Fake AI app
In plain terms
An app that promises the capabilities of a well-known AI tool, for free or with extra features. What it actually collects is your accounts and whatever you entrust to it.
Definition
A fake AI app is a piece of software, browser extension, or mobile app that presents itself as a well-known artificial intelligence tool, or as privileged access to one, in order to collect credentials or data.
How it works
The fast rise to fame of these tools creates a lasting gap between what people have heard named and what they actually know how to locate: few people know the official address of a service they only heard about last week. The fake exploits that gap, offering a free version, no waitlist, extra features, or availability in a country where the official one isn't offered. Two kinds of harvesting follow. The first is classic: credentials requested at sign-up, often via login with an existing account, and the broad permissions of a browser extension. The second is specific to these tools: what the user types into them — professional documents, personal data, confidential text — because the very use of the tool consists of handing over content.
Warning signs
- App promising free access to a tool that's normally paid
- Publisher different from the one behind the announced tool
- Browser extension requesting access to every site for a writing feature
- Login offered via an existing account on a site you didn't reach yourself
- App promoted through an ad or a sponsored result
- No privacy policy, or a policy claiming unrestricted use of submitted content
How to verify
Start from the official publisher rather than the tool's name: open its site, and follow the link it gives to its app. It's the only path that doesn't go through a search, which is exactly the terrain this attack exploits. Check the developer's name in the app store, and the permissions requested.
What to do
Only use the publisher's own apps, and decline extensions asking for access to every site for a minor feature. Regardless of fraud, never hand this kind of tool documents you wouldn't publish: submitted content leaves your machine.
If it already happened
Remove the app or extension, change the passwords of the accounts used to sign in to it, and revoke sessions and third-party app permissions. Take stock of what was submitted to the tool: if professional documents or personal data are involved, notify the appropriate party.
Frequently asked questions
- The app works and does give me answers.
- That's expected: it can relay requests to a real service while keeping a copy of what passes through and of entered credentials. The app appearing to work says nothing about what happens around it.
- What's at risk with what I typed into it?
- Everything submitted should be considered out of your control: documents, contact details, internal text. Make a list of it, and report it if professional information or data about other people is involved.
Related attacks
Official sources
Also known as: fake AI app, fake ChatGPT, fraudulent generator, malicious AI extension.
This article is part of the AI and synthetic content family. Last updated: 2026-09-03.