For Practice makes safe, a free place to practise spotting phishing and online scams, my AI and I also built a page on asking an AI for advice. At its heart are three steps: a screenshot, not the link; black out personal details; ask specific questions. For non-experts that's exactly right — short, no jargon.
This is why the rules are what they are. Every one of them is about context: what the AI gets to see, and what slips past it.
What the AI is good at here
Scams follow patterns: time pressure, threats, a sender who doesn't match the name, a link that leads somewhere other than it claims. Language models usually spot such patterns well when they're visible. They're available around the clock, never get impatient, and explain instead of just warning.
What comes out, though, is an assessment, not a check. The model only sees what you show it. It can't query the sender's mail server, look into your account or ring your bank. So "looks genuine" is not a green light — where money, passwords or remote access are involved, a second route always belongs in the picture.
A screenshot, not text: what's in the context decides the answer
Copy the text of an email into a chat and you copy more than you can see: white text on a white background, tiny characters, hidden paragraphs. That's exactly where instructions to the AI can hide — the trade calls it prompt injection. In 2025, 0DIN showed what that looks like (“Phishing for Gemini”): hidden text in an email got a mail assistant's summary feature to display an invented security warning, phone number included. The human saw a harmless email; the AI read an order.
A screenshot, by contrast, mostly contains only what a human can see too. It isn't watertight: in October 2025, Brave showed (“Unseeable prompt injections in screenshots”) an AI browser reading instructions out of a screenshot that were practically invisible to people — faint light-blue text on a yellow background. The rule still stands. It shrinks the problem; it doesn't solve it. For me, that's what lostcontext is about: what's in the context decides the answer — even if nobody sees it.
You black out details because the image ends up with the AI provider. Your name, customer and contract numbers, bank details and address stay out; the sender, the subject, the link's text and whatever you're being asked to do stay in. And one more rule follows from the context problem: if the AI itself offers a phone number or a link "to secure your account", that's exactly what should make you suspicious. Your bank's number is on your card, not in a chatbot's answer.
Don't let it click
Newer agents and AI browsers don't just read, they act: open links, fill in forms, go shopping. In August 2025, Guardio put that to the test (“Scamlexity”): an AI browser bought something in a fake shop and followed the link in a phishing email without asking. That's why the practice page also says: don't hand the AI the link "just to check". Decisions about money and passwords stay with people — more on that in the agent guardrails.
The quiet helpers
Not every helper is a chat. The scareware blocker in Microsoft Edge recognises full-screen scam pages — fake blue screens, supposed police lockouts — with an image model on the device, and is switched on by default on most Windows and Mac computers (Edge blog, 31 October 2025). Chrome does something similar against tech-support scams, with Gemini Nano on the device — though only with "Enhanced protection" turned on (Google, 8 May 2025). Both work locally — a good example of "small model, clear job".
Three questions instead of one
"Is this a scam?" is the obvious question — and the weakest. Three work better: What speaks for it, and what against? What can you not check? How do I check it by a route I already know?
The second matters most: it pulls the model's limits into the answer instead of hiding them. The third leads out of the chat — to your bank's app, to the number on your card, to the parcel tracking you open yourself.
Practise, don't just ask
An AI as a second opinion is good. Knowing the patterns yourself before the next message arrives is better. That's what Practice makes safe is for: a simulated inbox, a simulated phone, pop-ups and calls to practise on without risk — and, on the page “Asking AI for advice”, templates to copy that ask exactly these questions.
/compact — the essentials when context is tight:
An AI can be a good second opinion on a suspicious message: it spots patterns like time pressure, fake senders and foreign link targets, and explains them. But its answer is an assessment, not a green light, because it only sees what you show it. Copied text can carry hidden instructions to the AI (prompt injection), so use a screenshot rather than text or a link — that shrinks the problem but doesn't solve it. Don't let agents or AI browsers click anything; money and passwords stay with people. Instead of "Is this a scam?", ask three questions: What speaks for it and against it? What can you not check? How do I check it by a route I already know?