AI-Generated passwords: digital safeguard or vulnerability gateway?

A recent analysis conducted by Kaspersky raises significant concerns regarding the security of passwords generated using large language models (LLMs) such as ChatGPT, Llama, and DeepSeek.
Although these AI-based tools have gained traction as a means of generating ostensibly secure passwords, the study reveals that the outputs often follow recognizable patterns, rendering them more susceptible to compromise by cybercriminals.
Password vulnerabilities.
Experts indicate that the proliferation of digital services requiring authentication has led to the growing reliance on LLMs to generate seemingly strong password combinations. However, this approach can foster a false sense of security, as the passwords generated by these models frequently exhibit identifiable linguistic or structural patterns.
Alexey Antonov, Head of the Data Science team at Kaspersky, detailed the results of an experiment involving 1,000 passwords generated by ChatGPT (OpenAI), Llama (Meta), and DeepSeek (China). He provides further insight:
“All models understand that a robust password should consist of at least 12 characters, incorporating uppercase and lowercase letters, numbers, and symbols. Nevertheless, DeepSeek and Llama occasionally produced dictionary-based words with numeric substitutions: S@d0w12, M@n@go3, B@n@n@7 (DeepSeek); K5yB0a8dS8, S1mP1eL1on (Llama). Both models also frequently produced variants of the commonly used ‘password’: P@ssw0rd, P@ssw0rd!23 (DeepSeek); P@ssw0rd1, P@ssw0rdV (Llama). It goes without saying that such passwords offer little real protection.”
Patterns in AI-generated passwords.
By contrast, ChatGPT tended to generate strings that appeared more random—such as qLUx@^9Wp#YZ or P@zq^XWLY#v9. However, the analysis identified recurring elements, such as the frequent inclusion of the number 9, compromising the entropy required for robust cryptographic security.
The study also revealed that 26% of passwords generated by ChatGPT, 32% by Llama, and 29% by DeepSeek lacked either special characters or numeric digits.
Furthermore, DeepSeek and Llama occasionally produced passwords with fewer than 12 characters, further increasing their susceptibility to brute-force attacks.
This predictable structure allows attackers to accelerate brute-force attempts by prioritizing commonly used combinations, significantly reducing the computational effort and time required to breach credentials.
In 2024, Kaspersky developed a machine learning algorithm specifically designed to evaluate password strength. The findings were revealing: nearly 60% of passwords could be cracked in under an hour using contemporary attack technologies.
When applied to AI-generated passwords, the algorithm produced alarming results: 88% of passwords generated by DeepSeek and 87% by Llama were deemed vulnerable to sophisticated attack vectors. ChatGPT performed comparatively better, with 33% of its passwords considered insecure.
Antonov offers a detailed explanation:
“The core issue is that LLMs do not generate true randomness. Instead, they replicate probabilistic patterns derived from existing datasets, which makes the outputs predictable—particularly to attackers who understand the operational logic of these models.”
Recommendations for users.
In light of these findings, Kaspersky strongly advises against relying on AI tools for password generation. Instead, users should turn to dedicated password managers. These specialized solutions generate truly random, cryptographically secure credentials; store them within encrypted vaults protected by a master password; and provide additional features such as auto-fill capabilities, cross-device synchronization, and real-time breach monitoring.
Kaspersky’s concluding recommendation is unequivocal:
“While AI can support many tasks effectively, password generation is not one of them. The patterned and predictable nature of passwords created by LLMs makes them vulnerable to compromise. Rather than opting for shortcuts, invest in a trusted password manager. In an era marked by frequent data breaches, having a strong, unique password for every account is not just best practice—it is essential.”

