A reported feature, not a confirmed launch

A report published on August 14, 2026 says WhatsApp is testing a feature called Scam Alert that would identify messages showing signs of fraud and warn the recipient before they engage. The proposed tool would focus on messages from people not saved in a user’s contacts and present options to block and report the sender or treat the conversation as trusted.

The central claim is attractive: machine learning could examine scam indicators locally on the phone, rather than transmit the contents of private chats to Meta for assessment. That approach would aim to preserve WhatsApp’s end-to-end encryption while adding an early warning layer against social-engineering attacks.

However, the status of the feature needs careful qualification. The information originates with coverage of an Android beta build and has been repeated by technology publications. As of August 14, Meta has not published a product announcement describing Scam Alert, its technical design, the countries involved, compatible devices or a timetable for availability. It should therefore be treated as a reported feature in development, rather than a broadly released WhatsApp protection.

Why on-device analysis matters

End-to-end encryption means that the service provider is not supposed to be able to read the content of a standard private chat in transit. A server-side system that routinely inspected all messages for fraud would create obvious tension with that promise.

An on-device model is a potential compromise. The phone could assess message text and other locally available signals against patterns associated with fraudulent approaches, then display a warning without uploading the conversation for automated review. In principle, this lets the recipient benefit from predictive detection without making the platform a routine reader of personal messages.

That principle does not answer every privacy question. Public reports have not established exactly what signals the proposed model would use, how it would be trained, how frequently it would receive updates, whether diagnostics could leave the device, or how users could audit its behaviour. A privacy-preserving architecture also does not eliminate the normal risks of machine-learning classification: a legitimate new contact might be flagged, while a carefully written fraud attempt could be missed.

The proposed design appears to put the final decision with the user. That is sensible for a messaging service, where an unfamiliar number can be either a malicious sender or a real delivery driver, customer, colleague or family contact. Warnings should create a moment of scrutiny, not automatically decide whom people may speak to.

WhatsApp’s existing anti-scam measures

Meta has already introduced other protections that are distinct from the reported message-scanning feature. In March 2026, it said WhatsApp would show alerts when behavioural signals indicate that an attempt to link a new device to an account may be suspicious. Device-linking fraud can involve convincing a victim to enter a linking code or scan a QR code, enabling a criminal’s device to access the account.

That measure is not the same as an AI assessment of ordinary incoming WhatsApp messages. Meta has also expanded an AI-assisted scam-review option in Messenger, where a person can choose to share recent messages from a suspicious chat for review. The company has not publicly said that this Messenger workflow is being applied automatically to WhatsApp’s encrypted private chats.

This distinction is important because descriptions of “AI scam warnings” can easily blur several technologies together: account-protection prompts, automated enforcement against criminal accounts, user-submitted reports, and a prospective local model that assesses message content. They have different privacy implications and offer protection at different points in an attack.

A useful extra layer, not a solution

The case for additional safeguards is strong. The US Federal Trade Commission says consumers reported $2.1 billion in losses from scams that began on social media in 2025. WhatsApp was among the platforms identified in those reports, alongside much larger social networks. Common pathways include impersonation, investment groups, fake employment offers and messages intended to move a conversation to another service.

Fraudsters benefit from speed and psychological pressure. A message that claims an account has been compromised, offers a time-limited job, or appears to come from a friend can prompt action before a recipient verifies the claim. A well-designed warning could interrupt that impulse and make blocking or reporting a suspicious contact easier.

Yet no detection model can reliably determine truth from language alone. Criminals can change wording, use compromised accounts, cultivate a relationship over time or mix genuine information with false claims. Conversely, an unknown sender may have a valid reason to initiate contact. The value of a potential Scam Alert feature would therefore lie in risk signalling, not in certifying chats as safe or dangerous.

What users should do now

Until Meta documents the feature and begins a public rollout, users should not expect it to protect their chats. They should also be wary of messages claiming that a new WhatsApp setting must be enabled through a link or a downloaded app; such instructions can themselves be a route to account theft.

Practical safeguards remain straightforward:

  • Do not share WhatsApp verification or device-linking codes with anyone.
  • Treat unexpected requests for money, investment deposits, credentials or QR-code scans as suspicious.
  • Verify urgent requests through an independently known phone number or another trusted channel.
  • Block and report suspicious accounts in the app.
  • Enable two-step verification and review linked devices regularly.

An on-device scam warning could make these habits easier to apply at the moment they matter. But its eventual effectiveness will depend on transparent privacy controls, credible testing against false alerts, and clear communication about what the tool can and cannot detect.

Sources