign, whether you are on a phone call, video chat, or text thread.
You do not need to become a forensic expert to spot many AI interactions. You need a short list of behavioral tests and a habit of pausing before trust. Some signs are technical, like video glitches around the mouth or robotic audio artifacts. Others are human, like a grandchild refusing to answer a private question they would know. In the next sections, we walk through seven steps. Each step builds on the one before it. For more context on visual fraud, review AI deepfake video scams.
If you have already sent money or shared a password, do not let shame slow you down. File a report with the FBI IC3 and go to IdentityTheft.gov for recovery steps. Then use this guide to stop follow-up attacks. Scammers target the same person twice because they know trust was broken once. Your next verification habit is your strongest defense.
What You’ll Need
- Smartphone or computer with camera
- Private code word shared with family
- Known phone numbers saved in advance
- Access to official websites and banking apps
How Do You Verify AI vs Human Online?
- Pause and label every urgent request as unverified
The first step is not a technical tool. It is a decision to pause. AI-assisted scams depend on emotional pressure. A faked grandson may say he needs bail money within the hour. A fake bank agent may claim your account will close in 30 minutes. A romance bot may demand proof of love by wiring money. In each case, the AI or human scammer wants you to skip verification. Say this out loud: ‘I do not verify people under threat.’ Then take a breath. Write down the date, time, and claim. This simple record often reveals contradictions later. For more on synthetic romance tactics, see AI romance scam red flags.
Urgency does not prove truth. Real banks, police, and family emergencies can wait a few minutes for a callback. Scammers know that delays kill their scripts. If someone says you must stay on the line, that is a red flag. Treat it as evidence against the caller. A calm human who is who they claim to be will generally welcome a callback. An AI voice clone or a scammer will resist. This step connects to the next one because you need a private challenge ready before you respond.
Some AI attacks arrive by text or email, not voice. The same rule applies. Do not click a link because a message says your account is compromised. Open a new browser tab and log in through the official website. If you are unsure, forward the message to the company using a contact method from your statement. For deeper signs in text, see how to identify AI phishing emails. The pause itself blocks many credential theft attempts.
- Create a private code word and challenge question
A code word is a short phrase only your trusted circle knows. It can be a random object or a nonsense phrase. Pick something not on social media. Write it down only in a secure place. Then tell family members to ask for it during any emergency call. If the person cannot produce it, do not engage further. This works against AI voice cloning because even a perfect synthetic voice lacks private context that was never posted online. Scammers scrape public data. A private code word stays private.
For broader contacts, use a challenge question with a specific answer. Avoid questions with answers that exist in public records. ‘What street did I grow up on?’ is weak. ‘What is the name of the stuffed bear I kept in my first apartment?’ is stronger, but only if you never posted about it. Ask for the answer in a way that requires recall, not yes or no. A live human can hesitate and still answer. A bot may repeat your question or give a generic response. Write down the response exactly.
Do not use the same code word for every service. Your bank should never ask for a secret family code word. That is for personal contacts. For businesses, you will verify through official channels in the next step. This code word is especially useful for parents and older relatives. Share it calmly, not during a crisis. If your family member is targeted by a AI voice cloning scam, the code word becomes a fast test. A scammer will often argue or improvise. That failure is your answer.
- End the contact and call back on a verified number
This is the strongest test for phone and voice scams. Hang up. Do not use a number the caller gave you. Do not use a link from a text. Find the official number from a statement, the back of your card, or the agency’s website. For family, call the person’s regular mobile number. For a bank, call the number printed on your card. For a government agency, go to the official site. If the original caller was real, they will understand. If they try to keep you on the line, that is a classic scam tactic.
For video call platforms, end the call and reconnect using a new meeting link you create yourself. Do not accept a link sent by text or email from the same person who contacted you. Compromised accounts can send legitimate-looking links. When you initiate the contact through a known directory, you reduce the chance of speaking with an impersonator. This also helps with AI deepfake video scams, because a fake video feed can be reused, but a live reconnection on your terms is harder to fake.
Document the callback. Note whether the person answers, what they say first, and whether their story matches. If the phone rings many times and a different person answers, stop. If the caller claims they cannot receive calls but can only make them, that is another red flag. Law enforcement and bank fraud teams do not operate that way. The CISA recommends verifying contacts through known channels before sharing sensitive information. This step alone stops many impersonation scams.
- Inspect voice and audio for cloning artifacts
AI voice clones have improved, but they still leave traces. Listen for a flat emotional tone that does not match the words. A panicked loved one may sound calm or slightly robotic. Notice unnatural pauses between sentences. Some clones have a metallic or compressed quality, especially on cheap phone lines. Ask the person to laugh, cough, or say a sentence with strong emotion. A real human will produce natural variation. A clone may repeat the phrase almost identically or produce a clipped response.
Pay attention to background noise. A real call from a family member often has street sounds, a TV, or a dog. An AI voice clone may be generated in silence or with generic background looped audio. Ask a question about the environment: ‘What is that noise behind you?’ A human can answer immediately. A bot may give a vague answer or ignore it. If the call came from an unknown number, that does not automatically make it fake. But combine that fact with the other checks.
Record audio only if it is legal in your area. Even without recording, you can ask the person to say the code word from Step 2. A clone that was trained on public audio can still mimic the voice, but it may miss private rhythm and slang. If you hear robotic repetition or the person dodges the code word, you are likely dealing with AI. For more detailed signs, see how to spot an AI voice cloning scam. This step leads into video checks because many scammers now move to video once you push back.
- Check live video for deepfake glitches and unusual behavior
A live video call is not automatic proof. Deepfake software can swap a face in real time, but it struggles with fast movement and partial occlusion. Ask the person to move their hand across their face slowly. A deepfake may blur or warp the nose, chin, or eyes. Ask them to turn their head sharply to the side. Some models fail at extreme angles. Watch the mouth. If lip movements do not match the words clearly, suspect synthetic video. Real video has small natural delays, but the mouth shapes should align.
Look at the eyes and hair. AI-generated faces sometimes show unnatural reflections in the eyes or a glassy stare. Hair strands may flicker at the edges. Check for mismatched lighting between the face and the room. If the person nods, look for jumps or frame skips. Many video meeting apps now compress video, so poor quality alone is not proof. But a pattern of glitches around the face is more suspicious. Ask the person to hold up two fingers. Deepfake models can struggle with extra fingers or hand-face interaction.
Use a simple behavioral test. Ask the person to look at a clock behind them and read the time. If the video is pre-recorded or generated, the response may not match the current time. Ask them to point to an object you name in their room. A real human will look around and point. A synthetic feed may not have a live camera view of that object. For broader deepfake warning signs, read AI deepfake video scams in 2026. If the video feed refuses to do any movement test, treat the call as unverified.
- Analyze text and email patterns for AI writing
AI text has gotten smoother, but it often lacks specific personal detail. Read messages for a generic helpful tone that sounds like a customer service script. Scammers use AI to generate phishing emails that are grammatically clean but vague. They may say ‘your account has been flagged’ without naming the last four digits of your card or your account type. Real companies often include specific transaction details. Ask for those details. A bot may dodge or produce another generic sentence.
Look for repetition and unusual phrasing. AI models repeat sentence structures. They may use ‘I understand your concern’ more than a real friend would. They may produce perfect grammar while the person you know writes informally. If a text claims to be from your teenager but suddenly uses semicolons and corporate language, call them. Do not keep texting. If an email from your boss asks you to buy gift cards and uses words like ‘kindly,’ pause. That is a known scam pattern. For detailed clues, see how to identify AI phishing emails.
Challenge the writer with a specific question. ‘What did we have for dinner last Tuesday?’ or ‘What is my dog’s name?’ A real person knows or says they forgot. A chatbot may give a safe reply or ask you to move the conversation to another channel. If the person refuses to answer a simple personal question, stop sharing information. Text messages and emails are also where scammers push links. Never click a login link inside an unsolicited message. Go to the site directly.
- Confirm through a second trusted method or official record
One channel is not enough. If you verified a voice by calling the known number, also send a message through a separate app you have used before. If you checked a video call, also ask another family member if they have spoken with the person today. Cross-checking breaks impersonation. A scammer may control one account, but controlling two or three trusted channels is much harder. For money requests, require two forms of confirmation: a phone call and a text from a number already saved in your phone.
For financial or legal matters, use official records. Log in to your bank account to see if a charge exists. Call the fraud line printed on your card. Check your credit report or account statements for unauthorized activity. If someone claims to be from a government office, call the agency using a number from its official website. The BBB Scam Tracker lets you search similar reports in your area. If others have reported the same script, that is strong evidence. This step connects to reporting and recovery if you already shared data.
If confirmation fails, stop contact and block the number or account. Then report what happened. Use the FTC for consumer scams and the FBI IC3 for internet crime. If you gave personal information, begin recovery at IdentityTheft.gov. You can also follow this step-by-step guide to report an AI scam. If you gave personal data, consider freezing your credit and helping older relatives with AI scam protections. Quick reporting helps others too. Scammers often reuse the same voice or script, so your report may prevent another victim.
Red Flags & Warnings
- 🚨 Never trust caller ID alone. Scammers spoof phone numbers to show your bank, a family member, or even the police.
- 🚨 Do not pay or send money because a voice or video says there is an emergency. Confirm with a second trusted person first.
- 🚨 Do not click links in unsolicited texts or emails to verify your identity. Open a new tab and use the official website instead.
- 🚨 A live video feed is not proof of a real person. Deepfake tools can swap faces in real time, so use movement and code word tests.
- 🚨 Never share one-time passcodes, recovery codes, or remote desktop access with someone who contacted you first.
- 🚨 Urgency and secrecy are control tools. If someone tells you not to tell anyone or to stay on the line, end the call.
Frequently Asked Questions
Can AI copy a voice from a short video?
Yes. AI voice cloning tools can build a convincing copy from a few minutes of public audio. That audio often comes from social media or voicemail. Keep private details and code words out of any public clip.
How can I tell if a video call is live or pre-recorded?
Ask the person to perform an unpredictable action, like holding up a specific number of fingers or pointing at an object behind them. A pre-recorded deepfake cannot respond to your current request. Look for mouth sync errors and blurring around the face during movement.
What should I do if I already sent money to an AI scammer?
Contact your bank or payment app immediately and ask to reverse the transaction. Then report it to the FTC and the FBI IC3. If you shared personal data, go to IdentityTheft.gov to start a recovery plan.
Can AI bots respond in real time with convincing answers?
Yes. Large language models can answer quickly and adjust to your words. They still tend to repeat generic phrases and avoid specific personal questions. Challenge them with a private question that is not available in public records.
Are there apps that detect AI voices or deepfakes reliably?
Some detection tools exist, but they are not perfect. New AI models can defeat older detectors. Use detection apps only as a supporting clue, not your only defense. Behavior checks like code words and callbacks are more reliable.
Should I use a family code word even if it feels awkward?
Yes. A code word is one of the strongest protections against AI voice cloning and family emergency scams. Set it up now, before a crisis. Make sure every family member knows to ask for it during any urgent request.
What Should You Remember?
- Pause first: Urgency is the main tool of AI and human scammers. Never verify under pressure.
- Use a code word: A private phrase that was never posted online defeats most voice clones.
- Call back on a known number: End the contact and dial a number from your own records, not the caller’s message.
- Test live video: Ask for head turns, hand movements, and real-time object checks to expose deepfakes.
- Challenge text: Ask specific personal questions and avoid clicking login links in unsolicited messages.
- Confirm twice: Use a second trusted channel or official record before sending money or sharing data.
- Report quickly: File reports with the FTC and FBI IC3 if you suspect an AI scam.
This article is for general educational information only and is not legal, financial, or professional security advice. Scam tactics evolve quickly, so verify current guidance with official sources like the FTC, FBI IC3, or CISA before acting. Some links may be affiliate links that support this site at no cost to you.