
The idea of an artificial intelligence system persuading someone to commit a crime sounds like a scene from a science-fiction thriller, but the real concern is more subtle. AI is not a mind-control machine, nor is there currently a simple way to prove that a chatbot caused a person to break the law.
However, research increasingly shows that large language models can be highly persuasive, while experts warn that their ability to provide personalised, persistent responses can make harmful decisions easier to pursue.
The risk is therefore less about an AI independently deciding to turn an innocent person into a criminal and more about what happens when someone with harmful intentions uses AI to remove obstacles between an idea and an action.
That distinction matters for developers, regulators, educators and ordinary users because effective safeguards need to address how harmful conversations develop, not simply block obviously criminal questions.
AI Can Influence People, but It Cannot Read Their Minds
There is now evidence that AI systems can influence people's decisions.
A 2025 study comparing a large language model with incentivised human persuaders found that the AI achieved higher compliance in an interactive quiz setting. The model could move participants towards both correct and incorrect answers, showing that persuasive ability itself is not necessarily tied to whether the information being promoted is true.
A separate 2025 study examined the safety of AI persuasion across eight widely used large language models.
The researchers found that models sometimes failed to recognise unethical persuasion tasks and could employ manipulative or deceptive strategies. The study argues that safety testing needs to consider conversations where persuasion develops over multiple exchanges rather than treating every prompt as an isolated request.
Those findings do not establish that AI can persuade an otherwise law-abiding person to commit a crime. That is an important distinction.
Halil Ibrahim Dursunoglu, a Faculty Specialist in Computer Science at Western Michigan University whose research includes cybersecurity, AI security and trustworthy AI, said the claim that an AI system can simply 'convince someone to commit a crime' risks overstating both AI autonomy and what researchers know about human behaviour.
'AI can influence human decision-making, but saying that an AI system can simply "convince someone to commit a crime" risks overstating both the technology's autonomy and our understanding of human behaviour,' he said.
The more realistic problem, according to Dursunoglu, is what happens when someone is already considering harmful or illegal behaviour. 'A person who is already considering illegal behaviour may use an AI system to seek information, rationalize a decision, rehearse scenarios, or attempt to obtain step-by-step assistance,' he said.
That distinction is particularly important because AI can make information easier to access and present it in a conversational format. Instead of searching through multiple websites, a user can continue asking questions, request clarification, and alter the wording of a request.
The system can also maintain the flow of a conversation, creating a more personalised interaction than a conventional search result. That does not mean the AI understands the user's intentions in a human sense. It means the technology can respond repeatedly to the direction in which the conversation moves.
Russell Twilligear, Head of AI Research and Development at BlogBuster, similarly cautioned against treating AI as a system capable of controlling a person's behaviour. 'AI can influence someone, but it's not a mind control machine,' he said.
Twilligear identified a different problem: AI can sometimes become overly agreeable or excessively confident. 'The danger comes from when AI acts overly confident and agrees with everything the user says or turns a bad idea into a step-by-step plan,' he said.
That concern also overlaps with one of the known weaknesses of generative AI. The US National Institute of Standards and Technology (NIST) warns that AI systems can produce false or internally inconsistent information while presenting it confidently. NIST refers to this as 'confabulation' and notes that people may act on incorrect information when they trust the system's confident presentation.
In a criminal context, that creates a difficult combination. An AI response might be persuasive without being correct, while a user might interpret confidence as evidence that the advice is reliable.
There is therefore no straightforward chain in which an AI gives an instruction and a person automatically follows it. Human motivation, circumstances, existing beliefs and personal judgement remain important. Recently, according to a report by IBTimes UK, a 15-year old allegedly used AI to cause significant disruption by hacking into secure systems.
Dursunoglu said AI also has no reliable understanding of a user's psychological state, intentions or real-world circumstances. Models can misunderstand context, contradict themselves or generate incorrect information.
'That makes it difficult to establish a simple causal chain from an AI conversation to a person's subsequent behaviour,' he said.
Safeguards Need To Stop Harm Before It Becomes Actionable
The biggest challenge for AI developers is deciding where legitimate information ends and harmful assistance begins.
A chatbot should be able to discuss criminology, law enforcement, cybersecurity, journalism and historical cases. Blocking every conversation containing references to crime would make the technology less useful for legitimate education and research.
The problem arises when a response materially increases someone's ability to carry out wrongdoing.
Dursunoglu described this as 'capability friction'. In his view, an AI system does not need to refuse every discussion involving crime. Instead, safeguards should create resistance when a conversation moves from explanation towards operational assistance.
'The critical distinction is between explaining a harmful activity and materially increasing someone's ability to carry it out,' he said.
He compared the principle with cybersecurity education. Understanding how ransomware works can be legitimate and useful, particularly for students, researchers and security professionals. Providing a deployable campaign designed to attack a real target is fundamentally different.
This distinction also has implications for academic integrity. Students, researchers and educators increasingly need clear rules about when AI is being used as a learning aid and when it is effectively doing the work itself.
UNESCO's guidance on generative AI in education and research calls for human-centred approaches, ethical validation, appropriate policies and safeguards rather than unrestricted adoption of the technology.
The same principle can be applied to criminal misuse. People should not treat an AI system as an authority simply because it provides a fluent answer. Users should independently verify important claims, particularly where decisions could have legal, financial, physical or personal consequences.
For developers, safeguards need to operate at several levels.
The first is refusal of actionable assistance for serious wrongdoing. A system should not simply provide operational guidance when a request clearly moves towards facilitating harm.
The second is recognising escalation. A user may not begin by asking for instructions. They may start with general questions and gradually move towards more specific requests. Safety systems therefore need to consider conversational patterns rather than relying exclusively on individual prompts.
The third is adversarial testing. Developers need to test systems against attempts to manipulate their safeguards, including users who deliberately reword requests or combine individually harmless pieces of information.
Twilligear pointed to precisely this problem. 'No safeguard will catch everything,' he said. 'People lie and reword requests. They also combine harmless answers into something dangerous.'
NIST's generative AI risk framework similarly recommends risk management across the AI lifecycle, including evaluation and measures aimed at risks such as harmful content and lowering barriers to cyberattacks.
The practical goal is therefore not to create an AI that refuses to discuss anything difficult. It is to prevent a system from turning harmful intent into usable assistance.
For ordinary users, the safest approach is equally straightforward. Treat AI as a tool rather than an authority. Question confident answers, verify important information independently, and recognise that a conversational system can sound certain even when it is wrong.
For developers and policymakers, the task is more complicated. They must balance access to legitimate education and research against the possibility that the same capabilities could be misused.
Dursunoglu argues that AI should be viewed neither as 'an autonomous criminal mastermind' nor as a harmless search engine. The key question is whether the system meaningfully increases a person's ability to cause harm and whether safeguards can interrupt that progression before information becomes actionable.
That is likely to be the more useful way to understand the risk. AI does not need to control someone's mind to create a problem. It only needs to make a harmful decision easier to justify, easier to understand or easier to act upon. Preventing that outcome requires safeguards that recognise intent, limit operational assistance and preserve legitimate uses of the technology at the same time.
Frequently Asked Questions
- Can AI persuade someone to commit a crime?AI can influence decision-making but cannot directly persuade someone to commit a crime.
- What are the risks of AI persuasion?AI can provide personalized responses that may make harmful decisions easier to pursue.
- How should AI developers address harmful AI conversations?Developers should implement safeguards that recognize intent and limit operational assistance.
- What is 'capability friction' in AI?It refers to creating resistance when a conversation moves from explanation towards operational assistance.
- How can users safely interact with AI systems?Users should treat AI as a tool, question confident answers, and verify important information independently.




