Guides
Seventeen guides, in plain language
Drafted with AI assistance and reviewed by a person before publication — the same practice we recommend in these pages. Open to read, print, and share, with no account and no email required. If you’re brand new to this, start at the top.
Guide 01What is AI, really?
Minus the hype: AI is a very good pattern-matcher. It has read an enormous amount of text, images, and sound, and gotten good at predicting what usually comes next. When you ask a chatbot a question, it isn’t “thinking” the way you do — it’s assembling the most likely helpful answer, one word at a time. Think of it as the most well-read assistant you’ve ever met, who has skimmed a library’s worth of books but doesn’t truly understand any of it.
That’s why it’s useful — and why it’s not magic. It can draft a letter or summarize a document in seconds. But because it’s predicting rather than knowing, it can state something completely wrong with total confidence. There’s even a word for it: a “hallucination.” That’s a normal part of how the tool works, not a rare glitch.
The one idea to hold onto: AI is a tool, like a calculator or a car — powerful for certain jobs, and only as trustworthy as your own double-check. You stay in the driver’s seat. Knowing that is exactly what keeps you a step ahead of the people who misuse it.
Last reviewed August 2026 · Next: your first conversation →
Guide 02Your first conversation with an AI chatbot
If you’ve never used one, here’s the whole thing: you type a question or request in ordinary English, and it writes back. There’s no wrong way to hold it, nothing to break, and nobody watching you learn.
Start with something you already know the answer to. Ask it to explain how a microwave works, or what to do with the vegetables in your fridge. When you already know the subject, you can feel where it’s useful and where it’s confidently wrong — and that instinct is the whole skill.
Talk to it like a person, not a search engine. You don’t need special words. “My landlord won’t fix the heater, help me write a polite but firm letter” works better than typing “landlord heater letter.”
Three things worth knowing:
- You can ask it to change the answer. “Shorter.” “Less formal.” “Explain that like I’ve never heard of it.” Going back and forth is normal and expected.
- You can ask it to explain itself. If a word goes over your head, say so. “What does that word mean?” is a perfectly good message. It will not think less of you.
- It doesn’t remember you between conversations unless you’ve turned that on. Each new chat generally starts fresh.
A few starters to copy: “Explain what a deductible is like you’re explaining it to a friend.” · “Help me write a thank-you note for a job interview.” · “Summarize this letter and tell me if it needs a reply.” · “Give me five easy dinners using chicken, rice, and whatever’s cheap.”
What not to do on day one: don’t type in anything private, and don’t take an important answer at face value — about health, money, or law especially. Use it to get oriented, then check anything that matters.
Last reviewed August 2026
Guide 03A plain-English glossary of AI words
You don’t need this vocabulary to use AI — but you’ll hear these words on the news and from salespeople, and knowing what they mean makes it much harder to be impressed by nonsense.
- AI (artificial intelligence)
- A broad label for software that does things we used to think required a person — recognizing a face, writing a paragraph, suggesting a route.
- Chatbot
- An AI you talk to in ordinary language. ChatGPT, Google’s Gemini, and Microsoft’s Copilot are the common ones.
- Model
- The trained system underneath a chatbot. “A new model” means a new version of the engine.
- Prompt
- Whatever you type in. That’s all the word means.
- Training data
- The enormous pile of text and images the system learned patterns from. If something wasn’t in there, it may not know it.
- Hallucination
- When AI states something false with complete confidence — an invented fact, quote, or source. Common and expected, not rare.
- Generative AI
- AI that produces new content — writing, images, voices, video — rather than just sorting or finding things.
- Deepfake
- A fake image, video, or audio clip of a real person, made to look and sound genuine.
- Voice cloning
- Copying someone’s voice from a short recording so software can make it say anything. The engine behind “family emergency” phone scams.
- Algorithm
- A set of rules a computer follows. Older and broader than AI — the thing choosing what you see on social media is an algorithm.
- Machine learning
- The general method behind most modern AI: learning patterns from examples instead of being given explicit rules.
- Bias
- When a system’s answers skew unfairly, usually because the examples it learned from did.
- Agent
- An AI given permission to take actions on its own — browsing, booking, sending — not just answering. Newer, and worth extra caution.
- Copilot / assistant
- Marketing names for an AI built into a product you already use, like your email or word processor.
Last reviewed August 2026
Guide 04Using ChatGPT and other AI tools safely
An AI chatbot — ChatGPT is the best-known, and there are others like Google’s Gemini and Microsoft’s Copilot — lets you type a question in plain English and get a plain-English answer. Used well, it’s genuinely handy. Two rules keep it from biting you.
- Don’t hand over private information. Assume anything you type could be stored or seen by someone at the company. No Social Security numbers, no bank or card numbers, no passwords, no medical records with your name attached. If you’d hesitate to write it on a postcard, don’t paste it in.
- Treat every answer as a confident first draft, not gospel. These tools predict; they don’t know. They can invent a fact, a quote, or a “study” that never existed. For anything that matters, use it to get oriented, then confirm with a real source or a real professional.
Good, low-risk jobs for it: drafting an email you’re dreading, explaining a confusing letter in simple words, summarizing something long, brainstorming a list, or turning rough notes into something tidy. Keep the important decisions yours.
Last reviewed August 2026
Guide 05How to choose an AI tool
You don’t need to find “the best” AI tool. There isn’t one, and the answer would change by the time you finished reading about it. The useful question is smaller and it stays useful: what am I trying to do, and can I do it here safely, clearly, and at a price I understand?
This guide is about how to choose. Brands and features change constantly. The questions below don’t.
Start with the job, not the tool. “I should use AI” isn’t a goal. These are: rewrite my résumé bullets; summarize this long document; explain this letter in plain words; practice for an interview; help me draft a difficult email; check whether a message looks like a scam. Write your goal in one sentence. If you can’t, wait — the tool won’t clarify it for you, it will just produce confident words about whatever you type.
Start free, and start reversible. For almost everything on that list, a free option is enough to begin, and you may already have one built into your phone, your browser, or your word processor. You don’t need to buy anything to learn this. If a trial asks for a card, find the cancellation path before you start — and if you can’t find it easily, that itself tells you something about the company.
Pick one you can actually understand. A powerful tool you never open is worth nothing. Can you find the buttons? Can you start over? Can you copy your work out, or delete it? Is the help page written for a person or for an engineer? Confusing design isn’t your failing — it’s a sign the thing wasn’t built for you, and there are others.
Decide your privacy rules before you paste anything. A workable starting line: nothing that could seriously hurt you or someone else if it were seen. No account or ID numbers, no passwords, no medical records, no one else’s private information, nothing your employer or school treats as confidential. If a tool offers settings to turn off training on your chats, or a temporary conversation mode, look for them. Menus move; the habit of looking is what lasts.
Free usually means the business model is somewhere else — advertising, product improvement, or an upsell to a paid plan. That’s ordinary and it doesn’t make a tool bad. It does mean a free chat box is not a private diary.
Test it on your own real task, not a party trick. Don’t choose based on a clever poem in someone’s screenshot. Give it something you actually need, then ask for a shorter version, then ask what it might have gotten wrong, then check any fact you intend to act on. You’re hiring a fast assistant who sometimes invents details. Your job is editor.
Look for honesty about limits. Tools worth your time tend to admit the system can be wrong, make it obvious you’re talking to software, and give you a way to report a problem. Be wary of anything promising perfect accuracy, guaranteed income or a guaranteed job, or that it can replace a doctor, lawyer, or accountant — and be especially wary of pressure to decide right now. Scams love urgency. Real tools can wait while you think.
Only pay when you can name what you’re buying. Three conditions: you already use the free version enough to hit its limits, you can say in one sentence what paying gets you, and you know how to cancel. “Everyone says the paid one is better” is not a reason.
One tool is enough to start. You don’t need a collection. Pick one general assistant and add a second only when you have a repeated job the first one handles badly. Switching later is normal, and the skills carry over — asking clearly, protecting private information, checking what matters. Those work everywhere, which is why they’re worth more than any brand.
What’s mostly noise: leaderboards and benchmark scores, model sizes, “most advanced” and “most human-like” marketing, which company is in the news, and long feature lists you’ll never touch. These are how the industry talks to itself. None of them tell you whether a tool will help you write a cover letter on your phone.
Before you commit time or money, seven questions. Can I say my goal in one sentence? Can I try it without locking myself in? Does it work on the device I actually use? Do I know what I’ll never paste into it? Have I tested it on something real? Is the company honest about its limits instead of pressuring me? If it costs money, do I know what I’m buying and how to leave? Several “no” answers means keep looking — or that you don’t need a new tool yet.
A good choice for most people is rarely the flashiest one. It’s the one you understand well enough to use carefully: it helps you draft and think, your private things stay private, and you keep the judgment. If you feel behind, you aren’t. Most people are still working this out, and choosing slowly after testing it on your own work isn’t a beginner’s move. It’s the competent one.
Last reviewed August 2026 · We don’t review or rank individual AI products, and we accept no payment or free access from any company whose tools we mention.
Guide 06Using AI to help with a job application
This is one of the most genuinely useful things AI does — and one of the easiest to get wrong in a way that costs you the job. The line is simple: AI can help you say what’s true about you more clearly. It should never invent what’s true about you.
What it’s good at:
- Turning a plain list into proper resume lines. Give it your real duties in your own words and ask it to tighten them. You supply the facts; it supplies the polish.
- Cover letters. Paste the job posting, describe your genuine relevant experience, ask for a draft — then rewrite it in your voice. The first draft always sounds like a robot in a suit.
- Interview practice. “Ask me five likely questions for this job, one at a time, then tell me how to improve my answers.”
- Decoding a posting. “What is this job actually asking for, in plain terms?”
- Naming your experience properly. Many people undersell themselves because they don’t know the industry word for what they did for fifteen years. Describe it plainly and ask what it’s called.
Three hard rules. (1) Never let it claim a job, degree, certification, or skill you don’t have — that ends careers, not just applications. (2) Read every word before it goes out; it will occasionally invent a detail. (3) Make it sound like you. If you’d never say “leveraged synergies,” take it out — hiring managers read a lot of AI-flavored sludge, and plain writing stands out.
Don’t paste your whole personal history in. Work experience is fine. Social Security number, date of birth, home address, and references’ phone numbers are not.
Watch the scam side of job hunting. AI has made fake postings and fake recruiters far more convincing. Three FTC-verified rules: honest employers never ask you to pay for starter kits, training, or certifications — “Anyone who does is a scammer.” No honest employer sends you a check to deposit and then asks you to send part of the money on, or to buy gift cards with it. And the FTC’s newer warning: ignore unexpected texts or messaging-app messages about jobs — “Real employers will never contact you that way.”
Last reviewed August 2026 · Sources: FTC on job scams · FTC, “That job offer text is probably a scam”
Guide 07AI at work: what to know first
Plenty of people quietly use a chatbot to get through the workday. Usually that’s fine. Occasionally it’s a fireable mistake. The difference is worth five minutes.
Check whether your employer has a policy. Many now do, and it’s often permissive — but “I didn’t know” is a poor defense. If there’s an approved tool, use that one: workplace versions typically have different privacy terms than a personal account.
Don’t paste in anything that isn’t yours to share. Customer records, patient information, student data, employee files, unreleased plans, financials, anything under a nondisclosure agreement or attorney-client privilege. Pasting it into a personal AI account may count as disclosing it outside the company — regardless of your intent.
The test: if you wouldn’t email it to a stranger for feedback, don’t paste it into a personal AI account.
Anything that goes out with your name on it is yours. AI drafts; you’re accountable. Check the numbers, the names, the dates, and every claim. “The AI wrote it” has never once been a satisfying explanation to a customer or a boss.
Where it genuinely helps: first drafts of routine writing, summarizing long threads or documents, reformatting information you already have, preparing for a difficult conversation, explaining an unfamiliar term, or getting unstuck on how to start.
Last reviewed August 2026
Guide 08When not to use AI: health, money, and legal
A chatbot will answer a medical, financial, or legal question instantly, in a calm and authoritative voice, whether or not it’s right. It has no license, no accountability, no knowledge of your particular situation, and no way to tell you when it’s out of its depth. That combination is why these three areas deserve a rule of their own.
The rule: use AI to prepare, never to decide.
Good uses — getting oriented:
- “What does this word in my lab results mean?” — so you understand the letter in front of you.
- “What questions should I ask my doctor about this diagnosis?” — walking in prepared is a real benefit.
- “Explain in plain terms what an index fund is.” — general concepts, not what you should buy.
- “What does this clause in my lease generally mean?” — then take it to someone who can actually advise you.
Bad uses — deciding: whether to take a medication or change a dose; whether a symptom is serious; which investment to put your savings in; whether to sign, sue, settle, or plead. Those need a professional who is licensed, accountable, and actually looking at your situation.
In an emergency, don’t type — call. Chest pain, signs of a stroke, or any medical emergency:
call 911. For thoughts of suicide or self-harm, or any mental-health crisis, the
988 Suicide & Crisis Lifeline is free, confidential, and staffed 24 hours a day —
call or text 988, or chat at
chat.988lifeline.org. Text and chat are available in Spanish, and there is a dedicated line for veterans and service members. AI is never the right first responder.
One more, because it’s how people lose money: anything promising a specific financial return is either a guess or a scam. Real advisers can’t guarantee returns either — the difference is they’re accountable when they’re wrong.
Last reviewed August 2026 · Crisis support: 988 Suicide & Crisis Lifeline — call or text 988
Guide 09Your data and privacy when using AI
Most AI tools are apps or websites run by a company. That’s the whole mental model. Depending on the tool and your settings, what you type may be stored, reviewed by staff, or used to improve the product — so the useful question isn’t “is AI safe?” but “would I be comfortable if someone at this company read this?”
The postcard test: if you’d hesitate to write it on a postcard, don’t paste it in.
Don’t paste these into a personal AI account:
- Social Security or government ID numbers, passport or tax documents
- Bank, card, or account numbers
- Passwords, security questions, or one-time login codes
- Health details tied to a name — charts, insurance IDs, claim numbers
- Someone else’s private information: a client’s, a patient’s, an employee’s
- Anything under an NDA, attorney-client privilege, or student-records rules
Settings help, but they aren’t a privacy guarantee. Many tools let you turn off using your chats for training, and some offer a temporary or no-history mode. Both are worth finding. Neither makes a conversation private from the company. Delete conversations you no longer need, and put a strong, unique password and two-step verification on the account itself.
Watch what you upload, not just what you type. Photos and files can carry hidden metadata, including location or device details. Documents carry names, addresses, and account numbers you forgot were in there. Crop screenshots so only the needed part shows.
Be careful with unknown AI apps and browser extensions. An app promising miracles may exist mainly to harvest your data or contacts. Extensions are the sharper risk: an “AI assistant” extension may be able to read every page you visit, including your email and bank. Prefer well-known tools, and be suspicious of anything demanding access to your photos, contacts, or messages without a clear reason.
Don’t let the tool talk you into it. “Paste the whole document and I’ll redact it for you” still means you pasted the whole document.
One more, and it connects to the scams: be thoughtful about how much of your voice and face you post publicly. A short clip of clear audio can be enough to build a convincing fake — the FTC describes scammers working from “a short audio clip… which he could get from content posted online.”
Last reviewed August 2026
Guide 10How to spot an AI scam or deepfake
AI has made scams cheaper, faster, and far more convincing. The good news: the warning signs haven’t changed much — you just need to know what today’s version looks like.
What’s new. Scammers can clone a voice from a short audio clip taken off the internet, fake a video of a real person, and write flawless emails with no clumsy typos. A call that sounds exactly like your daughter, or a video of a public figure “endorsing” an investment, can be manufactured. The polish is fake. The pressure is real.
The tells are almost always the same three things:
- Urgency. “Act now,” “your account will be closed,” “wire the money within the hour.” Real institutions don’t work on a countdown clock. Scammers do, because panic stops you from checking.
- An unusual payment. Gift cards, wire transfers, cryptocurrency, or “just read me this code.” The FTC is blunt about this one: “No real business or government agency will ever tell you to buy a gift card to pay them.” If someone who sounds like family asks you to buy gift cards and read them the numbers off the back, that is the scam, not your relative.
- A channel you didn’t choose. A surprise text, pop-up, or call. The safe move is to reach them yourself, on a number you look up.
The one habit that protects you: slow down and verify on a second channel. Hang up and call back on a number you already have. Don’t tap the link — call the number on the back of your card. A deepfake can fake a face and a voice; it can’t fake being reachable at the real number you already know.
Last reviewed August 2026 · Sources: FTC on gift card scams · FTC on AI-enhanced family emergency scams · Report fraud: reportfraud.ftc.gov
Guide 11The fake “family emergency” call
The phone rings. It’s your grandchild — crying, in an accident or in jail, begging for money and whispering “please don’t tell Mom.” The voice is exactly right. Every instinct says help now. That instinct is precisely what the scam is built to exploit.
How it works. As the Federal Trade Commission puts it, all a scammer needs is “a short audio clip of your family member’s voice — which he could get from content posted online — and a voice-cloning program.” Add a spoofed caller ID so the screen shows a familiar name, a story soaked in urgency, and a demand for secrecy, and a stranger can sound like family.
The three red flags, together: extreme urgency, a plea for secrecy (“don’t tell anyone”), and a request for an unusual payment — gift cards, a wire, cash in an envelope, or crypto. Real emergencies don’t usually come with all three.
What to do in the moment — this is the FTC’s advice, and it works. Resist the pressure to send money immediately. Hang up, or say you’ll call right back. Then call the person on a number you already know is theirs. If you can’t bring yourself to hang up, the FTC suggests asking something only the real person would know — their examples are “What kind of dog do you have?” or “Where did you spend Thanksgiving last year?” Treat that as a stall, not as clearance: family details turn up on social media and in data breaches, so a correct answer does not prove it’s really them. Whatever they say, don’t send money or read out a code while still on that call. And this line matters most of all: “Call someone else in your family or circle of friends, even if the caller said to keep it a secret.” The demand for secrecy exists precisely to stop you doing that.
And if you can’t reach them — that is not proof the emergency is real. It is the most dangerous moment, because the scam is counting on you filling the silence with panic. A phone can be off, dead, or in a pocket. Call another relative, or call the place named in the story — the jail, hospital, or school — on a number you look up. Still send nothing on the first contact.
Worth setting up in advance. Many families agree on a password or phrase that anyone can ask for on an upsetting call. It only helps if everyone remembers it under pressure, so treat it as a supplement to hanging up and calling back, never a replacement — the safest next step is reaching the person through a number or channel you already trust, or reaching someone else who can. And tell the people in your life this scam exists; knowing the script in advance is half the defense.
Last reviewed August 2026 · Source: FTC, “Scammers use fake emergencies to steal your money” · Report fraud: reportfraud.ftc.gov
Guide 12Romance, investment, and crypto scams
These are the scams that empty retirement accounts, and AI has made them far more convincing. They work slowly — building trust over weeks or months — so the ask, when it comes, feels like helping a friend or seizing a once-in-a-lifetime chance.
Romance scams. A warm, attentive person meets you online. The relationship deepens fast, but you never quite manage to meet in person — the camera “won’t work,” or a video call looks oddly stiff (that can be a deepfake). Then comes a crisis or an opportunity that needs money. AI writes the tender messages and can even generate a face that doesn’t exist.
Investment and crypto scams. A friendly stranger (sometimes after a “wrong number” text) introduces a can’t-lose opportunity. You’re pointed to a slick app or website that shows your balance climbing. It’s fake. When you try to withdraw, there’s a “tax” or “fee” to pay first — and then another. The FBI has warned about this stage repeatedly, and recent cases add a new twist: couriers sent to collect cash in person.
If you are being told to pay a fee or tax to release your money, stop here. This is the single most expensive moment in the whole scam, because it feels like the last step before getting everything back. The FBI is unambiguous: victims “are unable to get their money back, even if they pay the imposed fees or taxes,” and “paying the scammers will not result in you recovering your funds.” The money already showing in your account was never there. Every additional payment is simply a new loss.
The pattern under both: someone you haven’t met in person + a request for money or cryptocurrency + urgency or secrecy + promises that sound too good to be true.
How to protect yourself: Never send money or crypto to someone you haven’t met in person. Be deeply skeptical of “guaranteed” returns — they don’t exist. Do a reverse image search on profile photos, which the FTC recommends. And before you invest or send anything, tell one person you trust; scammers work hard to keep you from doing exactly that.
Last reviewed August 2026 · Sources: FBI IC3 public service announcement on cryptocurrency investment fraud · FTC on romance scams · Report online crime to ic3.gov as soon as possible, whatever the amount
Guide 13“Is this real?” Checking what you see
AI can produce a photo, a video, a voice, or a news-sounding article that looks completely genuine. You don’t need to be a detective — you need a few quick habits before you believe, share, or act on something.
Pause before you share. The most powerful step is the boring one. AI hoaxes spread because they’re built to make you feel something — outrage, fear, a great deal — and share fast. A ten-second pause defuses most of them.
Ask three questions:
- Where did this actually come from? A screenshot with no source, or an account you’ve never heard of, is a reason for caution. Real news shows up in more than one reputable place.
- Does it want a reaction from me? “Share before it’s deleted” or a too-good-to-be-true offer is engineered to skip your judgment.
- Can I confirm it somewhere I already trust? Search the claim. If a public figure “said” something shocking, a real quote appears in real outlets.
Bottom line: you don’t have to prove something is fake. You just have to not treat “it looks real” as proof that it is real. Verify before you trust.
Last reviewed August 2026
Guide 14Deepfakes in the news
Alongside stolen accounts, one of the most common harms from AI-generated media is a false belief — spread fast by people who thought they were helping. This one asks something small of you: a pause.
Why it works. A fabricated clip of a public figure doesn’t have to fool you forever. It only has to fool you for the five seconds it takes to hit share. Emotional content travels faster than corrections, and the correction never reaches everyone who saw the original.
Four questions before you pass it on:
- Who is the source, and where else is it? Look for independent confirmation from outlets that do their own reporting — not the same clip re-uploaded in ten places. If a major story hasn’t been confirmed anywhere else yet, wait.
- How does it want me to feel? Fury, fear, and vindication are the emotions engineered to bypass judgment.
- Does the claim match what’s actually shown? Captions lie about real footage constantly. Old video from another place or year gets relabeled as today’s news.
- Can I find the original? Search the claim, or look for the earliest post and its date.
A note on “spotting” fakes. You’ll be told to look for odd hands, strange blinking, or garbled background text — those tells do still appear. But detection by eyeball is a losing race as tools improve. Source-checking is the durable skill.
Don’t share it to ask if it’s real. Posting “is this true?” still spreads it. Ask someone privately, or check first.
A different kind of deepfake, and a different response. Intimate images of real people shared without their consent — including AI-made ones, and including of teenagers — are a serious harm, and the answer isn’t fact-checking. Don’t view, share, or forward it “as a joke.” There are free tools and a legal right to removal: see guide 17.
The flip side worth knowing: as deepfakes spread, some people dismiss real evidence as “probably AI.” Healthy skepticism means checking the source — not concluding nothing is real. The goal is to be hard to fool, not impossible to convince.
Last reviewed August 2026
Guide 15What to do if you got scammed
First: this happens to smart, careful people. It is not a character flaw, and shame is the scammer’s best friend — it keeps you quiet when you should be acting. Move fast and calmly. Here’s the order that matters.
- Stop. End all contact. Don’t send another dollar — including to anyone who now offers to “help you recover” the money (that’s often the same crew, twice).
- Call your bank or card company right now. Use the number on a recent statement or the back of your card — not a number from a search result, because scammers buy ads to put fake numbers at the top. Speed matters, and there are real deadlines below.
- Change your passwords, starting with your email — it’s the master key to everything else. Turn on two-step verification where you can.
- Report it. The FTC at reportfraud.ftc.gov. If you gave up your Social Security number or other personal details, also go to IdentityTheft.gov — that’s a different FTC service that builds you a recovery plan. For anything online, the FBI’s IC3 at ic3.gov. You can also complain to the Consumer Financial Protection Bureau at consumerfinance.gov/complaint or 855-411-2372, which is worth doing if your bank won’t help.
- Freeze your credit at all three bureaus. It is free by federal law, doesn’t affect your credit score, and you can lift it any time. See the next guide for how.
- Write down what happened while it’s fresh: numbers, names, amounts, dates, screenshots.
- Tell someone you trust. A second set of eyes helps, and it breaks the isolation the scam depends on.
Know this before you call the bank — it is the difference between getting your money back and not.
People are often told “you authorized it, so there’s nothing we can do.” That is frequently wrong. Federal rules draw the line at who actually moved the money:
- If a scammer tricked you into giving up your login, debit card number, or a code, and then they moved money out of your personal bank account electronically — that may well be an unauthorized electronic transfer. The Consumer Financial Protection Bureau has stated this plainly, including when the caller pretended to be your own bank. Tell your bank you are reporting an unauthorized transfer and ask them to investigate under their error-resolution process (Regulation E). If they tell you it isn’t covered, don’t stop there — ask what recall, reversal, fraud-department, or complaint options exist. Note this rule covers personal bank and prepaid accounts; wires, checks, business accounts and credit cards work differently.
- If you sent the money yourself — you made the transfer, wrote the check, sent the wire — federal protection generally does not apply, and the FTC is blunt that you probably won’t get it back. Ask anyway. It is still always worth asking whoever you paid whether it can be reversed.
The deadlines are real. For an unauthorized electronic transfer, report it within 60 days of the statement that shows it. Miss that window and you can be liable for everything after it. If your physical card or phone was lost or stolen, report within 2 business days to cap your liability at $50. Those $50/$500 tiers are the rules for a lost or stolen card or device. If your card never left your wallet and someone used phished details to move your money without permission, that is still an unauthorized transfer you should report as such — the lost-and-stolen schedule simply isn’t the rule that fits your situation, and reporting inside the 60-day window generally means no liability at all. Being phished does not put you outside the protection.
For a credit card, your liability is capped at $50 by law, and if only the number was stolen you generally owe nothing. To dispute formally, write to the address for billing inquiries (not where you send payments) within 60 days of the statement.
How you paid changes what’s possible. Gift card: call the card company immediately, say it was used in a scam, ask for a refund, and keep the card and the receipt — the FTC publishes a list of gift card company contact numbers. Wire transfer: domestic wires have no federal error-resolution right, so call within minutes and ask for a recall. Money sent abroad through a remittance service: call the provider immediately. You may have a legal right to cancel within 30 minutes of paying — but generally only if the money hasn’t yet been picked up or made available to the recipient, so minutes genuinely matter. Zelle or a similar app: the authorized-versus-unauthorized rule above is what decides it.
Watch for the follow-up. Once you’ve been scammed, your details may be sold, and a second crew often arrives offering to recover your money for a fee. Be extremely skeptical of anyone who contacts you with that offer. Note that your bank, card company, or law enforcement genuinely might call you — so the rule isn’t “ignore everyone,” it’s hang up and call back on a number from your statement, the back of your card, or the agency’s official site — never a number they gave you.
Last reviewed August 2026 · This is general information, not legal or financial advice. Sources: CFPB Electronic Fund Transfer FAQs · Regulation E §1005.6 · FTC, “What to do if you were scammed”
Guide 16Helping someone else without taking over
If you’re the person your family calls when something looks strange online, this one’s for you. The goal isn’t to take over — it’s to make the safe move the easy move.
Start with respect, not alarm. The fastest way to lose the conversation is to make someone feel foolish or supervised. Try: “There’s a scam going around that fooled a friend of mine — can I show you what it looks like?” You’re sharing intel between adults. Nobody who feels judged calls you when something goes wrong — and you want them to call.
Agree on the call-back habit — and consider a family password. The safest default move, and the one the FTC recommends, is simple: on any upsetting call asking for money, hang up and reach the person through a number or channel you already trust — or reach someone else who can check on them. Many families also agree on a password anyone can ask for. It only helps if everyone remembers it while panicking, so teach the call-back first and treat the password as a bonus.
One rule that covers most scams: nothing moves on the first call — no money, and no codes. Anything urgent survives a hang-up and a call back on a number you already have.
Make yourself the second opinion. “Text me a photo before you pay anything unusual — I’ll look, no judgment.” Being an easy, shame-free phone call is worth more than any filter.
Practical things you can do together:
- Turn on two-step verification (an extra login check on the phone) for email and bank accounts.
- Turn on “silence unknown callers” — but keep a short allow-list for doctors, the pharmacy, and family.
- Ask the bank about alerts for large or unusual transfers, and about adding a “trusted contact” — someone the institution may call if they suspect something is wrong. Brokerages are required to ask for one; banks may or may not offer it. A trusted contact cannot see the account or move money, so it costs nothing in control.
- Freeze credit at all three bureaus — Equifax (800-685-1111), Experian (888-397-3742), and TransUnion (888-909-8872). It has been free by federal law since 2018, it does not affect credit scores, and it can be lifted online in about an hour when you need credit. You must do all three; a freeze at one doesn’t cover the others. What it does: blocks new accounts being opened in your name. What it does not do, in the CFPB’s words: it “doesn’t prevent identity thieves from taking over existing accounts” — and it can’t stop money someone was talked into sending themselves.
- If identity theft already happened, ask for an extended fraud alert. It lasts seven years, and you qualify once you’ve filed an identity theft report at IdentityTheft.gov or with the police. Unlike a freeze, you only need to contact one bureau — they tell the others. Most people have never heard of this one.
- A paid “credit lock” is not the same thing. A freeze is a legal right and free; the CFPB says locks are “no more effective than security freezes, which are free and which you have a right to by law.” Don’t pay for what the law already gives you.
- The Do Not Call registry is not scam protection. It can reduce legitimate telemarketing, but criminals ignore it and spoof numbers anyway.
If it already happened, lead with support. “Thanks for telling me — this happens to careful people, let’s fix it” gets you to the bank faster than “how did you fall for that?”
Last reviewed August 2026 · Sources: FTC on credit freezes and fraud alerts · CFPB on identity theft · See: what to do if you got scammed
Guide 17If someone shares an intimate image of you
This covers real photos and AI-generated fakes alike. If this is happening to you or to someone you’re helping: there are free tools that work, platforms covered by federal law owe you a fast removal, and none of this is your fault.
Save the evidence first — that one step really is first. Screenshots, links, usernames, dates, messages. Taking content down erases the proof a case would need later. After that, do the rest at the same time, not one after another. Don’t wait for a platform deadline before reporting a crime, and don’t let a step you can’t complete stop you doing the others.
- Save the evidence. Links, usernames, dates, messages, screenshots of where it appears.
- Block it from spreading, free and privately — if you still have a copy of the image. If you only have a link, skip straight to the next steps; this one needs the file. Your image never leaves your device — the tool creates a digital fingerprint and shares only that, so nobody views your picture.
- If the person was under 18 when the image was made — even if they’re an adult now — use takeitdown.ncmec.org, run by the National Center for Missing & Exploited Children. You can stay anonymous.
- If they were 18 or older when it was made, use stopncii.org, run by the Revenge Porn Helpline.
The dividing line is the person’s age when the image was made, not their age today.
- Ask every platform where it appears to take it down — do this now, not after the other steps. Since May 2026, federal law gives covered platforms 48 hours after they receive a valid removal request to take it down and make reasonable efforts to find and remove identical copies. Use the platform’s official reporting form rather than a casual message, and keep a record of what you submitted and when — that record is what starts the clock. Note that not every site or app is covered by that law; small forums, foreign hosts, and private groups may not be. Report to them anyway, and keep going.
- If they miss the 48 hours — or have no removal process — report the platform to the Federal Trade Commission at TakeItDown.ftc.gov. (Note: that FTC address is for complaining about a platform that didn’t act. It is a different service from NCMEC’s Take It Down tool in step 2. The similar names are unfortunate.)
- Report the crime — immediately, not after waiting on any platform. If the image is sexually explicit and involves someone under 18, do this first and right away: report it to the NCMEC CyberTipline at report.cybertip.org or 1-800-843-5678, staffed around the clock. Do not download, forward, or save extra copies — not even to prove what happened. Keep links, usernames, dates and messages instead. For adults, local police and the FBI at tips.fbi.gov or 1-800-CALL-FBI are both options. In California this violates Penal Code 647(j)(4), extended to cover deepfakes in 2024.
One thing to weigh before going to the police. If the person doing this is a partner, ex-partner, family member, or stalker — or if involving police could put your safety, housing, immigration status, or privacy at risk — talk to a victim advocate first and make a plan. Reporting may still be exactly the right call. It just shouldn’t be a reflex before you’ve thought about your own safety. The removal steps above work whether or not you ever involve the police.
If they’re demanding money or more images: don’t pay, don’t send anything, don’t negotiate, don’t keep talking to them. Paying does not make it stop. Block them and tell one person you trust — a parent, a friend, a teacher. This is a crime being committed against you, and adults who deal with it have seen it before.
And if it lands in your feed: don’t view it, don’t share it, don’t forward it “as a joke.” Report it and delete it. Passing it along is part of the harm.
Last reviewed August 2026 · Sources: TAKE IT DOWN Act, Public Law 119-12 · FTC · NCMEC · StopNCII