Does an account need a strong password for an important account? Asking AI might seem like an easy solution. This is because ChatGPT and Copilot are capable of many complex tasks. Not only do they write emails, make reports, and create code, but they can also make a safe password easily. However, researchers and providers of company IT services have found reasons for concern. This is because AI password generators can produce passwords that appear more secure than they actually are.

Company IT Services Should Not Let AI Create Password, Here’s Why
According to experts in company IT services, a recent study was conducted to test AI-generated passwords. They asked for a long password with different characters. The results were initially found to be very secure. Many of these included uppercase letters, numbers, and symbols. Their strength was well rated in strength checkers. In some cases, it was estimated to take centuries to crack. However, deeper analysis revealed a different story. It was found that these passwords had patterns that made them less secure.
Most generative AI uses large language models commonly called LLMs. They work by guessing what text is expected next in the sequence. As a result, this ability creates authentic and natural responses. However, passwords require something entirely different as predictability is a key component of good credentials. This means that AI systems were not designed for true randomness. Instead, their outputs reflect patterns learned during training. Unfortunately, those patterns can become a security weakness.
Researchers and company IT services professionals have examined dozens of generated passwords. The results show that several outputs did have similar structures, and some passwords were even duplicated. Although none contained repeated characters, initially, it may seem like a good thing. But, a random password, of course, will allow character repetition. In conclusion, it means that if there is no repetition, it implies that the output is affected by learned patterns. These predictable structures make passwords less secure.
Researchers and company IT services experts also examined password entropy. Entropy measures how unpredictable something truly is. The results showed that AI-generated passwords have significantly lower entropy. In contrast, truly random 16-character passwords performed much better. Unfortunately, by reducing unpredictability, the opportunities for attackers are also increased. In brute-force attacks, for example, they test enormous numbers of combinations, and predictable patterns can reduce the required effort. Therefore, visible complexity alone provides limited protection.
Online password checkers usually measure obvious complexity. This is because they often see numbers, symbols, and mixed case letters. Those features often produce impressive security scores. However, these tools may overlook hidden patterns. Additionally, structures generated by AI can still be predictable. Providers of company IT services stress that just because something looks complicated, it doesn’t mean that it is random. Even newer AI systems acknowledge this limitation. Gemini 3 Pro, for example, has warned users about password generation and advises against chat-generated passwords.
Use a trusted password manager instead, says company IT services providers. This is because most include dedicated password generators. These tools rely on cryptographic randomness. Cryptographic techniques produce true randomness and make it much more difficult to guess passwords. These are particular for security reasons. Although AI remains incredibly useful for productivity, passwords require specialized security tools. Use AI for work, but not your credentials.