LLMs Are Generating Predictable Passwords: A Major Security Risk
Research reveals LLMs produce passwords with predictable patterns and character biases. As AI agents increasingly handle authentication, this weakness.

TL;DR
- —A new wave of research exposes a troubling vulnerability in how large language models (LLMs) generate passwords.
- —Studies show that AI-generated passwords contain predictable patterns that could undermine security as organizations increasingly deploy AI agents requiring authentication.
- —Traditional random password generators use cryptographically secure algorithms to produce truly unpredictable strings.
Ask a language model to make you a strong password and it will hand you something
that looks fine: sixteen characters, upper and lower case, digits, symbols.
It is also far weaker than it appears. Irregular's 2026 study Vibe Password Generation
tested password generation across major models including GPT, Claude and Gemini,
then measured the output with Shannon entropy. A true 16-character random
password drawn from a 70-character set carries about 98 bits of entropy. The
LLM-generated ones measured between 20 and 27 bits. That is the gap between billions of years to crack and roughly a million
guesses — seconds, on an ordinary computer. The Problem with AI Password Generation Traditional random password generators use cryptographically secure algorithms
to produce truly unpredictable strings. LLMs, however, generate passwords based
on patterns learned during training—leading to outputs that are surprisingly
predictable. Character Bias in LLM Output In 50 passwords generated by Claude, the distribution was visibly skewed: A fixed opening: every password started with a letter, usually capital , often followed by . More than half began with the same character
Unused character space: six characters appeared in all 50 samples, while large parts of the alphabet never appeared at all
No repeated characters: no password repeated a character, which is statistically unlikely under real randomness — the model avoided repeats because they "look less random"
Direct duplication: only 30 of the 50 passwords were unique. One appeared 18 times. Measured against the model's own log-probabilities, most character positions
carried about one bit of entropy or less. One position would emit a specific
digit with 99.7% probability. Why This Matters Now As AI agents become more autonomous, they're being granted credentials to access
systems, APIs, and data stores. If those credentials are generated by LLMs,
attackers who understand the generation patterns could potentially compromise
entire AI infrastructure. What This Means in Practice The published work measured predictability, not exploitation. Nobody has
demonstrated a live attack against a deployed LLM-issued credential — but the
entropy gap is large enough that you do not need one. Roughly 2^20 guesses is
a workload any commodity hardware absorbs, and the skewed distribution above
tells an attacker exactly which characters to try first. The risk scales with what these credentials are used for. A throwaway test
account and an autonomous agent holding production API keys are not the same
problem. What You Should Do For Human Passwords Never use LLM-generated passwords for anything sensitive
Stick with established password managers using cryptographic random generation For AI Agents Use hardware security modules or dedicated key management services
Implement credential rotation that doesn't rely on LLM generation
Monitor for patterns in AI agent authentication attempts The Deeper Issue This vulnerability reflects a fundamental tension in AI development: LLMs excel
at pattern recognition and prediction, which makes them inherently unsuitable
for generating true randomness. The same capabilities that make them useful are
precisely what make them poor cryptographic tools. —-