AI assistants now hand out links routinely, wrapped in confident prose and stripped of every context clue you normally use to judge them.
Ask an AI assistant almost anything practical now and you will get links: the login page for a service, the form you need, the download. It is genuinely useful, and it has quietly removed most of the signals people rely on to decide whether a link is trustworthy.
The framing is authoritative. A link in an unexpected email arrives with obvious context — who sent it, whether you were expecting it, whether the wording is odd. A link in an AI answer arrives inside fluent, confident, apparently neutral prose. There is no sender to be suspicious of.
You asked for it. This is the significant one. Scepticism is highest when something arrives unrequested. When you asked a question and received an answer, you are in a receptive frame of mind, and the link feels like the thing you went looking for.
The address is often hidden. Many assistants show a title or a citation number rather than the full address. The information you would use to spot a lookalike domain is one click away rather than in front of you.
The model reproduces something wrong. Language models generate plausible text, and a plausible-looking address is not necessarily a real one. If the generated address happens to be a domain someone has registered — and people do register likely-looking mistakes — you are sent somewhere nobody intended.
The assistant searched, and the search result was poisoned. Assistants that browse the live web inherit whatever is ranking. Search-engine poisoning and malicious advertising are established techniques, and an assistant summarising results has no independent way to know a top result is fraudulent.
The source page was compromised. A legitimate site that has been compromised is still a legitimate site by every reputational measure. An assistant citing it is behaving correctly with bad material.
None of this requires the AI to be attacked or manipulated. Ordinary operation, applied to a web that contains fraudulent pages, is enough — and the confident framing makes the output more persuasive than the same link would be in an email.
Read the actual address before you act. Hover, or long-press on a phone, and look at the domain rather than the display text. Read it right to left: the part immediately before the first single slash is where you are going.
Be most careful when it leads to a login. An article or a reference page is low-consequence. A page asking for credentials or payment is where the cost of being wrong is real, and it is worth navigating there yourself instead.
Treat downloads as a separate decision. A link to a document or installer deserves the scrutiny you would give any download, regardless of how helpful the surrounding answer was.
Verify the claim, not just the link. If an assistant tells you a service has a particular policy or a form at a particular address, confirm it from the organisation’s own site reached independently.
The useful property of live page analysis is that it does not care where a link came from. A page that impersonates a sign-in screen is assessed the same way whether you arrived from an email, a search result, a text message or an AI answer — because the judgement is made on the page itself, at the moment it loads.
That matters more as the sources multiply. Email filtering does not see a link in a chat window. A blocklist does not know about a page created this morning. Something that reads the page as it renders covers the route regardless of how you got there.
Links from AI assistants are neither safe nor unsafe as a category. They are ordinary web links, delivered with unusually high credibility and unusually few context clues — which means they warrant the same check you would give a link in an unexpected email, and the check is easier to skip precisely because the answer felt so helpful.
SafeToOpen checks links in your browser and inbox in real time — free to start.
See plans →