Led product design and UX strategy for AI Scam Protection in the Webroot app: integrating a third-party AI scam-intelligence API into a high-stakes, high-trust consumer interface, built on responsible-AI principles that put clear verdicts ahead of fear.
Screenshot of a user checking a scam, URL and video with Webroot AI scam protection
Online content now looks realistic enough that even careful people can't confirm it on sight. The design had to serve the moment of doubt itself: something in the feed looks plausible, a relative has already shared it, and the user wants an answer before they pass it along.
The walkthrough below follows that story end to end in a staged demo environment, fictional social and video platforms seeded with an AI-generated "breaking news" broadcast, so the scenario could be shown safely. The user copies the link, pastes it into Scam Check, and gets a verdict in plain language.
Swipe or use the arrows to walk the full journey →
A motion prototype of the proposed interaction, from paste to verdict.
The shipped realization of the Scam Detection Assistant is AI Scam Protection: a dedicated module inside the Webroot app that lets people check whether something is legitimate before they act on it. The interface wraps a specialist third-party AI scam-intelligence API; the design work owned the trust layer around it — what the product asks users for, how verdicts read, and how the wait and the answer feel.
It accepts the content users are actually unsure about — email and direct-message text, files and documents, images, video, and links — through a single input. A user can drag a file in, paste a suspicious link, or paste the body of a message, and the assistant classifies it. Nothing in the experience uses countdowns or fear copy — the same calm, factual tone the persona research demanded.
Webroot, a flagship OpenText cybersecurity product, served millions of consumers across Windows, macOS, iOS, and Android. As scam calls, phishing attempts, and AI-generated fraud began outpacing consumer awareness, leadership saw an opening to lead the market with a contextual, AI-powered scam detection feature.
The opportunity was real, and so was the risk: a security assistant that overclaimed, alarmed users, or eroded trust would set the product back. Research surfaced that elderly relatives and lower-tech users were primary scam targets, but even tech-savvy users admitted to false confidence. Generative AI could power a contextual assistant, but rushing to market risked false positives, fear-based UX, and eroded trust. A principled design strategy was needed before any production code began.
Working as UX Lead across product, engineering, and business stakeholders, the charge was to take scam detection from concept to a shippable, trustworthy AI product — owning the strategy and the hands-on delivery, including the UX integration of the partner scam-intelligence API.
Grounding the assistant in real user behavior meant studying the people most exposed to scams — and those who only thought they were safe. The team ran generative research across three core personas representing the product's real customer base, with a bias/risk review baked in to ensure the design would not exploit user anxiety.
A recurring theme across all three personas was the gap between perceived and actual risk — users felt protected without understanding what protection meant in practice. This shaped a core design principle: verdicts, not lectures. The product needed to deliver immediate clarity without requiring users to learn cybersecurity concepts first.
Research also surfaced strong resistance to fear-based interfaces. Participants across cohorts described abandoning tools that felt alarmist or that used technical jargon to upsell. This directly informed the emotional tone of the assistant's conversational design — calm, factual, and action-oriented — and the notification system's threshold logic.
The scam detection assistant was Webroot's biggest product bet in years, and its highest-risk UX surface. Unlike passive protection (antivirus, VPN), this feature required active user participation: choosing what to submit, interpreting AI verdicts, and deciding whether to act on recommendations.
Leading the product design strategy meant resolving a fundamental tension: the assistant needed to be helpful enough to feel like a trusted expert, but restrained enough to avoid false confidence, fear exploitation, or over-dependence. The design strategy document, developed collaboratively across UX, engineering, privacy, and sales stakeholders, defined four non-negotiable principles before wireframes began.
Research consistently showed that asking users to decide whether something needed checking was itself a barrier. The assistant defaulted to a SmartScan approach — users should not need to know whether something was suspicious before submitting it. A URL, screenshot, or message could be pasted or uploaded, and the assistant handled classification.
Conversation flows led with the verdict, followed by the reasoning, followed by the recommended action. This inverted the typical AI assistant pattern of building to a conclusion — security decisions require immediate clarity, not narrative arc.
Every alert, warning, and verdict went through a bias/risk review before production. Language that implied catastrophe, exaggerated risk, or pushed toward upsell was flagged and revised. The assistant's voice was designed to read like a knowledgeable friend, not a threat dashboard — codified in a responsible-AI copy guide distributed to the content and engineering teams.
The assistant design worked through privacy review before any technical architecture was finalized, ensuring that submitted content — URLs, screenshots, messages — was handled with appropriate data minimization, clear consent flows, and transparent retention policies. Privacy was treated as a design constraint from the start.
Responsible AI framework established as a template for all future AI-powered features, including formal bias/risk review, ethical copywriting standards, and a privacy-first design protocol that predated legal requirements and positioned the product for regulatory compliance.
AI Scam Protection shipped inside the Webroot app — a SmartScan-first experience wrapping a third-party AI scam-intelligence API, letting users check email, messages, files, images, and links and returning a plain-language verdict, with privacy stated at the point of use.
A verdict-first conversation model that inverted the typical AI assistant pattern — leading with the answer, not narrative — and a calm, non-alarmist voice codified in a responsible-AI copy guide distributed to content and engineering teams.