Webroot & OpenText · 2021–2025 · UX Lead

Designing AI to protect people from fraudulent AI-generated content

Led product design and UX strategy for AI Scam Protection in the Webroot app: integrating a third-party AI scam-intelligence API into a high-stakes, high-trust consumer interface, built on responsible-AI principles that put clear verdicts ahead of fear.

Scam Protection verdict screen: a red-bordered result card reading 'Probably a scam' with plain-language guidance — do not respond or click links, don't share personal or financial information, delete and block the sender — plus options to view details or start a new scan.Screenshot of a user checking a scam, URL and video with Webroot AI scam protection
Role UX Lead & AI Product Design
Scope Research · Conversation design · Responsible AI · API integration UX
Team UX, Engineering, Product, Markting, Sales

"Is this real?" — a verdict in one paste

Online content now looks realistic enough that even careful people can't confirm it on sight. The design had to serve the moment of doubt itself: something in the feed looks plausible, a relative has already shared it, and the user wants an answer before they pass it along.

"As a user, I don't want to feel like I've been fooled and share something that's fake — but it's increasingly hard to tell these days." The user story that framed the interaction design

The walkthrough below follows that story end to end in a staged demo environment, fictional social and video platforms seeded with an AI-generated "breaking news" broadcast, so the scenario could be shown safely. The user copies the link, pastes it into Scam Check, and gets a verdict in plain language.

Interaction design demo

A motion prototype of the proposed interaction, from paste to verdict.

AI Scam Protection · Interaction Design Animated prototype · Figma Site →

AI Scam Protection: scan anything, get a verdict

The shipped realization of the Scam Detection Assistant is AI Scam Protection: a dedicated module inside the Webroot app that lets people check whether something is legitimate before they act on it. The interface wraps a specialist third-party AI scam-intelligence API; the design work owned the trust layer around it — what the product asks users for, how verdicts read, and how the wait and the answer feel.

It accepts the content users are actually unsure about — email and direct-message text, files and documents, images, video, and links — through a single input. A user can drag a file in, paste a suspicious link, or paste the body of a message, and the assistant classifies it. Nothing in the experience uses countdowns or fear copy — the same calm, factual tone the persona research demanded.


A trusted brand facing a fast-moving threat

Webroot, a flagship OpenText cybersecurity product, served millions of consumers across Windows, macOS, iOS, and Android. As scam calls, phishing attempts, and AI-generated fraud began outpacing consumer awareness, leadership saw an opening to lead the market with a contextual, AI-powered scam detection feature.

The opportunity was real, and so was the risk: a security assistant that overclaimed, alarmed users, or eroded trust would set the product back. Research surfaced that elderly relatives and lower-tech users were primary scam targets, but even tech-savvy users admitted to false confidence. Generative AI could power a contextual assistant, but rushing to market risked false positives, fear-based UX, and eroded trust. A principled design strategy was needed before any production code began.

Working as UX Lead across product, engineering, and business stakeholders, the charge was to take scam detection from concept to a shippable, trustworthy AI product — owning the strategy and the hands-on delivery, including the UX integration of the partner scam-intelligence API.

User research across three distinct audiences

Grounding the assistant in real user behavior meant studying the people most exposed to scams — and those who only thought they were safe. The team ran generative research across three core personas representing the product's real customer base, with a bias/risk review baked in to ensure the design would not exploit user anxiety.

"I think we all have this false sense of security until something actually happens to us." Quote from a research participant informing our personas

A recurring theme across all three personas was the gap between perceived and actual risk — users felt protected without understanding what protection meant in practice. This shaped a core design principle: verdicts, not lectures. The product needed to deliver immediate clarity without requiring users to learn cybersecurity concepts first.

Research also surfaced strong resistance to fear-based interfaces. Participants across cohorts described abandoning tools that felt alarmist or that used technical jargon to upsell. This directly informed the emotional tone of the assistant's conversational design — calm, factual, and action-oriented — and the notification system's threshold logic.

Responsible design for the Scam Detection Assistant

The scam detection assistant was Webroot's biggest product bet in years, and its highest-risk UX surface. Unlike passive protection (antivirus, VPN), this feature required active user participation: choosing what to submit, interpreting AI verdicts, and deciding whether to act on recommendations.

Leading the product design strategy meant resolving a fundamental tension: the assistant needed to be helpful enough to feel like a trusted expert, but restrained enough to avoid false confidence, fear exploitation, or over-dependence. The design strategy document, developed collaboratively across UX, engineering, privacy, and sales stakeholders, defined four non-negotiable principles before wireframes began.

01
Principle

SmartScan-first: no decision burden on users

Research consistently showed that asking users to decide whether something needed checking was itself a barrier. The assistant defaulted to a SmartScan approach — users should not need to know whether something was suspicious before submitting it. A URL, screenshot, or message could be pasted or uploaded, and the assistant handled classification.

02
Principle

Verdict-first conversation design

Conversation flows led with the verdict, followed by the reasoning, followed by the recommended action. This inverted the typical AI assistant pattern of building to a conclusion — security decisions require immediate clarity, not narrative arc.

03
Principle

No fear-based copy or dark patterns

Every alert, warning, and verdict went through a bias/risk review before production. Language that implied catastrophe, exaggerated risk, or pushed toward upsell was flagged and revised. The assistant's voice was designed to read like a knowledgeable friend, not a threat dashboard — codified in a responsible-AI copy guide distributed to the content and engineering teams.

04
Principle

Privacy-respecting by design

The assistant design worked through privacy review before any technical architecture was finalized, ensuring that submitted content — URLs, screenshots, messages — was handled with appropriate data minimization, clear consent flows, and transparent retention policies. Privacy was treated as a design constraint from the start.


A responsible-AI foundation adopted company-wide