foundations · Level 1

Stay safe with AI: scams, fake media and your privacy

A calm, practical guide for UK adults: spot AI-assisted scams and fake media, protect your privacy, and know where to report problems.

By Mickarle Wagstaff-Irons - Micky Irons

  • Level 1Starting out
  • 100 min
  • 7 chapters
  • Free PDF, no account
The Aperturefoundations / 01

Start with the essentials

The short answer

AI makes scams and fake media more polished, but the safe response does not change: pause, check and verify through a contact you already trust before you send money, codes or personal details. Visual tells and detection tools are not proof. Keep sensitive information out of chatbots, review your privacy settings, and know where to report problems in the UK.

What you will learn

  • You will be able to spot the pressure, secrecy and payment requests that mark a scam, whether or not AI wrote it.
  • You will be able to follow a pause, check, verify routine that uses contact details you already trust.
  • You will be able to explain why visual tells and detection tools are not proof, and what Content Credentials can and cannot show.
  • You will be able to redact a prompt and review the history and data settings of any AI tool you use.
  • You will know your basic rights under UK data protection and how to ask a company what it holds about you.
  • You will know where to report scams, fake media and data problems in the UK, and have a household verification plan.

Who it is for

Any adult in the UK who uses AI tools or may be targeted by AI-assisted scams, with no technical background. You need a pen and paper or a notes app, and one online tool you already use for the settings activity. This workbook gives general information, not legal or security advice.

Before you start

  • None beyond curiosity. It helps to have read What is AI? first, which explains what chatbots are. No technical knowledge is needed.

Keep learning

The complete workbook

This workbook helps ordinary adults in the UK handle AI-assisted scams, fake images and audio, and privacy questions without fear or technical knowledge. You will learn a pause, check, verify routine, what deepfake detectors and content credentials can and cannot show, what to keep out of a chatbot, and where to report problems. It ends with a household plan.

  1. 01
    How AI changes scams, and what stays the same

    AI has made scams more polished and easier to aim. The trick underneath is old, and so is the defence.

    In the workbook · 1 exercise
  2. 02
    A habit that works whatever the technology

    You cannot out-spot software. You can build a routine that does not depend on spotting anything.

    In the workbook · 1 exercise
  3. 03
    Fake and altered media: what to trust instead

    We once treated pictures, audio and video as evidence. AI has weakened that habit, so learn what to lean on instead.

    In the workbook · 1 exercise
  4. 04
    What to keep out of a chatbot

    Anything you type into an online AI tool leaves your device. Decide what goes in before you type.

    In the workbook · 1 exercise
  5. 05
    Your settings, your history and your rights

    You do not need a technical guide to see what a tool does with your data. You need to know where to look and what to ask.

    In the workbook · 1 exercise
  6. 06
    If it goes wrong, and where to report it

    Embarrassment keeps some people quiet. The official advice is the opposite: act quickly, tell people and report it.

    In the workbook · 1 exercise
  7. 07
    Household habits and your plan

    A few small habits make a whole household harder to fool, and most cost nothing.

    In the workbook · 1 exercise

Also inside: a 10-point checklist, a glossary of 12 terms and 10 questions and answers to test yourself. 7 hands-on exercises, each with a worked answer at the back where the workbook gives one.

No login, no card, no account. Before the download we ask you to follow Mickai (two quick links). Free to download and use for personal learning, study groups and inside your own team. Please do not resell the workbooks or republish them as your own. Link people to trust-agent.ai instead.

Test yourself

Questions and answers

Can someone really copy a voice with AI?

Police Scotland describes voice cloning scams, where AI tools copy your voice so someone else can pretend to be you, for example to ask people you know for money. Its advice: ring the person back on their usual number, consider code words with family, and avoid publicly sharing videos and audio clips. A voice alone is not proof of identity.

Can I spot a deepfake by looking closely?

Not reliably. Ofcom's paper says people creating fakes adapt, that forensic techniques can have short lifespans, and cites a Royal Society finding that most people struggle to spot high-quality deepfakes. Ofcom says users should not be left to identify them alone. Rely on source, context and verification through a channel you trust.

Can an AI-detection tool prove a picture or clip is fake?

No. Ofcom's paper cites research showing that lowering resolution, cropping or duplicating a file often gave incorrect results, and that yes or no answers can be hard to interpret. A tool's verdict, either way, is one clue. Do not upload private images to detectors without thinking about privacy.

What do Content Credentials tell me?

They are a signed record of a file's origin, edits and any recorded AI use, and checking shows whether the file or record has been altered. The C2PA says they do not show whether content is true, that a missing credential does not make content untrustworthy, and that credentials can be removed. Trust depends on the signer.

What should I never type into a chatbot?

Passwords, codes, PINs, bank and identity numbers, other people's private details, confidential work material and anything that would harm you if public. The NCSC advises against including sensitive information in queries to public chatbots. Redact names and details before you paste, and add them back yourself.

How do I find out what a tool does with my chats?

Look in its settings for history, data use, memory, connected apps and sharing, then search its privacy policy for words like retain, delete, train and review. Note what you find and the date. If you cannot find an option, treat that as a finding and type less. Menus differ and change.

Do I have rights over my data held by an AI company?

Under UK data protection law you have rights over your own personal information held by organisations. The ICO says AI developers and deployers that decide how personal data is used need clear ways for people to use those rights. It lists rights to be informed, get copies, correct, delete (in some circumstances), object and limit use. Organisations usually have one month to respond. If unhappy, complain to them, then the ICO.

I think I have been scammed. What do I do now?

Stop contact. If money or cards are involved, tell your bank first, using the number on your card or 159 if your bank supports it. Report to Report Fraud (0300 123 2040) in England, Wales and Northern Ireland, or to Police Scotland on 101. Change reused passwords and turn on two-step verification. Call 999 if you are in danger.

Is a family verification phrase worth it?

It costs nothing and can help in a genuine emergency. Police Scotland suggests code words with family and friends. Agree it in person, keep it out of photos and messages, and use it only when someone urgently asks for money or help. It supports calling back on a known number and does not replace it.

Is it my fault if I was fooled?

Anyone can be fooled. Report Fraud says fraud is a crime, anyone could be a victim, and people sometimes stay silent through embarrassment. It adds that romance fraud is never the victim's fault. The NCSC says scams are getting smarter and some fool experts. Tell your bank quickly, report it, and speak to someone you trust.

When you have finished

Get your certificate of completion

Type your name and download a certificate for this workbook as a PDF, ready to print or to add to LinkedIn. It is made on your own device, so your name is never sent to us. It is a self-declared certificate, not an accredited qualification.

Learn the language

Key terms

Generative AI
Software that produces new text, images, audio or video from a prompt.
Phishing
Scam emails, texts or calls that try to trick you into visiting a website or handing over details.
Voice cloning
Using AI tools to copy a person's voice so that someone else can pretend to be them.
Deepfake
Audio-visual content generated or manipulated using AI that misrepresents someone or something (Ofcom's definition).
Redact
To remove or replace sensitive details, such as names and numbers, before you share or paste something.
Provenance
The recorded history of a piece of content: where it came from and what was done to it.

6 of the workbook's 12 terms. The complete glossary is in the workbook.

Follow the evidence

Sources and checks

Facts last checked: .

These workbooks use AI assistance. See how the workbooks are made.

  1. Phishing scams: how to spot and report themNational Cyber Security Centre (NCSC)
  2. How to spot a scam email, text message or callNational Cyber Security Centre (NCSC)
  3. Report a scam emailNational Cyber Security Centre (NCSC)
  4. Report a scam textNational Cyber Security Centre (NCSC)
  5. Report a scam advertNational Cyber Security Centre (NCSC)
  6. Phishing scams: if you've shared sensitive informationNational Cyber Security Centre (NCSC)
  7. Recovering a hacked accountNational Cyber Security Centre (NCSC)
  8. Turn on 2-step verification (2SV)National Cyber Security Centre (NCSC)
  9. Install the latest software and app updatesNational Cyber Security Centre (NCSC)
  10. Use a strong and separate password for your emailNational Cyber Security Centre (NCSC)
  11. The near-term impact of AI on the cyber threat (published 24 January 2024)National Cyber Security Centre (NCSC)
  12. ChatGPT and large language models: what's the risk? (blog, published 14 March 2023)National Cyber Security Centre (NCSC)
  13. What to do about a scam call, text or messageOfcom
  14. Types of scam calls, texts and messagesOfcom
  15. How to protect yourself from scam calls, texts and messagesOfcom
  16. Deepfake Defences: Mitigating the Harms of Deceptive Deepfakes (discussion paper, 23 July 2024)Ofcom
  17. How can tech firms help users spot deepfakes? (11 July 2025)Ofcom
  18. Harmful online content: how to report it and where to get helpOfcom
  19. Report Fraud service goes live with full public launch in January 2026 (4 December 2025)City of London Police
  20. What is Report Fraud?Report Fraud (City of London Police)
  21. Guide to reporting cyber crime and fraudReport Fraud (City of London Police)
  22. What to do if you are a victim of fraudReport Fraud (City of London Police)
  23. Romance fraudReport Fraud (City of London Police)
  24. Investment fraudReport Fraud (City of London Police)
  25. Voice cloning scamsPolice Scotland
  26. Phone scamsPolice Scotland
  27. How to report a crimePolice Scotland
  28. Contact usPolice.uk
  29. Reporting fraudStop! Think Fraud (UK Government national campaign)
  30. Stop! Think Fraud: how to stay safe from scamsStop! Think Fraud (UK Government national campaign)
  31. Protect yourself from scamsFinancial Conduct Authority (FCA)
  32. Fake reviews: guidance on the prohibition under paragraph 13 of Schedule 20 to the Digital Markets, Competition and Consumers Act 2024 (CMA208, 4 April 2025)Competition and Markets Authority (GOV.UK)
  33. Better protection for victims thanks to new law on sexually explicit deepfakes (press release, 22 January 2025)Ministry of Justice (GOV.UK)
  34. Sexual Offences Act 2003, section 66B: Sharing or threatening to share intimate photograph or filmlegislation.gov.uk (The National Archives)
  35. Sexual Offences Act 2003, section 66E: Creating purported intimate image of adultlegislation.gov.uk (The National Archives)
  36. C2PA and Content Credentials Explainer (specification 2.4)Coalition for Content Provenance and Authenticity (C2PA)
  37. C2PA Harms Modelling (specification 2.4)Coalition for Content Provenance and Authenticity (C2PA)
  38. C2PA Security Considerations (specification 2.4)Coalition for Content Provenance and Authenticity (C2PA)
  39. Content CredentialsContent Credentials (C2PA project)
  40. What rights do I have over my personal information?Information Commissioner's Office (ICO)
  41. What is personal information?Information Commissioner's Office (ICO)
  42. Getting copies of your information (SAR)Information Commissioner's Office (ICO)
  43. Your right to get your data deletedInformation Commissioner's Office (ICO)
  44. How to make a data protection complaint to an organisationInformation Commissioner's Office (ICO)
  45. Make a complaint about how an organisation has used your personal informationInformation Commissioner's Office (ICO)
  46. A guide to the data protection exemptionsInformation Commissioner's Office (ICO)
  47. Engineering individual rights into generative AI models (response to the consultation series on generative AI)Information Commissioner's Office (ICO)

Created by Mickarle Wagstaff-Irons - Micky Irons with the Mickai team. Published by Mickai LTD. Last updated 26 September 2026.

NextKeep going

Where to go next