01543 524594  ·  hello@initialit.co.uk
CYBER ESSENTIALS · MICROSOFT PARTNER · UK HELPDESK · 5.0 ★ GOOGLE
HomeBlog › Cyber Security

Don’t trust AI to generate your passwords (the one job it is genuinely bad at)

AI tools look like a clever shortcut for generating strong passwords. They aren’t. Here is why, and what to use instead, for any UK business that cares about its accounts.

Andy Price · Founder27 May 2026 · 5 min read

If you needed a strong password right now, would you ask Microsoft Copilot or ChatGPT to generate one for you? It feels like a clever shortcut. The result looks fine: long, mixed case, plenty of symbols. The catch is that AI is the wrong tool for the job, and the password you get back is much weaker than it looks. For any UK business with anything worth protecting, that matters.

Hi, I’m Andy from Initial IT. We run cyber security for businesses across Lichfield, Tamworth, Cannock and the wider West Midlands, and this question has come up more than once this year. So here is the short version, in plain English.

Key takeaways

  • AI tools like ChatGPT and Copilot are language models. They are trained to predict text, not to be truly random.
  • AI-generated passwords pass strength meters but contain hidden patterns that make them faster to crack.
  • Use a proper password manager that produces real random passwords (1Password, Bitwarden, NordPass).
  • Even better, pair that with multi-factor authentication and conditional access so a stolen password is no longer enough.
  • For UK SMBs, this all sits inside a properly configured Microsoft 365 Business Premium environment.

Why AI-generated passwords look strong but actually are not

AI tools like Copilot and ChatGPT run on something called a Large Language Model (LLM). That model is brilliant at predicting natural sounding text. It is the wrong shape for true randomness. Strong passwords need real randomness. The two qualities are in tension.

Researchers recently tested AI password generators. On the surface, the results looked great: long strings of mixed-case letters, numbers and symbols that scored highly on online strength meters. Some tools even claimed centuries to crack. When the passwords were analysed properly, a different picture emerged.

The tell-tale patterns AI keeps repeating

The researchers found:

  • Repeating structures. Many AI passwords followed very similar shapes, even when asked for “random” strings.
  • Duplicates. Some passwords showed up more than once across different sessions and tools.
  • Almost no repeated characters. That sounds like a good thing, but true random text often does contain repetition. Removing it on purpose is a learned habit, not real randomness.

They measured something called “entropy”, the technical name for how unpredictable a string of characters really is. AI passwords scored far lower than a genuinely random 16-character password should. That makes them measurably easier to attack with modern cracking techniques.

What you should use instead, for a UK SMB

The fix is boring. Use a proper password manager that produces truly random passwords. Pair it with multi-factor authentication so a stolen password is no longer enough on its own. For a small businesses up to 100 staff UK business, that usually means:

  1. A business password manager for the team. 1Password, Bitwarden Business or NordPass Teams all work well.
  2. Multi-factor authentication everywhere, ideally via Microsoft Authenticator with number matching, so attackers cannot harvest fatigue-clicked approvals.
  3. Microsoft Entra ID P1 conditional access (included in Microsoft 365 Business Premium) so logins from risky locations, unknown devices or impossible-travel get blocked or challenged.
  4. Passkeys where they are available. Passkeys replace passwords entirely on supported sites, using your device’s biometrics.
Free 60-minute webinar
Cut through the AI hype, in plain English
Where AI saves time, where it leaks data and how to roll out Microsoft Copilot safely for a UK business.

A useful side-note about Microsoft Copilot

The above is one of the reasons we are careful about where we let AI tools play in a business. Microsoft 365 Copilot is great for drafting documents, summarising emails and triaging Teams chat. It is the wrong tool for inventing your master password. Most things AI is asked to do well, it does well. The trick is knowing the small list of things it is the wrong tool for.

For a longer plain-English version of where AI helps and where it does not, our free 60-minute AI webinar for business owners walks through it.

How we help

Setting up a proper password manager, multi-factor authentication and conditional access for a UK SMB is part of our cyber security work. Want a sanity-check on your current setup? Book a quick chat with me, or call 01543 524 594.

Frequently asked questions

Is it safe to ask ChatGPT or Copilot to generate a password?

No. AI tools are trained on patterns of natural text, not true randomness. Their passwords look strong but contain learned shortcuts that make them easier to crack. Use a proper password manager instead.

What is the best password manager for a UK small business?

Any reputable business-grade tool works. We see 1Password Business, Bitwarden Business and NordPass Teams most often in UK SMBs. All produce genuinely random passwords and share access safely across a team.

How long should a strong password be?

For business accounts, at least 14 characters of true randomness, ideally 16 or more. Length and unpredictability matter more than which special characters you sprinkle in.

Does multi-factor authentication still matter if my passwords are strong?

Yes. MFA is the safety net for everything else. Even a strong password can leak in a phishing attack. MFA stops an attacker turning that leak into a real breach.

Where can I find UK government advice on passwords?

The NCSC has clear guidance for businesses and individuals at ncsc.gov.uk.

Quick check: where does your business stand on cyber security?

The questions in our free 2-minute Cyber Security Health Check are the eleven we ask every new client first. Score yourself, see the per-category breakdown, get the three highest-impact fixes for your specific gaps. No marketing list.

Take the 2-minute Cyber Health Check

– Andy Price, Founder & MD, Initial IT · 01543 524 594 · hello@initialit.co.uk