It’s no surprise that this creates a mindset shift, if AI can handle complex written work, why not let it take on smaller, technical jobs too?
One of the most common examples we’re now seeing is password generation.
It feels logical. Ask AI for a strong password, and it delivers a long string of characters filled with symbols, uppercase letters, numbers and random-looking sequences. It ticks all the visible boxes.
But this is where things start to become risky.
Why “looking secure” isn’t the same as being secure
Password strength is often misunderstood.
Most people, including experienced professionals, judge a password based on how it looks. If it’s long, complex and contains mixed characters, it’s assumed to be safe.
Even many online password checkers reinforce this assumption.
However, these tools only measure visible complexity. They don’t assess the underlying structure or unpredictability of the password.
In regulated industries, this distinction matters. Security isn’t about appearance, it’s about verifiable strength, especially when auditors, insurers or regulators become involved.
The problem with AI-generated passwords
AI tools are built using large language models. These systems are fundamentally designed to generate text that appears natural, structured and meaningful.
That’s exactly why they’re useful.
But it’s also exactly why they are unsuited to creating secure passwords.
Strong password security depends on one key principle: randomness.
AI, by design, does not produce true randomness. Instead, it predicts what comes next based on patterns learned from existing data.
When researchers tested AI-generated passwords, they found:
- Repeating structural patterns
- Similar formatting across multiple outputs
- Occasional duplicates
- A noticeable avoidance of character repetition
That last point is particularly important.
True randomness often includes repetition, sometimes even in clusters. The absence of this suggests that the password is being shaped by rules rather than generated unpredictably.
Why this creates real business risk
From a compliance and governance perspective, predictable patterns introduce unnecessary risk.
Attackers use advanced tools to exploit patterns faster than ever before. What looks complex to a person can still be vulnerable to automated brute-force or pattern-based attacks.
In regulated sectors such as legal, financial and insurance services, the implications are significant:
- Exposure of client data
- Breach of data protection obligations
- Increased cyber insurance risk
- Reputational damage
- Potential regulatory penalties
This is why foundational practices still matter. Even as technology evolves, basic security controls remain critical, something explored further in strategies for preparing for cyber threats
Entropy: The hidden measure behind real security
The technical term that sits behind all of this is entropy — a measure of unpredictability.
High entropy means a password is difficult to guess because it lacks patterns.
Low entropy means there are predictable elements that reduce the number of attempts required to crack it.
AI-generated passwords consistently show lower entropy than truly random ones.
This means that even if they appear strong on the surface, they are statistically easier to break.
Why password managers are still the gold standard
If AI isn’t the answer, what should businesses do?
The most effective approach hasn’t changed: Use a trusted password manager with a built-in generator.
These systems are specifically designed for security and use cryptographic randomness, mathematical processes engineered to produce unpredictable results.
They also provide additional benefits:
- Secure storage
- Controlled access across teams
- Easy onboarding and offboarding
- Policy enforcement
- Reduced human error
This aligns with best practice guidance seen in modern cyber security frameworks and day-to-day operational advice. It also reduces the risk of staff using browsers to store passwords which creates hidden risks
The danger of convenience-led decisions
One of the biggest risks businesses face today isn’t a lack of tools, it’s overconfidence in them.
AI is powerful, but it encourages shortcuts.
Shortcuts in security are rarely neutral. They either strengthen your defences or quietly weaken them.
In this case, relying on AI for password generation falls into the second category.
The danger is subtle because nothing appears broken. Systems still work. Logins still succeed. There are no immediate warnings.
But underneath, you’re introducing a vulnerability.
Aligning password practices with business governance
For professional firms, password management shouldn’t be left to individual staff habits.
It should be part of a wider governance framework.
This includes:
- Defined password policies
- Mandatory use of password managers
- Regular audit and review
- Multi-factor authentication enforcement
- Clear onboarding and offboarding procedures
When implemented properly, this creates consistency, something that is increasingly expected by insurers, regulators and clients alike.
As discussed in why old passwords are still unlocking systems, failing to manage credentials properly can leave businesses exposed long after they think risks have been removed
AI has a role, just not here
It’s important to be clear: this is not an argument against using AI.
In fact, AI can deliver real value across many areas of a business:
- Documentation
- Client communication
- Knowledge summarisation
- Productivity improvements
But security is different.
Security relies on predictability for defenders and unpredictability for attackers. AI excels at patterns. Security often demands the absence of them.
That’s why choosing the right tool for the right job matters.
Final thought: don’t confuse intelligence with security
AI feels intelligent. That can lead to misplaced trust.
But intelligence and security are not the same thing.
When it comes to protecting sensitive business and client data, the goal isn’t to be clever, it’s to be robust, consistent and defensible.
And that means avoiding tools that introduce patterns where unpredictability is essential.
If you’re unsure whether your current password approach meets modern security expectations, it’s worth reviewing it before it becomes a problem.
What next?
One of my passions is helping businesses to succeed and if I can help you save some money as well – even better. You can fill out our contact form, phone us or click on the appointment button below and let’s start a conversation to see if I can help your business. Our guarantee:
- There are no hidden charges – this is a 100% free 15 minute consultation with no hidden charges.
- We will never spam you or sell on your contact details.
- We will treat your information with absolute confidentiality.









