Artificial intelligence has rapidly moved from “interesting” to “essential” in many businesses. In professional service firms, tools like Copilot and ChatGPT are already being used to draft documents, support research, summarise client communications and even assist with compliance tasks.

It’s no surprise that this creates a mindset shift, if AI can handle complex written work, why not let it take on smaller, technical jobs too?

One of the most common examples we’re now seeing is password generation.

It feels logical. Ask AI for a strong password, and it delivers a long string of characters filled with symbols, uppercase letters, numbers and random-looking sequences. It ticks all the visible boxes.

But this is where things start to become risky.

Why “looking secure” isn’t the same as being secure

Password strength is often misunderstood.

Most people, including experienced professionals, judge a password based on how it looks. If it’s long, complex and contains mixed characters, it’s assumed to be safe.

Even many online password checkers reinforce this assumption.

However, these tools only measure visible complexity. They don’t assess the underlying structure or unpredictability of the password.

In regulated industries, this distinction matters. Security isn’t about appearance, it’s about verifiable strength, especially when auditors, insurers or regulators become involved.

The problem with AI-generated passwords

AI tools are built using large language models. These systems are fundamentally designed to generate text that appears natural, structured and meaningful.

That’s exactly why they’re useful.

But it’s also exactly why they are unsuited to creating secure passwords.

Strong password security depends on one key principle: randomness.

AI, by design, does not produce true randomness. Instead, it predicts what comes next based on patterns learned from existing data.

When researchers tested AI-generated passwords, they found:

  • Repeating structural patterns
  • Similar formatting across multiple outputs
  • Occasional duplicates
  • A noticeable avoidance of character repetition

That last point is particularly important.

True randomness often includes repetition, sometimes even in clusters. The absence of this suggests that the password is being shaped by rules rather than generated unpredictably.

Why this creates real business risk

From a compliance and governance perspective, predictable patterns introduce unnecessary risk.

Attackers use advanced tools to exploit patterns faster than ever before. What looks complex to a person can still be vulnerable to automated brute-force or pattern-based attacks.

In regulated sectors such as legal, financial and insurance services, the implications are significant:

  • Exposure of client data
  • Breach of data protection obligations
  • Increased cyber insurance risk
  • Reputational damage
  • Potential regulatory penalties

This is why foundational practices still matter. Even as technology evolves, basic security controls remain critical, something explored further in strategies for preparing for cyber threats

Entropy: The hidden measure behind real security

The technical term that sits behind all of this is entropy — a measure of unpredictability.

High entropy means a password is difficult to guess because it lacks patterns.

Low entropy means there are predictable elements that reduce the number of attempts required to crack it.

AI-generated passwords consistently show lower entropy than truly random ones.

This means that even if they appear strong on the surface, they are statistically easier to break.

Why password managers are still the gold standard

If AI isn’t the answer, what should businesses do?

The most effective approach hasn’t changed: Use a trusted password manager with a built-in generator.

These systems are specifically designed for security and use cryptographic randomness, mathematical processes engineered to produce unpredictable results.

They also provide additional benefits:

  • Secure storage
  • Controlled access across teams
  • Easy onboarding and offboarding
  • Policy enforcement
  • Reduced human error

This aligns with best practice guidance seen in modern cyber security frameworks and day-to-day operational advice. It also reduces the risk of staff using browsers to store passwords which creates hidden risks

The danger of convenience-led decisions

One of the biggest risks businesses face today isn’t a lack of tools, it’s overconfidence in them.

AI is powerful, but it encourages shortcuts.

Shortcuts in security are rarely neutral. They either strengthen your defences or quietly weaken them.

In this case, relying on AI for password generation falls into the second category.

The danger is subtle because nothing appears broken. Systems still work. Logins still succeed. There are no immediate warnings.

But underneath, you’re introducing a vulnerability.

Aligning password practices with business governance

For professional firms, password management shouldn’t be left to individual staff habits.

It should be part of a wider governance framework.

This includes:

  • Defined password policies
  • Mandatory use of password managers
  • Regular audit and review
  • Multi-factor authentication enforcement
  • Clear onboarding and offboarding procedures

When implemented properly, this creates consistency, something that is increasingly expected by insurers, regulators and clients alike.

As discussed in why old passwords are still unlocking systems, failing to manage credentials properly can leave businesses exposed long after they think risks have been removed

AI has a role, just not here

It’s important to be clear: this is not an argument against using AI.

In fact, AI can deliver real value across many areas of a business:

  • Documentation
  • Client communication
  • Knowledge summarisation
  • Productivity improvements

But security is different.

Security relies on predictability for defenders and unpredictability for attackers. AI excels at patterns. Security often demands the absence of them.

That’s why choosing the right tool for the right job matters.

Final thought: don’t confuse intelligence with security

AI feels intelligent. That can lead to misplaced trust.

But intelligence and security are not the same thing.

When it comes to protecting sensitive business and client data, the goal isn’t to be clever, it’s to be robust, consistent and defensible.

And that means avoiding tools that introduce patterns where unpredictability is essential.

If you’re unsure whether your current password approach meets modern security expectations, it’s worth reviewing it before it becomes a problem.

What next?

One of my passions is helping businesses to succeed and if I can help you save some money as well – even better. You can fill out our contact form, phone us or click on the appointment button below and let’s start a conversation to see if I can help your business. Our guarantee:

  • There are no hidden charges – this is a 100% free 15 minute consultation with no hidden charges.
  • We will never spam you or sell on your contact details.
  • We will treat your information with absolute confidentiality.
AI, Best Practice
An illustration depicting an emergency stop concept for artificial intelligence in a business setting, representing AI governance, risk control and compliance readiness for professional firms.

How Would You Stop AI in an Emergency?

If an AI tool in your firm did something it shouldn't: sent incorrect advice, exposed client data or triggered a compliance breach; could you intervene quickly and explain what happened to a regulator? For most professional firms, the honest answer is not confidently. This post explores why AI governance is now as critical as any other risk framework in your business, and what you can do about it today.

0

Best Practice, Cyber Security
Dark background with cascading green digital code characters and bold white text asking Is Your Data less secure than you think, with the word less highlighted in orange, representing the hidden gap between perceived and actual data security in business

Is Your Data Security Keeping Pace With Your Business?

Most professional service firms believe their data security is under control — but confidence and compliance readiness are not the same thing. As cloud platforms, legacy systems and AI tools increase complexity beneath the surface, the gap between perceived security and actual governance grows. This post examines the questions every regulated firm should be asking about where data lives, who has access, and whether the answers would satisfy an auditor.

0

AI
Business professional reviewing Microsoft Copilot features on a Windows 11 screen in a professional office environment evaluating AI productivity tools for regulated firms

Is Microsoft Copilot Really the Top Productivity App in Windows 11?

Microsoft has declared Copilot the number one productivity app in Windows 11. For regulated firms handling sensitive client data and strict compliance requirements, bold marketing claims deserve careful scrutiny. Real productivity for professional services teams depends on solid foundations: organised files, reliable processes, and proper governance, not just a new AI assistant. Before adopting any tool, the smarter question is where does your team actually waste time?

0