Gloria’s lasagna sat on the stove at 6:41pm, still bubbling at the corners. Her phone lit up on the granite with a WhatsApp from a number that was not in her contacts. The profile photo was her son Luis at graduation, the same crop he still uses on Instagram. A 22-second voice note. It sounded like him: the allergy rasp, the way he says Ma. He said he dropped his phone, this was Marco’s WhatsApp, a same-day repair was $800, he had a 7:15am warehouse shift, send Apple Cash to a handle she had never seen, and please do not tell Dad because he will freak. Her thumb was on Send. Then she looked at the handle. It was a string of digits, not the email Luis has used for five years. She called his real number from Favorites. Second ring. Microwave in the warehouse break room. Luis had not sent a voice note. His phone was in his pocket.
This is Part 26 of Phase P, and Part 1 of AI safety for everyday life. The last Phase P series was AI agents for everyone. Setup, prompting, memory, and agents covered how to use the tools. This series is the money-and-trust layer. Everyday AI safety starts here, not with science fiction. Next is School, work honesty, and citations. If what you wanted was local models and privacy settings, that is the older privacy tutorial. The rest of the path sits on Learn and Practical AI.
What you’ll learn
- Name the six tells on a money ask that arrives as voice, video, email, or a listing
- Verify identity on a second channel you already own, not on the inbound thread
- Treat video and audio as forgeable, the same as a well-written email
- Spot fake hiring tests, fake ChatGPT investment chats, cloned brand ads, and romance scripts that ask for crypto
- Use ChatGPT, Claude, Gemini, or Grok as drafting tools, never as a bank or a wire-confirm desk
Six tells that beat a familiar voice

The clip sounded like Luis. That is the point of a voice clone. The Federal Trade Commission has warned since 2023 that a scammer can copy a voice from a short public clip, then call and pretend to be family. The FCC later said the same for cloned robocalls and deepfake video links. You win by reading the ask, not by squinting at the waveform.
Gloria’s 22 seconds carried six tells. Urgency: $800 now, 7:15am shift, same-day shop. Secrecy: do not tell Dad. A new payment rail: an Apple Cash handle that had never appeared in five years of family Venmo. Refusal to video-call, baked into the story (Marco’s phone, camera is whatever). Slightly off phrasing: Luis says “the shop on Morse,” not “the mechanic shop.” And the classic cover for a new number: I dropped my phone.
Map those onto the FTC’s four scam signs and the picture gets dull in a useful way. Scammers pretend to be someone you know. They invent a problem. They pressure you to act immediately. They tell you to pay in a specific way: cryptocurrency, a wire, a payment app, or a gift card with the numbers read off the back. Gloria got all four in one voice note. The clone only supplied the rasp. You do not need all six tells. One honest pause is enough. A “CEO” Slack that only has urgency and a gift-card rail is still a stop.
Rule of thumb: A new payment handle plus a 20-minute deadline is a stop. Call the known number before you open Apple Cash.
Call back on a number you already have

The FTC’s consumer line on family-emergency clones is blunt. Do not trust the voice. Call the person who supposedly contacted you, on a phone number you already know is theirs. If you cannot reach them, try another family member or a friend. Gloria did that in under four minutes. Luis answered. The $800 stayed in her checking account.
Out of band means a channel you already owned before the ask arrived. Favorites. The work directory. The number on the back of the debit card. The company’s real Slack search, not the inbound DM. The careers page on the company’s own domain, not the Indeed listing that emailed you. The inbound thread is hostile territory. Caller ID lies. WhatsApp profile photos get lifted. Email display names get forged. A FaceTime thumbnail can be a still.
Work the same move on a fake executive. Thursday at 11:08am, Gloria’s AP inbox showed a Teams chat from “R. Hale, CFO” asking her to buy eight Google Play cards for a client lunch because the corporate card declined. Hale sits two floors up. She walked the stairs. He was in a vendor meeting with his real laptop open. The chat account was a lookalike. The $200 of cards never left the drugstore rack. If the person does not pick up, you still do not pay. You call a second relative. You wait. A real tow truck can sit for the length of one extra ring. A clone cannot survive a known number.
Video and photos can be fake too
Audio is the loud version of this problem. Video is the version people still treat as proof. A 12-second clip of “Luis” in a parking lot, lips moving, is still a file. Deepfakes (generated video or audio made to look like a real person) are good enough now that glitch-hunting is a weak hobby. Odd blinks used to be a party trick. They are not a control. The FCC’s consumer guide puts celebrity deepfake ads and cloned family calls in the same bucket: reach the real person, or the real company, before you send money.
Live video on a number you already have is a better check than a file they sent. Ask something unscripted. “What did you burn at dinner on Sunday.” “What color is the chipped kettle.” Gloria’s kettle is blue and ugly. A clone trained on Instagram has the graduation photo. It does not have the kettle. If they stall, refuse the camera, or keep returning to the $800, you hang up and use the known number anyway.
Still images lie in quieter ways. Romance scams on the FTC’s consumer pages often start with a handsome profile, a job that keeps them overseas, then a plane ticket or a medical bill. Generated photos made that cheaper. The tell is still the ask. They will not meet. They will want money on a rail you cannot reverse. The FTC’s crypto page is one sentence you can tape to a monitor: only scammers demand payment in cryptocurrency.
Too-good jobs, crypto chats, and cloned ads
Voice clones steal trust you already have. Too-good offers steal trust you wish you had: a job, a return, a famous face saying buy. The defense is the same rail-and-channel test. The costume changes.
Fake hiring tests want documents. A listing for “remote AI evaluator, $45 an hour, 20-minute unpaid test, then upload your driver’s license and a voided check for payroll” is a data harvest with a job title on it. Real employers do not collect a Social Security card through a Google Form in the first email. In December 2024 FTC staff wrote that reported job-scam losses were more than $220 million in the first six months of that year, with task scams (tiny “app boosting” jobs, then your own money in to reach the next tier) as a large slice of the reports. Treat that as reported harm, not a census. Reject any listing that asks you to pay to get paid.
Gloria’s nephew Dex, 24, almost funded a different costume. A TikTok showed a chat window that looked like ChatGPT, branded as an “investment agent,” promising a $250 USDT deposit would start trades. The URL was a lookalike. OpenAI does not take your USDT to run a secret money bot. As of writing, ChatGPT, Claude, Gemini, and Grok will draft a grocery list. They will not hold your coins. Dex closed the tab after Gloria made him read the real help center, not the ad. A video that looks like a celebrity selling pans or a trading bot is an ad file too. The FCC flagged deepfake celebrity cookware pushes: open the real brand site yourself. Gift cards are the same shape. The FTC repeats that they are for gifts. No government office, no “HR portal,” and no family emergency is paid in Google Play or Apple codes.
What chat products are and are not
ChatGPT, Claude, Gemini, and Grok are writing tools with a search-shaped memory of the public web. They are not your bank. They cannot see Luis in the break room. They cannot see Hale two floors up. They cannot see the Apple Cash handle on Gloria’s screen. Pasting a transcript into a chat and asking “does this sound like a scam” may return a decent essay. That essay is not verification. Verification is the second ring on the known number.
People try the chat anyway. After the voice note, Gloria almost dropped the transcript into ChatGPT because the tab was already open from a work draft. She typed three words, deleted them, and called Luis instead. A lookalike site wearing a ChatGPT coat may cheer the deposit. You cannot tell which one you opened from the confidence of the prose. Do not paste routing numbers, ID scans, or the voice file into a consumer chat to “double-check.” Use the chat later to draft the fridge script. Do not use it as the control that releases $800.
Vendor usage policies (OpenAI, Anthropic, and the others) already forbid using the products to run scams. That rule protects their terms, not your checking account. Your rule is smaller. The chat box does not approve wires.
Channel, verify step, never-do
Worked grid for Gloria’s week, plus the costumes around it. The numbers are hers ($800, eight gift cards) or the FTC’s reported job-scam figure above. Nothing else here is a national crime rate.
| Channel | Verify step | Never-do |
|---|---|---|
| Voice note or call | Hang up. Call the number already in Favorites. Ask the family word. | Pay on that thread. New Apple Cash, Zelle, wire, crypto, gift cards. |
| Video clip or live request | Call back on the known number. Demand a live, unscripted question. | Trust a file they sent. Treat a still as FaceTime. |
| Email, Slack, or “CEO” text | Walk upstairs, or search the real company directory. Confirm in a channel you already use. | Buy gift cards because the display name matches. |
| Job listing, dating chat, or ad | Open the real careers page or brand site yourself. Reverse-search the recruiter. | Upload ID and a voided check to a “hiring test.” Send crypto to an “investment agent.” |
What that table does: it separates the costume from the control. The costume is the voice, the logo, the job title. The control is a channel you owned on Wednesday. If the control is missing, the money stays put.
A family call-back script
Print this. Put it on the fridge. Fill the brackets in person, not in the family WhatsApp after the fact. Gloria’s word is a dumb one on purpose (blue kettle), because Instagram does not know the kettle.
FAMILY CALLBACK (fridge copy)
Word we picked in person: [blue kettle]
Known numbers: Luis [Favorites], Gloria [Favorites], Dad [landline]
If anyone asks for money by voice, video, text, or chat:
1. Do not reply on that same thread.
2. Call the person on a number already in contacts.
3. If they do not pick up, call a second family member.
4. Ask for the family word. Hang up if they stall or refuse video on the known number.
5. Never send Apple Cash, Zelle, Venmo, wire, crypto, or gift cards on an urgent ask.
6. New handle, new URL, or "I dropped my phone" means stop.
7. After you are safe, report at ReportFraud.ftc.govWhat that script does: it turns Gloria’s four minutes into a default. The word is a cheap second factor. The known-number list is the real one. Change the word if it ever leaks. Do not post a photo of the fridge sheet.
Common mistakes
- Trusting the rasp because it sounded like Sunday dinner. Clones copy rasp.
- Calling back the inbound WhatsApp or the caller ID, which is still their thread.
- Sending a “small test” of $50 to see if the handle is real. Small tests cash out too.
- Pasting the transcript into ChatGPT and treating the answer as a callback.
- Uploading a license and a voided check to a 20-minute hiring test.
- Keeping the secret because the clip said do not tell Dad. Secrecy is the product.
How to practice this week
Pick the family word at dinner, on paper, phones face down. Fill the fridge script. Run one fake drill: Gloria’s $800 note, or Hale’s gift cards, for 10 minutes. Next in this series is School, work honesty, and citations (Part 2). The series hub is AI safety for everyday life. If you still need account hygiene before the next scare, Part 7 of setup is the door for that, not a fourth payment app.
Quick recap
- Treat a familiar voice as untrusted until a known number picks up.
- Call a number you already own. Never the inbound thread.
- Video files and celebrity ads can be fake. Live, unscripted, known-number video is the check.
- Too-good jobs, crypto “agents,” and cloned ads fail the same rail test.
- ChatGPT is a draft box. It does not confirm wires.
Sources
Research and further reading used for this article:
- FTC Consumer Advice: How To Avoid a Scam (four signs: pretend, problem or prize, pressure, specific payment rail)
- FTC: Scammers use AI to enhance their family emergency schemes (voice clones from a short public clip; call a number you know)
- FTC: Fighting back against harmful voice cloning (boss or family voice asking for money or account numbers)
- FCC: Deep-fake audio and video links (cloned voices, celebrity deepfake ads, call the real person before you send money)
- FTC: Job scams and the FTC staff press note on reported job-scam losses, including more than $220 million in the first half of 2024 (December 2024 release)
- FTC: What To Know About Cryptocurrency and Scams (only scammers demand payment in cryptocurrency)
- FTC: Avoiding and Reporting Gift Card Scams (gift cards are for gifts, not payments)
- ReportFraud.ftc.gov (where to tell the FTC after you are safe)
- OpenAI usage policies and Anthropic usage policy (vendor rules; they are not a substitute for a callback)
- AMS: AI safety for everyday life (this series)
Keep going
Same lessons in your feed
Short diagrams and hooks on Instagram, X, and Facebook.
