Artificial intelligence has rapidly moved from “interesting” to “essential” in many businesses. In professional service firms, tools like Copilot and ChatGPT are already being used to draft documents, support research, summarise client communications and even assist with compliance tasks.

It’s no surprise that this creates a mindset shift, if AI can handle complex written work, why not let it take on smaller, technical jobs too?

One of the most common examples we’re now seeing is password generation.

It feels logical. Ask AI for a strong password, and it delivers a long string of characters filled with symbols, uppercase letters, numbers and random-looking sequences. It ticks all the visible boxes.

But this is where things start to become risky.

Why “looking secure” isn’t the same as being secure

Password strength is often misunderstood.

Most people, including experienced professionals, judge a password based on how it looks. If it’s long, complex and contains mixed characters, it’s assumed to be safe.

Even many online password checkers reinforce this assumption.

However, these tools only measure visible complexity. They don’t assess the underlying structure or unpredictability of the password.

In regulated industries, this distinction matters. Security isn’t about appearance, it’s about verifiable strength, especially when auditors, insurers or regulators become involved.

The problem with AI-generated passwords

AI tools are built using large language models. These systems are fundamentally designed to generate text that appears natural, structured and meaningful.

That’s exactly why they’re useful.

But it’s also exactly why they are unsuited to creating secure passwords.

Strong password security depends on one key principle: randomness.

AI, by design, does not produce true randomness. Instead, it predicts what comes next based on patterns learned from existing data.

When researchers tested AI-generated passwords, they found:

  • Repeating structural patterns
  • Similar formatting across multiple outputs
  • Occasional duplicates
  • A noticeable avoidance of character repetition

That last point is particularly important.

True randomness often includes repetition, sometimes even in clusters. The absence of this suggests that the password is being shaped by rules rather than generated unpredictably.

Why this creates real business risk

From a compliance and governance perspective, predictable patterns introduce unnecessary risk.

Attackers use advanced tools to exploit patterns faster than ever before. What looks complex to a person can still be vulnerable to automated brute-force or pattern-based attacks.

In regulated sectors such as legal, financial and insurance services, the implications are significant:

  • Exposure of client data
  • Breach of data protection obligations
  • Increased cyber insurance risk
  • Reputational damage
  • Potential regulatory penalties

This is why foundational practices still matter. Even as technology evolves, basic security controls remain critical, something explored further in strategies for preparing for cyber threats

Entropy: The hidden measure behind real security

The technical term that sits behind all of this is entropy — a measure of unpredictability.

High entropy means a password is difficult to guess because it lacks patterns.

Low entropy means there are predictable elements that reduce the number of attempts required to crack it.

AI-generated passwords consistently show lower entropy than truly random ones.

This means that even if they appear strong on the surface, they are statistically easier to break.

Why password managers are still the gold standard

If AI isn’t the answer, what should businesses do?

The most effective approach hasn’t changed: Use a trusted password manager with a built-in generator.

These systems are specifically designed for security and use cryptographic randomness, mathematical processes engineered to produce unpredictable results.

They also provide additional benefits:

  • Secure storage
  • Controlled access across teams
  • Easy onboarding and offboarding
  • Policy enforcement
  • Reduced human error

This aligns with best practice guidance seen in modern cyber security frameworks and day-to-day operational advice. It also reduces the risk of staff using browsers to store passwords which creates hidden risks

The danger of convenience-led decisions

One of the biggest risks businesses face today isn’t a lack of tools, it’s overconfidence in them.

AI is powerful, but it encourages shortcuts.

Shortcuts in security are rarely neutral. They either strengthen your defences or quietly weaken them.

In this case, relying on AI for password generation falls into the second category.

The danger is subtle because nothing appears broken. Systems still work. Logins still succeed. There are no immediate warnings.

But underneath, you’re introducing a vulnerability.

Aligning password practices with business governance

For professional firms, password management shouldn’t be left to individual staff habits.

It should be part of a wider governance framework.

This includes:

  • Defined password policies
  • Mandatory use of password managers
  • Regular audit and review
  • Multi-factor authentication enforcement
  • Clear onboarding and offboarding procedures

When implemented properly, this creates consistency, something that is increasingly expected by insurers, regulators and clients alike.

As discussed in why old passwords are still unlocking systems, failing to manage credentials properly can leave businesses exposed long after they think risks have been removed

AI has a role, just not here

It’s important to be clear: this is not an argument against using AI.

In fact, AI can deliver real value across many areas of a business:

  • Documentation
  • Client communication
  • Knowledge summarisation
  • Productivity improvements

But security is different.

Security relies on predictability for defenders and unpredictability for attackers. AI excels at patterns. Security often demands the absence of them.

That’s why choosing the right tool for the right job matters.

Final thought: don’t confuse intelligence with security

AI feels intelligent. That can lead to misplaced trust.

But intelligence and security are not the same thing.

When it comes to protecting sensitive business and client data, the goal isn’t to be clever, it’s to be robust, consistent and defensible.

And that means avoiding tools that introduce patterns where unpredictability is essential.

If you’re unsure whether your current password approach meets modern security expectations, it’s worth reviewing it before it becomes a problem.

What next?

One of my passions is helping businesses to succeed and if I can help you save some money as well – even better. You can fill out our contact form, phone us or click on the appointment button below and let’s start a conversation to see if I can help your business. Our guarantee:

  • There are no hidden charges – this is a 100% free 15 minute consultation with no hidden charges.
  • We will never spam you or sell on your contact details.
  • We will treat your information with absolute confidentiality.
Cyber Security
A laptop screen displaying a Windows 11 update prompt, illustrating the risk of a convincing fake update targeting regulated professional firms.

Why a Routine Update Has Become a Board-Level Risk

For regulated firms, a routine software update should never become a compliance incident. Yet a highly convincing fake Windows 11 update is now fooling even experienced professionals, and a single click can expose client data. This post explains how the scam works, why it slips past security tools, and the governance-led steps every professional firm should take to stay protected and audit-ready.

AI, Best Practice
Illustration depicting AI-driven automation creating hidden blind spots in business decision-making processes, representing the governance challenges faced by regulated professional service firms

How AI Agents Cause Governance Blind Spots

AI agents are doing more than assisting your team, they're beginning to shape decisions and trigger actions across your firm. For regulated businesses, the question is no longer whether AI is involved, but whether you can explain and defend every outcome it influences. Here's how to close the governance gap before it becomes a compliance issue.

Productivity, Software
A professional reviewing Windows 11 updates on a laptop screen, symbolising improved productivity and reduced IT frustrations for regulated businesses

Windows 11 Is Finally Addressing What Has Been Frustrating Your Team

Constant new features are not what professional firms need from their operating system — they need reliability, consistency, and fewer distractions. Microsoft has recognised this, and the latest Windows 11 direction prioritises fixing real-world frustrations over adding experimental tools. From scaling back unnecessary AI, to smoother updates and a faster File Explorer, here is what is changing and why it matters for governance-focused businesses.

AI, Best Practice
An illustration depicting an emergency stop concept for artificial intelligence in a business setting, representing AI governance, risk control and compliance readiness for professional firms.

How Would You Stop AI in an Emergency?

If an AI tool in your firm did something it shouldn't: sent incorrect advice, exposed client data or triggered a compliance breach; could you intervene quickly and explain what happened to a regulator? For most professional firms, the honest answer is not confidently. This post explores why AI governance is now as critical as any other risk framework in your business, and what you can do about it today.