New Zealanders are confident they can catch an AI fake, but our judgements don’t match our actions, with 66% of New Zealand adults convinced they’d catch an AI fake the moment they saw one. And 40% have shared, or considered sharing, at least one sensitive item with an AI tool.
Spotting a fake and guarding your own data are very different habits, and that gap sits at the centre of the newly released Avast 2026 Safe Tech Report. Avast commissioned the study to see how people are navigating trust, privacy, and AI in everyday life.
“Being confident you’d spot an AI fake and knowing when and how to protect your data are two different skills – but confidence in one can convince people they’re safe with the other, too, and that’s the trap,” said Richard Watts, Head of Avast. “Chatbots aren’t confidants. Check what a tool actually does with your data before you share anything and remember it’s still somewhere else your information could be exposed. If you wouldn’t want it repeated to a stranger, don’t hand it over to the bots.”
Findings from the latest Gen Threat Report put that confidence to the test: AI was involved in tens of millions of video encounters worldwide in the first half of 2026, and roughly one in every 30 of them was flagged as a scam. At that scale, even a small share adds up to a lot of convincing fakes slipping past exactly the kind of confidence 66% of Kiwis rely on.
“What we see in the threat landscape reinforces what consumers are telling us here. Spotting that something was made with AI is only part of the challenge,” said Michal Salat, Threat Intelligence Director for Gen Threat Labs. “Through our Fearless Planet Index, we see how scams are evolving in the real world, and AI is increasingly making the first impression more convincing. But underneath, attackers are still pulling the same psychological levers – urgency, trust, fear and the promise of something too good to pass up. The technology may be changing, but the human behaviours scammers exploit remains remarkably consistent.”
That same self-assurance is lowering people’s guard elsewhere, including the workplace, with 21% of adults having shared, or considered sharing, a CV with an AI chatbot and 17% having done the same with a work document, treating it as a one-off exchange.
But the bigger risk in 2026 isn’t a one-time leak. It’s that AI tools remember, which means a CV or a work document shared may not disappear when the tab closes; it can sit in a system’s memory long after the conversation ends, where it could be exposed in a future data breach, surface in someone else’s chat, or be folded into training data, all without the person’s knowledge.
People know the classic red flags; they just talk themselves past them. The report found the easiest warning signs adults shrug off in the moment include an offer that looks too good (42%), a request for personal details to “verify” identity (39%) and pressure to act fast (38%).
Real-world scam data backs this up; research from Gen Threat Labs into fake celebrity videos and AI-generated scam content found a similar pattern. The realistic face or voice is just the wrapping, while the too-good offer, the urgency, and the request to “verify” personal details are what’s doing the persuading. The very red flags people take least seriously are also the ones today’s AI scams rely on most to succeed.