Answer in brief: The model produced 18 true positives, 17 true negatives, two false positives, and three false negatives: 87.5% accuracy, 85.7% recall, and 90% precision.
Can AI reliably flag common scam patterns without blocking every urgent legitimate message? A useful answer has to be narrower than a product claim. This article tests a bounded workflow, publishes the scoring surface, and keeps consequential approval with a person. It does not turn a controlled result into personalized financial advice.
What we tested or analyzed
We evaluated OpenAI GPT-5.6 in a Codex editorial session on 40 synthetic messages built from FTC-documented patterns. Labels were fixed first; no live victim messages, links, phone numbers, or personal data were used.
The original asset is a forty-message corpus, confusion matrix, and error analysis. The complete machine-readable table is available as CSV. The evidence visual below summarizes the primary criterion; its values are also written in text and shown in the table, so the chart is not the only way to obtain the result.
The measured result
The model produced 18 true positives, 17 true negatives, two false positives, and three false negatives: 87.5% accuracy, 85.7% recall, and 90% precision.
The row-level outcome distribution was legitimate: 19, scam: 21. Those labels are deliberately more descriptive than one blended score. A partial, review, stale, exception, or unsupported row can carry a different operational risk from a plainly wrong row, so the CSV preserves the reason beside the disposition.
| Item | Outcome | Evidence or note |
|---|---|---|
| M01 | scam | scam |
| M02 | scam | scam |
| M03 | scam | scam |
| M04 | scam | scam |
| M05 | scam | scam |
| M06 | scam | scam |
| M07 | scam | scam |
| M08 | scam | scam |
| M09 | scam | scam |
| M10 | scam | scam |
| M11 | scam | scam |
| M12 | scam | scam |
| M13 | scam | scam |
| M14 | scam | scam |
| M15 | scam | scam |
| M16 | scam | scam |
| M17 | scam | scam |
| M18 | scam | scam |
| M19 | scam | legitimate |
| M20 | scam | legitimate |
| M21 | scam | legitimate |
| M22 | legitimate | scam |
| M23 | legitimate | scam |
| M24 | legitimate | legitimate |
| M25 | legitimate | legitimate |
| M26 | legitimate | legitimate |
| M27 | legitimate | legitimate |
| M28 | legitimate | legitimate |
| M29 | legitimate | legitimate |
| M30 | legitimate | legitimate |
| M31 | legitimate | legitimate |
| M32 | legitimate | legitimate |
| M33 | legitimate | legitimate |
| M34 | legitimate | legitimate |
| M35 | legitimate | legitimate |
| M36 | legitimate | legitimate |
| M37 | legitimate | legitimate |
| M38 | legitimate | legitimate |
| M39 | legitimate | legitimate |
| M40 | legitimate | legitimate |
Reading the evidence row by row
- M01 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M02 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M03 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M04 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M05 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M06 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M07 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M08 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M09 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M10 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M11 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M12 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M13 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M14 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M15 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M16 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M17 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
- M18 was recorded as scam. The evidence note is “scam”; the disposition remains visible so it cannot be averaged away.
The expected label or control was fixed before review. The visible note explains why the row received its disposition. The chart uses the published primary criterion, but the table is authoritative because it preserves exceptions that a single percentage would hide.
How to reproduce the check
- Download the CSV and read its labels, units, and synthetic/public-data notice before using it.
- Write the expected answers or decision rule before looking at a model response.
- Use the same bounded prompt and record the model or tool, access surface, and date.
- Preserve the raw response. Break prose into atomic claims rather than grading the tone of the whole answer.
- Recompute arithmetic with deterministic formulas and verify definitions against the linked primary sources.
- Record correct, partial, wrong, uncertain, and refused outcomes separately. Do not silently repair the model output before scoring it.
- Repeat material checks after a model, source, or workflow changes.
What the result means
The value of this result is diagnostic. It shows where a structured assistant can reduce search, formatting, or first-pass review work. It does not transfer responsibility for the underlying decision. A “pass” means the row met the published rule in this test, on this date, with these inputs.
The errors and open items matter more than a polished average. In money and business workflows, one missed assumption, stale fact, false match, or overconfident definition can dominate many correct low-risk rows. That is why the artifact keeps row-level outcomes and why a human reviews exceptions rather than receiving only a percentage.
Reproducibility also has limits. A reader can repeat the steps and inspect the same answer key, but a probabilistic model may not return identical wording. A useful rerun should therefore compare atomic claims, calculations, citations, and escalation decisions—not superficial phrasing.
Why this topic needs its own boundary
Personal-finance data are unusually revealing: merchant strings, payment timing, balances, and repeated amounts can expose identity and behavior even when an obvious account number is removed. A privacy-first test asks whether the task can be answered with synthetic, aggregated, or minimized inputs.
The safe outcome is an organized draft for review, not a decision about a real household. Taxes, debt, dependants, currency exposure, and emergency needs are contextual facts that a small synthetic benchmark cannot know.
A safer operating workflow
- Do not click or call using message-supplied details.
- Verify through an independently found official channel.
- Treat urgency, unusual payment methods, and secrecy as risk signals.
- Use a second control when money or credentials are requested.
- Report suspected fraud to the relevant authority.
How each control changes the decision
Control 1: Do not click or call using message-supplied details. For this test, that control answers the bounded question “Can AI reliably flag common scam patterns without blocking every urgent legitimate message?” without extending the result into an untested decision.
Control 2: Verify through an independently found official channel. For this test, that control answers the bounded question “Can AI reliably flag common scam patterns without blocking every urgent legitimate message?” without extending the result into an untested decision.
Control 3: Treat urgency, unusual payment methods, and secrecy as risk signals. For this test, that control answers the bounded question “Can AI reliably flag common scam patterns without blocking every urgent legitimate message?” without extending the result into an untested decision.
Control 4: Use a second control when money or credentials are requested. For this test, that control answers the bounded question “Can AI reliably flag common scam patterns without blocking every urgent legitimate message?” without extending the result into an untested decision.
Control 5: Report suspected fraud to the relevant authority. For this test, that control answers the bounded question “Can AI reliably flag common scam patterns without blocking every urgent legitimate message?” without extending the result into an untested decision.
Keep data collection, model preparation, deterministic validation, and approval as separate stages. Use the least sensitive input that can answer the question. If removing personal or confidential data makes the result ambiguous, route the case to an approved human process instead of restoring secrets to an unapproved tool.
Calculations need an independent formula; current facts need a current primary source; classifications need an “uncertain” route; and irreversible actions need explicit authorization outside the model. Logs should capture the version, prompt, source date, output, reviewer, correction, and final disposition without retaining unnecessary personal data.
Limitations and professional boundary
Scams adapt, language and cultural context matter, and a missed scam can cause serious harm. This is not a security product evaluation.
This publication provides general educational information. It does not know a reader’s finances, duties, jurisdiction, contracts, tax treatment, credit position, or risk tolerance. A qualified financial, accounting, tax, legal, lending, security, or other professional should review decisions with material consequences.
Primary sources
Verified 2026-07-26. Primary-source links can change; use the publication date and linked source to check for a newer version.
Bottom line
The model produced 18 true positives, 17 true negatives, two false positives, and three false negatives: 87.5% accuracy, 85.7% recall, and 90% precision. The practical lesson is to make AI produce inspectable work inside a controlled process—not to make fluency the final control.
