WhatsApp’s AI Scam Shield Won’t Warn You About People You Know

WhatsApp Scam Alert: Meta’s New On-Device AI Warns Users About Suspicious Messages

Meta has introduced a new WhatsApp security feature called Scam Alert, designed to help users spot suspicious messages before they get tricked. The company shared a technical overview of the feature on August 12, explaining how it uses artificial intelligence while keeping message privacy intact.

Unlike many online safety tools that send data to cloud servers for analysis, WhatsApp Scam Alert works directly on the user’s phone. When the feature is enabled, WhatsApp downloads a small AI model to the device. This model checks incoming messages against patterns commonly found in reported scams, including suspicious phrasing, conversation structures, and tactics often used by fraudsters.

The key point is privacy: the message content does not leave the phone for this scam detection process. WhatsApp’s end-to-end encryption remains in place, meaning only the sender and recipient can read the actual message.

If the AI model believes a message may be part of a scam, WhatsApp displays a warning inside the chat. Only the recipient sees this alert. The sender is not notified, and WhatsApp does not automatically report the conversation to Meta.

After receiving a warning, the user can choose what to do next. They can block the sender, report the chat, or continue the conversation if they believe the message is safe. Reporting only happens if the user actively selects the report option.

However, there is one major limitation: Scam Alert only checks messages from people who are not saved in the user’s contacts.

That means messages from friends, family members, coworkers, or anyone already in the address book are not scanned by the AI model. This is important because many WhatsApp scams rely on compromised accounts. If a scammer takes over the account of someone you know, the fraudulent message may appear to come from a trusted contact. In that situation, Scam Alert may not warn you at all.

This creates a clear gap in protection. Some of the most convincing scams happen when attackers impersonate someone familiar, such as a relative asking for urgent money or a friend claiming to have a new number. If the account is already trusted, the new feature may remain silent.

Another feature could also become a weak point. If WhatsApp shows a warning and the user believes it is incorrect, they can mark the chat as trustworthy. Once that happens, the warning disappears permanently for that contact.

This makes the experience smoother for legitimate conversations, but it also introduces risk. Scammers often pressure victims into making quick decisions. If a fraudster convinces someone that the warning is a mistake, the user may mark the chat as safe and never receive another alert for that contact again.

Users who mark a chat as trustworthy may also choose to send the last five received messages to WhatsApp voluntarily. This is optional and does not happen automatically.

Meta is also trying to make Scam Alert more transparent than typical AI-based security tools. Each version of the AI model is entered into a public registry with a checksum before deployment. The signature is handled by Cloudflare, and Meta says it does not have the key needed for that signing process.

The model weights are also published so researchers can review whether the AI is actually focused on detecting scams rather than doing anything broader. This is meant to build trust and allow independent experts to verify how the system works.

WhatsApp users will also be able to view a record of Scam Alert activity. Under the account information section, users can request details showing which messages were checked and which model version was active at the time.

Meta says statistics about warnings and user responses are processed in isolated computing environments. Before the company sees this data, it is aggregated and altered in a way that prevents it from being tied to individual users.

For now, Scam Alert is not widely available. The feature is currently being tested in a limited beta alongside Meta’s bug bounty program. Meta has not confirmed when it will roll out to all WhatsApp users or which countries will receive it first.

Until Scam Alert becomes available, users should continue following basic anti-scam habits. If someone asks for money, claims to have a new phone number, or creates a sense of urgency, verify the request through another channel. The safest option is to call the person directly using a number you already know.

WhatsApp Scam Alert could become a useful extra layer of protection, especially against messages from unknown senders. But it is not a complete shield. Scams that come from hijacked accounts, trusted contacts, phone calls, or cloned voices can still bypass this system. The best defense remains caution, verification, and refusing to act under pressure.