The Wording Patterns That Give Away an AI-Written Scam Message

Sep 03, 2026By Jay Kells
Jay Kells

A few months ago I got a message that stopped me mid-scroll, not because it looked suspicious but because it looked too good. No typos, no clumsy phrasing, no "Dear Valued Customer" giveaway. It read like it had been written by someone who genuinely cared about getting the tone right. That's exactly the problem. The old advice about spotting a scam by its bad grammar has quietly stopped working, and I think most people haven't caught up to that yet, myself included until that message made me sit up and actually think about why it felt so convincing.

Why "Bad Grammar Means Scam" Stopped Being Useful Advice


For years the safest tell was a clumsy sentence, a missing article, a word that didn't quite fit British English. That advice made sense when scam messages were being translated badly or copied from a template nobody had proofread. It doesn't hold anymore. A generative AI tool can produce fluent, grammatically correct, context-appropriate text in seconds, in whatever tone you ask for, and scammers have noticed exactly as quickly as everyone else has. Treating polished writing as a sign of legitimacy now works against you rather than for you, which is an uncomfortable habit to unlearn after years of being told the opposite.


The Over-Polished Tone That Actually Gives It Away


What I've started noticing instead is almost the opposite problem: messages that are too smooth. A real colleague, a real delivery company, a real bank, they all have a slightly inconsistent house voice, because different humans wrote different bits of it at different times, updated it in different years, and left in small quirks nobody bothered fixing. An AI-generated message tends to read as one continuous, evenly-paced voice from greeting to sign-off, with none of the small verbal tics a real person or a real long-standing company template usually carries. It's a subtle thing to describe but once you start looking for it, it's oddly noticeable, like a photo that's been smoothed just slightly too much, technically clean but missing the texture a genuine version would have.


Personalisation That's Detailed but Slightly Wrong


The other pattern I watch for is personalisation that's specific without being accurate. Scammers now have access to enough scraped or leaked data to drop your name, your rough location, or even a company you've actually used into a message convincingly. What gives it away is that the detail is often adjacent to the truth rather than exactly right, a delivery company you used two years ago rather than the one you're actually expecting a parcel from, or a job title that's close but not quite yours. A message that knows something about you but gets one specific fact slightly off is worth far more suspicion than one that's generic, because it tells you the detail was pulled from a dataset rather than known first-hand, and a real company checking its own records wouldn't make that particular kind of mistake.


Messages That Never Ask a Real Question Back


I've also noticed that AI-written scam messages tend to be strangely one-directional. They tell you something urgent and give you an instruction, but they rarely ask a genuine clarifying question the way a real exchange would. A real courier query, a real colleague chasing an invoice, a real customer service reply usually has some back-and-forth quality to it, referencing something specific you said or did earlier in an actual thread. A scripted message, however well-written, is built to deliver a payload and move you toward a link or a reply, not to actually have a conversation, and that structural giveaway survives even when the wording itself is completely flawless.


How I Actually Check Before I Reply to Anything Like This


None of this replaces basic verification, it just tells me when to slow down and go looking for it. If a message claims to be from a company, I go to that company through a channel I already trust rather than anything in the message itself, typing the website address in myself or calling a number from a previous genuine bill rather than anything supplied in the message. Keeping decent security software running in the background helps too, since something like Bitdefender will often flag a malicious link before I even get to the point of deciding whether the wording felt off in the first place. These are close to the simple checks I already run whenever something feels engineered rather than organic, just applied specifically to how a message is worded rather than what it's actually asking me to do.


Why I Still Don't Rely on Spotting the Wording Alone


I want to be honest that this is a moving target. The tells I've described here are true today and may not be reliable in a year, because the techniques scammers use keep evolving roughly as fast as the tools that generate them do. Wording analysis is a useful early filter, not a verdict, and I never let a message pass just because it happened to feel a bit clumsy or fail one of these checks. The habit that actually protects me is verifying through a channel I chose myself, every single time something asks me to act quickly, regardless of how convincing or how polished the writing turns out to be.


If you want a second opinion on what to watch for more broadly, NCSC keeps genuinely current guidance on this, and my free Safety Toolkit walks through the verification habits I rely on day to day.