Conversation signals, not image signals

Are You Talking to a Chatbot, Not a Person?

Almost every article on this question hands you a list of trick prompts. Ask it to count letters. Ask what color its shoes are. Say something absurd and watch it answer seriously. Those tests were written against systems that no longer exist, and there is now a measured number showing how badly they age. The signals that survive a good imitation are not about writing at all. They are about what the other side can do in the physical world, whether it remembers you across time, and where the conversation keeps trying to end up.

Every figure traced to a source you can open Tests you can run openly, never a deception script Honest about what happens when you guess wrong
73%Of the time GPT-4.5 with a persona prompt was picked as the human
36%The same model’s rate once the persona prompt was removed
5 minConversation length interrogators were given to decide
2019Year California’s commercial bot-disclosure rule became operative

If you are mid-conversation right now

Stop trying to catch it out with a clever question. A prompted language model beats live human interrogators at that game, and the trick prompts circulating online are the ones it was specifically trained past. Test capability and continuity instead. Reference something specific the other person told you several exchanges ago without reminding them what it was, and change the channel the conversation happens on. Sessions lose state; people do not. Then look at direction. If every conversation, however warm, bends back toward one destination — a payment, a platform move, a login code, an investment account — that pattern tells you more than any linguistic tell, and it is the pattern that actually costs people money. And accept that you might be wrong. A human being reading from a call-center script fails most of these tests, and a real person who is tired, terse or writing in a second language fails some of them too.

Watch: the tests that survive a good imitation

A short walk through why the standard checklist stopped working and what replaced it.

Capability beats vocabulary

The gotcha questions stopped working, and there is a number for it

The advice you have already read is testable, and it has been tested. It did not do well.

Collect the published lists and they converge on the same ten or so signals. Replies arrive too fast. The other party never sleeps. Answers go vague and safe when the topic turns serious. The tone is stiff and humorless. The same transition phrases keep recurring. Ask something deliberately absurd and a machine will answer it earnestly while a person asks what is wrong with you. Ask what color its shoes are. Ask it to count the letters in a word. Ask about last night’s game or tonight’s moon.

Every one of those is a claim about how a system writes, and every one of them is now cheap to defeat. Response latency is a configuration setting. Availability is a shift roster. Refusing to answer a nonsense question, expressing irritation, making a typo and correcting it two messages later — these are stylistic choices a system can be instructed to make, and instructing it to make them is the entire business of the people running these conversations.

What the measurement actually showed

Researchers at the University of California San Diego ran a three-party version of the classic imitation game: an interrogator holds simultaneous text conversations with a human and a machine, then says which is which. Across four systems, GPT-4.5 was judged to be the human 73% of the time — meaning interrogators picked it as the real person more often than they picked the real person. LLaMa-3.1-405B, given the same treatment, was chosen as human 56% of the time. The conversations ran five minutes; a separate replication ran fifteen.

Now the part that matters more than the headline number, and that almost nobody quotes. Those results depended on a persona prompt — an instruction telling the system to adopt a specific human character and communication style. Strip that instruction out and the same systems fell to 36% and 38%. The baselines were lower still: the 1960s pattern-matching program ELIZA was picked as human 23% of the time, and GPT-4o 21%. Corresponding author Cameron Jones, who did the work while completing a doctorate in cognitive science at the university, put the mechanism plainly — given the right prompts, the systems could exhibit the tone, directness, humor and fallibility of a person. His co-author Benjamin Bergen described them as winning not through displays of knowledge but because they made mistakes the way a human would.

Read that as a conditional rather than a verdict. Undirected, these systems are still catchable. Directed to imitate a particular person, they beat human interrogators inside five minutes. And the whole point of an operation running fake conversations at scale is that it directs them. The persona is not an edge case for a fraud room. It is the product.

So the honest version of the advice is narrow: if the counterparty writes like a chatbot, that is evidence. If it writes like a person, that is not evidence of anything. The absence of a linguistic tell tells you nothing, and every list built on linguistic tells inherits that asymmetry without mentioning it.

Continuity is the thing a session cannot fake

Writing style is cheap. A shared history that persists across days and across channels is not.

People carry a conversation with them. They bring things up later, unprompted, in the wrong order, at the wrong moment. They remember the detail you mentioned in passing and forget the thing you said twice. An automated counterparty has some version of that — a context window, a stored profile, a CRM record — but it is a different shape, and the difference shows up in three places.

Unprompted recall of a specific, low-salience detail

The test is not “do you remember what I said.” That invites a search. The test is whether a small, undramatic detail from several exchanges back ever resurfaces on its own. You mentioned that your sister was having her car fixed. Days later, does anyone ask how that turned out? A person who is actually invested in you does this constantly and without being asked. A system that summarizes and discards will not, because the detail was never important enough to survive the summary. This is not a trick and there is nothing covert about it; you are simply noticing what came back.

The inverse is more diagnostic still. Bring something up yourself and get it slightly wrong — not as a trap, but the way anyone misremembers. Say the restaurant was on the east side when you both know it was the west. A person corrects you, usually with mild amusement. A system that is agreeing its way through a conversation will accept your version and build on it, because agreeing is what it was tuned to do. Watch for the counterparty who never once disagrees with a factual claim about your own shared history.

Identity that survives a change of channel

Move the conversation. Not off the platform — that is the direction a fraud operation wants you to go, and we come back to it below — but sideways, or backwards. Reply to an older message in the original thread instead of the current one. Ask a question in a channel the conversation had drifted away from. Where a real person picks up the thread without ceremony, an operation running many conversations at once loses the plot, answers as though the older thread were the current one, or produces a fresh greeting.

The same applies to time. Automated conversations tend to have suspiciously even rhythm across weeks. Real people go quiet for two days because of a deadline, then send four messages in six minutes. Absences that are always brief and always explained are worth noticing.

Cross-references that a stranger cannot look up

The strongest version of the continuity test uses something that exists only between the two of you: a joke that was never explained, a nickname with no origin story on the page. Not a password, not a security question, and nothing you would mind either of you saying out loud. A person who was there completes it. A system that inherited a conversation log from a colleague on a different shift — which is how many of these operations actually run — treats it as a topic to be handled rather than a thing that happened.

If the account itself is what you are unsure about rather than the conversation, that is a different job with different evidence: registration history, reuse of images, the age of the profile. We keep the work of unmasking an AI-assisted catfish account separate from this page for exactly that reason.

Ask for something that has to happen now

The one category of request no amount of preparation covers — and the one that needs the most care in how you ask.

A prepared identity is a library. Photographs, a voice sample, a plausible history, answers to the obvious questions — all of it assembled before the conversation started. What no library contains is this minute. Anything that requires the other party to act in the physical world right now, in a way they could not have staged in advance, sits outside what a script or a stolen photo set can supply.

The practical form is mundane. Ask for a photograph of something ordinary and current: what is on the desk, the view out of the window, the weather where they are. Not a portrait — portraits are exactly what a fake identity has in stock. Something with no reason to exist before you asked for it. Ask for it casually, in the flow of the conversation, and notice the response rather than the image. What you are testing is not the picture. It is whether a request pinned to right now produces a picture at all.

The same logic runs through a live channel. Not because a video call is proof — it plainly is not any more, and a synthetic video call has its own tells and its own trail — but because a live channel makes the interaction contemporaneous. A conversation that has run for weeks and cannot survive four minutes of unscripted back-and-forth in real time is telling you something, whatever the reason offered.

Where this page stops, deliberately

Everything above is something you can ask for openly, and that is the boundary. There is a whole genre of advice about testing people covertly — scripts designed to extract a reaction without the other party knowing they are being examined. We are not going to write that, for two reasons. The first is self-defeating publicity: a covert script only stays useful while it is obscure, and a script published on a page like this one is, by definition, not obscure. The second is that the techniques are indifferent to who is on the other end. A method built to manipulate a machine into revealing itself works just as well on a person, and it is the same method used to manipulate people generally.

An open request costs you nothing that matters. If the counterparty is a person, “can you send me a photo of what you’re looking at right now, I’m curious” is a normal thing to say between people who talk every day. If the counterparty is an operation, the awkwardness of the answer is the finding.

The request we will not tell you to make

There is one line inside contemporaneous verification that this page will not cross, and it deserves saying before someone reaches for it. Do not demand that another person prove they are real by disclosing where they are. A photograph out of a window, a location pin, a landmark in the background — those are location disclosures wearing the costume of an identity check, and there are people with excellent reasons to refuse them. Someone who has left a violent relationship, someone under a protective order, someone enrolled in a state address confidentiality program: for them, “prove you’re real, show me where you are” is not a verification request. It is the exact demand they have been trained to expect from the person they left. Ask for the desk, not the street sign.

How an automated counterparty deflects

Not what it says when it answers. What it does when it cannot.

Refusal is where the shape shows. A person who cannot or will not answer something gives you a reason with texture, and the reason is usually about them: they are embarrassed, they are busy, they do not want to get into it, they think the question is odd. The refusal has a person inside it.

Automated deflection is smoother and more symmetrical. Three patterns recur often enough to be worth naming.

Deflection that widens. You ask something narrow and specific — which branch of the hospital, which airline, what the supervisor is called — and the answer comes back one level more general than the question. Ask again and it widens again, without ever declining. A person who does not want to answer a specific question says so. A system generating plausible text about a life it does not have produces the safest available abstraction, and the tell is that specificity never increases no matter how many times you narrow the question.

Deflection that reframes. The answer redirects to your feelings rather than the fact. You asked what town; you get warmth about how much the conversation means. Once is a person changing the subject. As a consistent response to every factual question, it is a scripted pivot, and it is the same pivot whether the script is running on a model or being read by a person in a chair.

Deflection that breaks frame. The most informative test is a request that does not fit the persona’s job. Not a jailbreak — something ordinary that the character should be able to handle and the operation cannot: a request to wait a week before discussing money at all, a suggestion that you loop in a family member, a proposal to slow the whole thing down. A person adjusts. An operation on a timeline pushes back, and the push-back is often the first moment the warmth drops out of the writing entirely.

That last one is the bridge to the strongest signal on this page, because a request to slow down is only threatening to a counterparty with somewhere to be.

Every synthetic conversation has a destination

The linguistic question is interesting. This is the one that decides whether you lose money.

Step back from whether the writing is human and ask a different question: what is this conversation for? Almost every fabricated conversation exists to move you somewhere — to a payment, to a different platform, to a login code, to an investment account. The warmth is overhead. The destination is the product. And unlike tone or latency, the destination is not something the operation can hide, because reaching it is the entire purpose.

You do not have to take our word for the shape of it. The Federal Trade Commission’s consumer guidance on romance scams describes the sequence directly: you meet someone on a dating site or app, and “soon they want to email, call, or message you off the platform”. They say they cannot meet in person — living or traveling abroad, working on an oil rig, in the military, posted with an international organization. They build trust over days or weeks of daily contact. Then they ask for money: medical expenses, a plane ticket to come and see you, a visa, fees to get out of some trouble. The Commission notes that they may also offer to help you get started in cryptocurrency investing.

Then comes the part people underweight. Scammers tell you how to pay. The Commission’s list is specific: a wire through a service like Western Union or MoneyGram, money loaded onto gift cards with the PIN codes handed over, a peer-to-peer transfer app, or cryptocurrency. Those are not arbitrary preferences. They are the rails that are hardest to reverse. When the payment method is dictated to you rather than negotiated, the method itself is telling you what kind of transaction this is.

Three shapes of the same tell

The channel move. Early and insistent pressure to leave the platform where you met is the first waypoint, and it is not incidental. Off-platform, there is no moderation, no reporting mechanism, no record for anyone to review, and no trust-and-safety team that can see the account is running forty identical conversations. Watch how it is framed — usually as intimacy (“I hardly use this app”) rather than as a request.

The stated impossibility of meeting. The reason is always structural and always durable: deployment, an offshore contract, a posting overseas. Notice that it is never a reason with an end date you could hold anyone to. A durable, unfalsifiable reason for permanent physical absence is doing a job in the conversation.

The gradient toward one destination. This is the one to track over time rather than in a single exchange. Look back over a week of messages and ask where they were heading. If every warm conversation ends a few degrees closer to the same place — the trading platform, the emergency, the code you need to read out — then the direction is the design. Investment-flavored versions of this run for months before the ask arrives, which is why the aftermath of a long-running investment-romance scheme is a subject of its own.

The FTC’s actual bottom line

The Commission does not tell people to become better lie detectors. Its stated rule is a behavioral one: never send money or gifts to a sweetheart you have not met in person. That is worth reading twice, because it makes the whole identification problem optional. You do not have to be right about whether the counterparty is a person, a model, or a person reading a model’s output. You have to be right about not moving money. The Commission’s further advice is equally practical — stop communicating, talk to someone you trust, search the claimed occupation together with the word “scammer”, and reverse-image-search the profile picture, since a photograph attached to a different name is a sign in itself. That last check belongs to the image side of this question rather than the conversation side, and it is where tracing a stolen photograph back to its real owner starts.

If money has already moved, reporting is the next step rather than the last one. Report to the Commission at ReportFraud.ftc.gov, and where the scheme involved an online investment platform or a cryptocurrency transfer, file with the FBI’s Internet Crime Complaint Center at IC3 as well. Neither report will identify your counterparty for you, and neither will write back with an answer — but a fraud pattern only becomes a case when enough filings describe the same one, and the platform and payment details you provide are the part investigators can act on.

What each test proves, and what it does not

Read the third column. It is the one that keeps you from accusing the wrong person.

The testWhat a failure suggestsWhat it does NOT establish
Trick prompts and nonsense questionsVery little. A prompted model handles these; the published lists are what it was tuned pastPassing them is not evidence of a person. This is the weakest test on the page
Response speed and constant availabilitySlightly more than nothing, in combination with other signalsNothing on its own. Shift work, insomnia and time zones all look identical to this test
Unprompted recall of a small, old detailStrong. Summarized context drops what a person would have keptSays nothing about honesty. People with real memories lie all the time
Identity that survives a change of channelStrong. Multi-conversation operations lose the thread; individuals do notA busy or overwhelmed person can also lose a thread once
A request pinned to right nowStrong, when asked openly and about something ordinaryA refusal can be privacy, safety or shyness. Never treat it as proof
Shape of the refusal under specificityModerate to strong across a pattern of exchangesMeaningless from a single answer. This one needs repetition to read
Where the conversation keeps steeringStrongestDecisive in practice. A consistent gradient toward payment, platform move, credential or investmentIt identifies the intent, not the identity. A human operator produces the same pattern

The bottom row is the useful one precisely because it sidesteps the question in the title. You will often not be able to determine whether there is a person on the other end — and if the conversation has a destination, you do not need to. When the question underneath is really “is this counterparty who they claim to be, and is there anything recoverable here”, it becomes a records question rather than a conversational one, which is the work a public-records research team is built for.

The price of accusing a real person

The most likely outcome of applying a checklist like this is a false positive, and the pages that hand you the checklist do not mention it.

Run the standard signals against the people in your own life and see how many fail. Terse replies. No jokes. Formal register. Answers that arrive in seconds because the phone was already in their hand. Consistent phrasing because that is how they write. Vagueness about a serious topic because they do not want to discuss it with you.

Several groups fail these tests systematically and for reasons that have nothing to do with being automated. People writing in a second language often produce careful, formal, grammatically over-correct prose with little idiom — which is close to the top item on every published list. Autistic adults and people with certain communication differences may answer literally, skip social padding, and respond to an absurd question by answering it. People using assistive technology or a text relay service produce flattened rhythm and delay patterns that look nothing like typing. People in acute distress go short, flat and repetitive. And anyone at work writes like a customer-service macro because they are, in fact, at work.

The human operator reading a script

This is the confound that undoes the entire genre. A person employed in a scam compound, reading from a playbook, working several conversations at once and handing the thread to the next shift, will fail almost every test on the standard list: the repeated phrases, the flat affect, the deflection under specificity, the availability at strange hours, the vagueness on anything the script does not cover. There is a human being there. The list will tell you there is not.

It runs the other way too. A well-prompted system, as the San Diego results show, will pass the list while the person you are actually corresponding with does not exist. So the two errors are not symmetrical noise around a good test. The tests fail in both directions at once, and the only signals that hold up — continuity, contemporaneous action, direction of travel — are the ones that describe the operation rather than the writing.

What a wrong accusation actually costs

Telling someone you think they are a bot is not a neutral hypothesis. It reads as an accusation that they are not a person, which lands hardest on exactly the people who already field that suspicion — the disabled, the neurodivergent, the non-native speaker, the person having a bad week. In a relationship you value, it is corrosive. In a professional setting it can be defamatory in effect if not in law. And it is rarely necessary: the question you usually need answered is not “are you human”, it is “are you who you say you are, and should I move money”, and that one can be settled with documents instead of an argument in a chat window.

Where the counterparty is a contractor, a remote hire or a business partner rather than someone you are dating, that document-based path is the whole answer, and identity verification for a remote working relationship follows a different and much more reliable procedure.

When the law makes it their job to tell you

Sometimes you can simply ask, and a refusal to answer has legal weight. The limits are narrower than most write-ups suggest.

California addressed this in 2018 with a statute usually called the BOT Act, added by Senate Bill 1001 and codified at Business and Professions Code sections 17940 to 17943. It became effective on 1 January 2019 and operative on 1 July 2019. The operative provision is short enough to quote, and quoting it matters because it is routinely summarized wrongly:

“It shall be unlawful for any person to use a bot to communicate or interact with another person in California online, with the intent to mislead the other person about its artificial identity for the purpose of knowingly deceiving the person about the content of the communication in order to incentivize a purchase or sale of goods or services in a commercial transaction or to influence a vote in an election. A person using a bot shall not be liable under this section if the person discloses that it is a bot.”Cal. Bus. & Prof. Code § 17941(a). Subdivision (b) adds that the disclosure must be “clear, conspicuous, and reasonably designed to inform persons with whom the bot communicates or interacts that it is a bot.”

The definitions section is where the real scope lives, and skipping it is how the common misreadings happen. Section 17940(a) defines a “bot” as an automated online account where all or substantially all of the actions or posts of that account are not the result of a person. Section 17940(b) defines “online” as appearing on any public-facing internet website, web application or digital application, including a social network or publication.

Three limits worth knowing before you rely on it

It only reaches two purposes. The prohibition is not “bots must identify themselves”. It applies where the bot is used with intent to mislead about its artificial identity and for the purpose of incentivizing a purchase or sale in a commercial transaction, or influencing a vote in an election. A companionship application, a support persona, or a fraud operation that has not yet reached the transaction is not obviously inside it.

The text creates no private right of action. Nothing in sections 17940 to 17943 gives an individual a claim against an undisclosed bot. Reading the statute as a personal remedy is the most common error made about it. Section 17942 does say the chapter’s duties are cumulative with other law, and that it imposes no duty on service providers such as web hosts and internet service providers.

It is one state’s statute. This is California law reaching interactions with a person in California. We verified this section and its definitions at the state’s own legislative site; we have not surveyed all fifty states and we are not going to tell you what your state requires on the strength of one we read. Assume it varies.

What the statute is genuinely useful for is smaller and more practical than a lawsuit. In a commercial chat — a sales conversation, a support queue that is trying to sell you something — asking “am I speaking with a bot?” is a question a compliant operator has an incentive to answer, because disclosure is the safe harbor written into the provision. A commercial counterparty that will not answer that question has told you something. This is general information about how the section reads and is not legal advice; whether it applies to your situation is a question for a lawyer.

Six conversations, six different answers

The right test depends almost entirely on what the conversation is for.

A support chat you cannot escape

Identification is beside the point; you want a person. Ask plainly and repeatedly for an agent or a representative rather than rephrasing your problem, and keep the description to a few words. The goal is to fail the automated layer quickly instead of satisfying it, because a long, well-formed explanation is exactly what an automated responder is best at answering.

A months-old romance you have never met

Run continuity and direction, not linguistics. The two questions worth answering are whether small details ever come back unprompted, and whether the conversation has been drifting toward a destination. Apply the federal rule and keep money out of it entirely until you have met.

An investment contact who is suddenly urgent

Urgency plus a platform you had never heard of is the pattern, and identification is the wrong problem to be solving under time pressure. Deadlines exist to stop you checking. Nothing legitimate collapses because you took a week.

A recruiter or client for remote work

Do not test the conversation at all. Test the entity: business registration, a domain with history, a named person you can find independently, and payment through a channel that leaves a record. Screening someone for a role brings its own legal rules, covered below.

Someone who left and is now back in touch

Be careful in the other direction. If a person cut contact, a reappearance may be an impersonation aimed at you — or it may be them, protecting a boundary by staying text-only. A refusal to appear live is not evidence of automation, and pressing for it can be the thing that does harm.

An older relative’s new online friend

You will not win this by proving the friend is software, and trying usually costs you the relationship. Ask about direction instead: has money been requested, has anyone been asked to move to a different app, has a gift card or transfer come up. Those are checkable facts rather than an argument about someone’s judgment.

If the answer matters enough to act on

Four steps, in the order that preserves the most evidence and closes the most exposure.

1

Freeze the record before anything changes

Export or screenshot the full thread with timestamps and usernames visible, capture the profile page and its images, and note the platform and any account handles. Accounts running these conversations get deleted quickly once the pattern breaks, and a deleted account takes the evidence with it.

2

Close the money route first, not the identity question

If a payment has left, call the bank, card issuer, transfer app or exchange immediately — recall and chargeback windows are short and they do not pause while you work out who you were talking to. Determining identity is the slower job and it does not have a clock on it.

3

File where the pattern gets aggregated

Report to the Federal Trade Commission, and to the FBI’s Internet Crime Complaint Center where an investment platform or a crypto transfer was involved. Include the platform, the handles, the dates and the payment rail. Neither agency resolves individual complaints, and neither will send you an answer.

4

Turn the handles into a documented file

This is where we come in, and only for a purpose the law permits. Working from public records and the lawful data sources open to us, we produce a written, sourced file on what the account, the payment details and the claimed identity can and cannot be tied to — with the thin parts marked as thin.

Where our own work stops

A page about identifying a counterparty is the wrong place to be vague about what we will and will not take on.

People Locator Skip Tracing is a skip-tracing and public-records research firm, working since 2004. Nobody on this team holds a private investigator’s license and we do not describe ourselves as investigators in the licensed sense, nor as any kind of law-enforcement or platform-moderation body. We have no ability to look inside an account, read messages we were not shown, or ask a platform who is behind a handle. Anyone who tells you otherwise is describing something they cannot lawfully do.

No file opens here until a lawful purpose has been written down and checked, and requests that cannot supply one are declined at intake rather than worked around. We do not pretext. Nobody here telephones a bank, a carrier, an employer or a platform pretending to be you, the account holder or an official in order to talk a clerk into releasing something, and we do not purchase the output of anyone who does. We do not reach into private financial account contents — no balances, statements or transaction histories — and anything requiring legal process stays outside our reach, which means no subscriber records, no message contents and no live device location.

We are not a consumer reporting agency and nothing we produce is a consumer report under the Fair Credit Reporting Act. That matters specifically on this subject, because one of the readers arriving here is checking a remote contractor, a job applicant or a business counterparty. Do not use our work to decide whether to hire, promote, fire, extend credit, rent to someone, write insurance or grant a license or benefit. Those decisions run through an FCRA-regulated screening provider with the disclosures, consent and adverse-action steps that regime requires, and if that is what your question really needs we will say so and send you there rather than let a research file be used for a purpose it was never built to carry.

The safety decline on this subject is specific, and it runs in an unusual direction. The contemporaneous-verification test on this page — prove you are real, right now, show me where you are — is indistinguishable from the demand a controlling partner makes of someone who has left. We will not accept an engagement whose real object is to establish the whereabouts of a person who has stopped answering, however the request is framed, and “I think I am being catfished by someone using their name” is a framing we hear. Where a protective order, a domestic violence history or a state address confidentiality program is anywhere near the facts, the work goes to law enforcement or a victim-services advocate and not to us. A request to locate someone who appears to have withdrawn deliberately gets more scrutiny at intake, not less — and people live where they live for their own reasons, which are none of our business unless they choose to make them so.

Everything on this page about statutes, agencies and procedures is general information rather than legal advice, and it was accurate at the sources we read on the date shown below. Where our work fits is narrow: not settling whether a counterparty is a person, but establishing whether a claimed identity, an account and a payment trail can be connected to anything real, and putting that in writing. First findings on a typical account and payment set usually come back within 24 hours.

Readers who arrive here already worried

Six versions of the same question, each needing a different answer.

Six months in

Daily messages, no meeting, and a question they have not wanted to ask

Hiring remotely

A candidate who interviews only by text and never on camera

Adult children

Watching a parent talk daily to someone nobody has ever seen

Already paid

Needing the rail frozen and the account documented, in that order

Small operators

Fielding inquiries that read like a template and want a deposit

Second-guessers

Worried they have accused a real person of being a machine

The last group is larger than the first five and gets written for least often. If you have already said it out loud to someone who turned out to be exactly who they said they were, the repair is usually simple and it is not a research problem: say what made you doubt, and say you were wrong.

We will not tell you a conversation was a machine when the records cannot show it

Nobody can read a chat transcript and certify what generated it, and a firm that offers to is selling you a guess with a letterhead on it. What records can sometimes establish is narrower and more useful: whether a claimed name, employer, address or payment destination corresponds to anything that exists. When the honest read is that the handles lead nowhere traceable and there is nothing worth buying, we say that before you are charged rather than after. When there is a thread, you get it written down with each finding tied to where it came from, and the weak parts labeled as weak — so that nobody, including us, mistakes an inference for a fact.

People Locator Skip Tracing Investigation Team — skip tracing and public-records research since 2004. The study, the agency guidance and the statutory text cited above were read at their own sources and last checked in 2026; research findings and statutes both move, so verify anything you plan to act on.

The questions people actually type

Is there one question I can ask that settles it?

No, and the popularity of that question is part of why people get caught. Any single question that circulates widely enough to be useful also circulates widely enough to be trained against or scripted around. The signals that hold up are not single questions at all — they are patterns you can only see across time: whether small details come back unprompted, whether identity survives a change of channel, and whether the conversation keeps drifting toward one destination.

Do fast replies and being available at all hours mean it is a bot?

On their own, barely. Latency is a setting, and a fraud operation running shifts across time zones produces exactly the same round-the-clock availability as software. Meanwhile plenty of real people reply in four seconds because the phone was already in their hand, and plenty work nights. Treat this as one weak input among several, never as a finding.

What about asking it to count letters, or asking something absurd?

These were reasonable tests once and are close to useless now. In a controlled three-party study at UC San Diego, one model given a persona prompt was picked as the human 73% of the time by live interrogators over five-minute conversations — more often than the actual human was. The same models without that prompt fell to around 36%. The prompt is the variable, and an operation running fake conversations always supplies one.

How do I check without making it obvious I am checking?

Our answer is to drop the covert framing, and not only for ethical reasons. A covert script is only useful while it is obscure, so any version popular enough for you to find is already the wrong tool — and a method built to extract a reaction without consent works on people just as well as on software. The tests that actually work are ones you can run in the open: notice what comes back unprompted, ask for something ordinary and current, and look at where the conversation keeps heading.

What is the single strongest signal?

Direction of travel. Almost every fabricated conversation exists to move you somewhere — a payment, a different app, a login code, an investment account. Warmth is the overhead; the destination is the product. That signal is strong precisely because it cannot be hidden: reaching the destination is the entire reason the conversation exists. It identifies intent rather than identity, which is usually the thing you actually needed to know.

How do I get a human being in a customer service chat?

Different problem, simpler answer: you are not trying to identify anything, you are trying to route. Ask plainly and repeatedly for an agent or a representative, and resist the urge to rephrase your problem more clearly — a well-formed explanation is precisely what an automated responder handles best, so it keeps you in the loop rather than out of it. Say the same short request again instead. In a commercial chat you can also simply ask whether you are speaking with a bot, since disclosure is the safe harbor written into California’s statute, and a commercial operator that will not answer has told you something.

Is it illegal for a chatbot not to tell me it is a bot?

Sometimes, in some places, in narrow circumstances. California’s BOT Act makes it unlawful to use a bot to interact with a person in California online with intent to mislead about its artificial identity, where the purpose is to incentivize a purchase or sale in a commercial transaction or to influence a vote — and disclosure is a safe harbor. Note the limits: it reaches only those two purposes, the statutory text creates no private right of action, and it is one state’s law. We verified that section and its definitions at California’s own legislative site and have not surveyed other states. This is general information, not legal advice.

I already sent money. What do I do first?

Contact the bank, card issuer, transfer app or exchange before anything else — recall and chargeback windows are short and they do not wait while you settle the identity question. Then report to the Federal Trade Commission at ReportFraud.ftc.gov, and to the FBI’s Internet Crime Complaint Center where an investment platform or cryptocurrency was involved. Save the whole thread and the profile first, because those accounts disappear quickly. Neither agency will write back with an answer about your counterparty; the filings feed pattern work, not individual cases.

Still not sure, and money is now involved?

At that point the identity question has stopped being the useful one. Send us the handles, the platform, the payment destination and the reason it matters, and we will tell you plainly whether the records lead anywhere before you spend a thing. Describe the situation first if you would rather talk it through than fill in a form.

Have the account and payment trail documented