Here is a question I have started hearing from business owners around Lichfield: “Andy, can I just ask AI to make me a strong password?” It sounds sensible. The tools are right there, and they are clearly clever. So why not?
The short answer is no, not for anything that matters. AI tools like ChatGPT and Copilot are built to predict plausible text, not to create true randomness, and a strong password depends on randomness. The passwords they produce often look impressive but carry hidden patterns that make them weaker than they appear. For real security, use a password manager’s built in generator and turn on multi-factor authentication.

Key takeaways
- AI tools are designed to predict natural sounding text, not to produce true randomness, and randomness is exactly what a strong password needs.
- AI generated passwords often score well on a strength meter but contain repeating structures and lower entropy, which makes them easier to crack.
- Online strength checkers only measure visible complexity, so they miss the hidden patterns AI leaves behind.
- Use a password manager’s built in generator for true randomness, a unique password per account, and multi-factor authentication on everything important.
- AI is a genuinely useful productivity tool. It is just the wrong tool for this one security job.
Why do people ask AI to create passwords?
It is an easy habit to fall into. The same tools that draft your emails, summarise long documents and tidy up your notes can also spit out a sixteen character string of letters, numbers and symbols in a second. That feels like a smart shortcut.
And in fairness, AI is good at plenty of things. We help businesses use it well every day. The problem is not AI itself. The problem is using it for a job it was never built to do.
Are AI generated passwords actually secure?
On the surface, they look great. Long, mixed case, peppered with symbols. Drop one into an online strength meter and it often scores brilliantly, with cheerful messages saying it would take centuries to crack.
But when researchers analysed batches of AI generated passwords properly, a different picture emerged. They found repeating structures, near duplicates and very similar patterns across passwords that were meant to be unique. Tellingly, the passwords almost never contained repeating characters. That sounds like a good thing, but genuine randomness often does repeat. Its absence is a clue that the password is following learned rules rather than being truly unpredictable.
Even some of the newer AI models now warn people not to rely on chat generated passwords for sensitive accounts. When the tool itself is telling you to think twice, that is worth listening to.
What does entropy mean, and why does it matter?
Entropy is just a technical word for how unpredictable something is. A genuinely random sixteen character password has very high entropy, so an attacker has an enormous number of combinations to try. The more entropy, the longer a brute force attack takes, where software guesses huge numbers of combinations very quickly.
AI generated passwords measure far lower on entropy than a truly random one of the same length. Online checkers do not catch this because they only see the surface, the symbols and the mixed case. They cannot see the underlying patterns. So a password can look strong and still be a soft target.
What should you use instead?
The fix is simple and it is not expensive. Use a password manager with a built in generator. These rely on cryptographic randomness, which is a mathematical process specifically designed to produce unpredictable results. That is the opposite of how an AI language model works.
A good setup looks like this:
- A password manager that generates and stores a long, unique password for every account.
- One strong master password or passphrase to unlock it. The NCSC three random words approach works well here.
- Multi-factor authentication switched on for every important account, so a stolen password alone is not enough to get in.
The NCSC, the UK’s national cyber authority, recommends password managers for exactly this reason. It is the boring, reliable answer, and boring is good when it comes to security.
What this means for businesses in Lichfield and Staffordshire
For the firms we look after across Lichfield, Tamworth, Cannock and the wider West Midlands, weak or reused credentials are still one of the most common ways attackers get in. That matters even more for the law firms and accountancy practices we work with, who hold confidential client data and, in many cases, client money.
This is the kind of thing we sort quietly as part of managed cyber security and IT support in Lichfield: rolling out a password manager across the team, switching on multi-factor authentication, and lining it all up with Cyber Essentials. Done properly, your team gets stronger security and less hassle at the same time.
So should you stop using AI altogether?
Not at all. AI is excellent for summarising a long email thread, drafting a first version of a document, or turning messy notes into a clear plan. Used well, it genuinely saves time, and helping businesses do that safely is a big part of what we do. You can see our take on that on our Copilot and AI page.
Just keep it away from the jobs that depend on true randomness. Generating the secrets that protect your business is one of them.
Free AI webinar for business owners
See what AI can safely do for your business, and where the real risks are. A practical, plain English session with no hard sell.
Save my seat →Free 2-minute tool from Initial IT
Should you roll Microsoft Copilot out yet?
11 honest questions, an instant readiness score, and a short plan tailored to your business. No marketing list.
Take the readiness quiz →Frequently asked questions
Can I ask Copilot or ChatGPT to make me a password?
You can, but I would not rely on it for anything important. The passwords look strong yet carry hidden patterns and lower entropy. Use a password manager’s generator instead, which is built for genuine randomness.
Are password managers actually safe?
Yes, and they are far safer than reusing the same password or keeping a list in a notebook or browser. Your passwords sit in an encrypted vault, unlocked by one strong master password and protected with multi-factor authentication. It is the approach the NCSC recommends.
What makes a password genuinely secure?
Length and unpredictability, plus being unique to that one account. A long, randomly generated password from a password manager is ideal. For the master password, a passphrase made of a few random words works well and is easier to remember.
Do I still need multi-factor authentication if my passwords are strong?
Yes. Multi-factor authentication is the single most valuable thing you can switch on. It means that even if a password is stolen or guessed, it is not enough on its own to get into the account.
Can you set this up for our business?
We do this all the time. We roll out a password manager and multi-factor authentication across your whole team as part of managed IT and Cyber Essentials, with no fuss for your staff. Give us a ring on 01543 524594 or drop us a line and we will sort it.
Quick check: where does your business stand on cyber security?
The questions in our free 2-minute Cyber Security Health Check are the eleven we ask every new client first. Score yourself, see the per-category breakdown, get the three highest-impact fixes for your specific gaps. No marketing list.
Take the 2-minute Cyber Health Check
– Andy Price, Founder & MD, Initial IT · 01543 524594 · hello@initialit.co.uk
