Thu 13 Aug 2026 / 16:03 ET
Kernel
Internet 3 min read

WhatsApp Scam Alert beta adds on-device AI screening for suspicious messages

Meta’s optional WhatsApp Scam Alert beta flags likely scams on a phone, while keeping message classification off its servers.

Dana Voss

By Dana Voss / Security Correspondent

WhatsApp Scam Alert beta adds on-device AI screening for suspicious messages
img: The Verge

Meta has started a limited WhatsApp Scam Alert beta, an optional tool that screens messages from people outside a user’s contacts list for patterns associated with fraud. The company says the model runs on the phone, a design meant to add a warning layer without sending message text to WhatsApp for classification.

The feature arrives before a broader release and has not yet been made available to all WhatsApp users. Meta says it is continuing to test the system through its bug-bounty program and is asking outside security researchers to examine its implementation.

How does WhatsApp Scam Alert work?

After a user enables Scam Alert, WhatsApp downloads a machine-learning model to the device. Meta says the model evaluates incoming messages from non-contacts using conversational structure and linguistic signals drawn from scam patterns in chats previously reported by users.

If the system decides a message is probably a scam, it puts a warning inside the chat. The other participant cannot see that warning. The recipient can block the account, report it, or keep talking.

A warning is not a verdict, and Meta has not published independent evidence in the supplied material showing the system’s detection rate or false-positive rate. The company gives users a way to override it: marking a conversation as trusted removes the alert and stops Scam Alert from flagging that chat again. A user who does so can also choose to send WhatsApp the five most recently received messages to help improve the model. That sharing is optional.

Does Scam Alert send WhatsApp messages to Meta?

Meta says no message content leaves the device to classify a chat, and a scam warning does not automatically report the chat, sender, or message to WhatsApp, Meta, or another party. Reporting remains a user action.

The company says it does collect limited performance data as anonymous, differentially private aggregate counts of warnings and user actions. According to Meta’s technical description of Scam Alert, those aggregates are processed in a confidential-computing environment. Meta also says it will publish model versions on a public transparency ledger before deployment and make model weights available for researchers to review. Those are Meta’s technical assurances, not an independent audit of the system.

How is this different from WhatsApp’s device-linking warning?

This is message screening, not the earlier WhatsApp protection for suspicious device-linking requests. In March, Meta said that warning was intended to catch attempts to persuade someone to hand over a linking code or scan a QR code, which could attach a scammer’s device to the victim’s account. Scam Alert instead examines the text of incoming chats locally after the user turns it on.

For users, the practical boundary is clear: the new tool can surface a risk signal, but it does not replace checking unfamiliar requests for money, account codes, or urgent instructions. Meta has described the beta’s mechanics and privacy design, but its effectiveness will remain an open question until it receives wider testing and independent scrutiny.

This story draws on original reporting from The Verge.

More Internet/

view all ↗