Scams used to be easier to catch because they were often badly made — stilted phrasing, a voice that didn't quite sound like the person it claimed to be, an email full of small grammar mistakes. AI tools have closed most of that gap, which means the old advice of "look for mistakes" catches noticeably less than it used to.

Voice cloning is the sharpest example: a scammer needs only a short public sample of someone's voice — a video, a voicemail greeting, a social media clip — to generate a convincing clone saying anything they type, in that person's actual voice. The classic version is a panicked call that sounds exactly like a family member claiming an emergency and asking for money urgently, and the emotional pressure to act fast is the actual attack, not the technology underneath it.

Fake support bots work the opposite way: instead of impersonating someone you know, they impersonate a company you already trust — a convincing chat window on a lookalike site, or a "customer service" number that comes up first in a search result but isn't the real company at all, staffed by an AI script designed to extract a password or payment details under the guise of "verifying your account."

AI-written phishing emails have lost the broken-English tell entirely — a modern phishing email can be grammatically perfect, personalized with real details scraped from a public profile, and styled to match a company's actual visual branding closely enough that a quick glance won't catch it.

The defense that still works against all three is the same one: verify through a separate, independent channel rather than trusting the contact method the message itself gave you. If a call claims to be a family member in trouble, hang up and call them back on the number you already have saved. If an email claims to be your bank, don't click its link — navigate to the bank's site yourself, the way you normally would. AI changed how convincing the bait looks; it didn't change that verifying independently still defeats it.