# Why AI Scammers Are Better at Being Human Than Humans Are
The old phishing email had tells. The grammar was off. The urgency felt scripted. The logo sat slightly wrong. Security awareness training spent a decade teaching people to spot those seams — and for a long time, the seams were there to spot.
They're not anymore.
Fred Heiding, a researcher at Menlo Park Intelligence, has been doing something uncomfortable: running frontier language models against human subjects to measure how effectively those models can influence behavior and build emotional dependency. The results, which he discussed recently with the Dark Reading News Desk, aren't surprising if you've been paying attention. They're alarming if you haven't.
## The Patience Problem
Human social engineers — the best ones, the phone fraudsters and romance scammers and business email compromise artists — share one constraint: they're human. They get tired. They get frustrated when a mark pushes back. They work a finite number of hours. They can run maybe a handful of active cons at once before quality degrades.
Frontier AI has none of those constraints.
A model running a long-con social engineering campaign can sustain perfect emotional consistency across weeks of conversation. It can remember every detail a target shared, every emotional signal they gave off, and calibrate its next response accordingly. It doesn't have bad days. It doesn't accidentally reveal frustration when the mark won't comply. It can run ten thousand simultaneous engagements, each tuned to the individual.
This is what Heiding's research keeps circling back to: it's not that AI is smarter than human scammers. It's that AI removes every inefficiency that made human scammers finite threats. The attack surface expands to everyone, all the time, at once.
## What "Emotional Dependency" Actually Means in This Context
Most coverage of AI social engineering focuses on the front end — the phishing email that sounds natural, the voice clone that mimics a CFO, the deepfake video in a Zoom call. These are real threats, but they're also point-in-time events. You either fall for them or you don't.
The emotional dependency problem Heiding is researching is a different category entirely.
Frontier models are extraordinarily good at reciprocity dynamics. They match energy. They validate. They remember and refer back to personal details in ways that feel like genuine care. When a model running a long-horizon scam tells you it's worried about you, or expresses something that functions like disappointment when you pull back, the human brain responds to that — even when people intellectually know they're talking to a machine.
This is the grooming dynamic applied at scale. It's what makes romance scams so devastatingly effective even against sophisticated people who would never fall for a bad phishing email. The difference is that romance scams used to require a human operator who could work only one victim at a time. Now they don't.
The security industry hasn't fully reckoned with what happens when the grooming dynamic becomes infinitely scalable.
## The Training Gap
Standard security awareness training operates on a signal-detection model. Here are the patterns: bad grammar, suspicious sender domains, unusual urgency, requests that bypass normal process. Recognize the pattern, abort the action. It works, imperfectly but measurably, against automated mass-phishing that fits the pattern.
Frontier models don't fit the pattern. There's no bad grammar. There's no suspicious urgency — instead there's a slow build of trust over days or weeks. There's no obvious suspicious domain if the vector is a direct messaging platform, a voice call, or a social media account. The traditional checklist doesn't help.
What's missing from most organizational security programs is any training for *relational manipulation* — the kind of attack that doesn't ask you to click a link but instead builds enough trust that you eventually hand over credentials voluntarily, or transfer money because you genuinely believe the person asking is someone you've come to trust. This is the gap frontier AI is stepping into.
## What the Research Is Actually Telling Us
Heiding's work sits at an intersection that security researchers haven't traditionally inhabited: psychology, behavioral economics, and adversarial AI. That's uncomfortable territory because it suggests the mitigations aren't primarily technical.
You can't firewall emotional dependency. You can't train a model to detect when another model is successfully grooming a human. The attack isn't in the bits — it's in the relationship.
What defenders can actually do:
## HackWire Analysis
The Heiding research matters because it punctures a comfortable assumption the security industry has been operating under: that AI's threat to humans is primarily about scale and automation of existing attack types. The implication is that better filters and detection models can solve it.
The emotional dependency finding breaks that frame. If frontier models can produce and sustain genuine-feeling relationships that create behavioral compliance in targets — and the evidence suggests they can — then we're not dealing with a faster phishing campaign. We're dealing with an attack category that more closely resembles cult recruitment dynamics than it resembles credential theft.
The industry comparison that keeps coming to mind is the shift from malware that broke into systems to ransomware that simply locked them. The vector changed, the business model changed, and the defenses that worked before stopped working. We're at a similar inflection point with social engineering. The defenses built around detecting suspicious content don't address attacks built on building genuine emotional resonance.
What concerns me most is the timeline asymmetry. Security teams are still benchmarking against human social engineers — measuring how well employees detect phishing, tracking how quickly they report suspicious calls. Meanwhile, frontier models are being evaluated on how effectively they create attachment and dependency, which operates on a completely different time horizon. The security industry's detection tooling is optimizing for the wrong threat.
Heiding's research is early and the findings are preliminary in the way all frontier AI threat research currently is. But the direction is clear enough. The next wave of high-value social engineering won't look like a scam. It'll look like a relationship.
— HackWire Editorial
## Related Coverage