WhatsApp's Scam Alert checks suspicious messages without sending them to Meta
WhatsApp is testing a private scam-detection layer that runs locally on the phone, warning users about suspicious messages from unknown numbers without uploading those chats for classification.

WhatsApp is testing a new security feature that tries to solve an uncomfortable problem: how do you inspect private messages for scams without turning private messaging into server-side surveillance?
Its answer is Scam Alert, an optional feature that downloads a small machine learning model to the user's device and analyses incoming messages from people who are not saved as contacts.
The classification happens on the phone. Meta says message content does not leave the device for scam classification, and the fact that a message was flagged is not automatically reported to WhatsApp.
That technical choice is more important than the warning banner itself.
Scam detection normally improves when a platform can inspect more data. is designed to prevent the platform from reading private messages. WhatsApp is trying to get some of the security benefit without weakening that privacy boundary.
This is a limited beta, not a switch that has appeared for everyone
Meta published an early technical look at Scam Alert on August 12, 2026.
The company describes the current stage as a limited beta. That means users should not assume the option is already available on every Android phone or iPhone.
When enabled, the model examines incoming messages from non-contacts and looks for patterns associated with scam conversations. Meta says it uses conversational structure and linguistic signals rather than uploading the conversation to a cloud model.
If the system believes a message is likely to be fraudulent, the recipient sees a private warning inside the chat.
The sender does not see that warning.
The recipient can then block the sender, report the chat, continue the conversation, or mark the chat as trusted if the warning appears to be wrong.
That is an important design decision. The software is estimating risk, not proving criminal intent.
How can a phone detect a scam from language?
Scams vary widely, but many share recognisable patterns.
A message may:
- Create artificial urgency
- Impersonate a company or authority
- Promise a reward
- Ask for credentials
- Move toward an unexpected payment request
- Pressure the recipient to act before verifying
- Build trust before introducing a financial demand
Machine learning can classify combinations of these signals.
The important word is probabilistic.
A legitimate delivery driver, new client, school administrator, recruiter, bank representative, or family member using a new number could still resemble a scam pattern.
False positives are therefore inevitable.
A security feature should help a person make a better decision without pretending uncertainty has disappeared.
Why on-device processing matters
End-to-end encryption protects message content while it travels between participants.
A server-side scam scanner would create a new place where message content might need to be decrypted, uploaded or analysed.
On-device inference avoids that for the classification step.
Meta says:
- The model runs locally.
- Message content stays on the device for scam classification.
- The warning itself is not automatically reported.
- Users control whether the feature is enabled.
- Performance telemetry is designed to avoid exposing private message content.
There is one separate feedback path.
If a person marks a flagged conversation as trusted, WhatsApp says the user can optionally share a limited number of recent received messages to help improve the system.
That sharing is optional.
The interface needs to preserve that distinction clearly. "Processed locally" and "voluntarily submitted as feedback" are different privacy states.
Encryption does not protect you from believing the wrong person
Encrypted messaging protects a conversation from interception.
It cannot stop a user from trusting a convincing scammer.
That is why modern fraud increasingly targets the human endpoint instead of the cryptography.
A criminal does not need to break WhatsApp's encryption if they can persuade the victim to send money willingly.
This is particularly relevant in Kenya and other markets where WhatsApp sits beside , online banking, social commerce, informal business and family remittances.
A conversation can move from a greeting to a payment request in minutes.
A warning before the user acts can be more valuable than a fraud investigation after the money has moved.
On-device AI is becoming a product strategy
Scam Alert reflects a broader change in mobile AI.
Smaller models can now run efficiently enough on phones to perform narrow tasks without calling a server every time.
That can provide:
- Lower privacy exposure
- Faster response
- Less dependence on connectivity
- Lower cloud cost
- Better compatibility with encrypted products
The harder challenge is device diversity.
WhatsApp is used on premium flagships and inexpensive Android phones.
A security feature that works only on powerful hardware would leave out many of the users most exposed to mobile fraud.
Meta will need to prove that the model can be efficient across a broad range of supported devices.
What Scam Alert cannot solve
No classifier can stop every fraud attempt.
Attackers can adapt their language or move to:
- Calls
- Voice notes
- Images
- QR codes
- Fake websites
- Other messaging platforms
A sophisticated scammer can also spend days building trust before making a suspicious request.
Users still need basic habits:
- Be cautious with unknown numbers.
- Verify unusual requests through a separate channel.
- Never share PINs, passwords or one-time codes.
- Treat urgency as a reason to verify, not a reason to hurry.
- Check the identity of someone asking for money.
- Report suspicious accounts where appropriate.
The best security feature is one layer in a larger defence.
The tecMAMBO take
Scam Alert is one of the more sensible uses of AI in messaging because it addresses a narrow and measurable problem.
The interesting innovation is not that machine learning can recognise suspicious language.
It is that WhatsApp is trying to do so without quietly redefining what private messaging means.
If the beta proves accurate across languages, cultures and lower-end phones, it could become particularly useful in markets where messaging and money are tightly connected.
The risk is the usual one.
A security system becomes easier to improve if it is allowed to see more.
WhatsApp will need to resist solving every accuracy problem by expanding what leaves the device.
FAQ
Does WhatsApp send my messages to Meta for Scam Alert?
Meta says scam classification runs on the device and message content is not sent to its servers for that classification.
Does a warning automatically report the sender?
No. Meta says a Scam Alert detection is not automatically reported.
Is Scam Alert available to everyone?
No. Meta currently describes it as a limited beta.
Sources
Ask MAMBO
Have a plain-English question about this topic? Send it in and we may answer it in a future guide.
Ask a question

