Think First, Verify Always: the three-minute protocol against AI deception.

Published in MIT Sloan Management Review

Two moves. Three minutes. One habit that holds up against a cloned voice, a fake invoice, or a message that looks exactly like your bank. Learn it here, use it today, and teach it to anyone.

What this is, and why it exists.

For most of history, deception had a tell. A stranger’s voice, an odd phrase, a story that did not quite hold. Your instincts had something to catch.

AI took the tells away. It can clone a familiar voice, write in a colleague’s exact cadence, and manufacture urgency at a speed no human could match. The manipulation is now fluent, personal, and instant, and it is aimed at the one thing a password cannot protect: your judgment. The trouble is not that people are careless. It is that the pressure is engineered to make careful people move before they think.

Think First, Verify Always is the answer, and it is built to be learned in the time it takes to make coffee. Two moves. Slow down, then verify. That is the entire protocol, and it works the same whatever the threat wears. Learn it here and you can apply it to the next message, call, or request that reaches you.

The two moves.

Slow down. Urgency is the weapon, so take the pressure off first. Every engineered scam needs you to act right now, before you think, because a pause is where it falls apart. A real request survives that pause. A manufactured one rarely does. The moment a message pushes you to move immediately, treat that push as the signal to stop and think first. You are not being rude and you are not being slow. You are doing the one thing the manipulation is designed to prevent.

Verify always. Confirm who you are actually dealing with through a separate channel you choose and already trust. A number you dial yourself. A person you reach directly. The official site you type in from memory. Never the link in front of you, never the number the caller gave you, never the account in the message. This is the whole trick: never verify a message using the message itself. If the request is real, a two-minute check costs you nothing. If it is not, that check is exactly where the scam ends.

Two moves, in that order. Short enough to teach a family over dinner, simple enough to hold when your heart is pounding, which is the only place it has to work.

How to use it today.

Carry the same two moves into any message, call, or request. The specifics change; the habit does not.

A voice on the phone says a loved one is in trouble and needs money now. Slow down. Then hang up and call that person, or someone who is with them, on the number you already have. Hear their real voice before you do anything. Verify always.

A text says your account is locked, tap here to fix it. Slow down. Then do not tap the link. Open the app or type the address yourself and check from there. Verify always.

An email from your boss asks you to move money or buy gift cards before end of day. Slow down. Then confirm in person or on a number you know is theirs before a dollar or a code leaves your hands. Verify always.

A message tells you to keep it secret, do not tell anyone. Slow down. Real institutions do not work this way. Verify out loud with one person you trust. Verify always.

One rule ties them together: the more a request pushes you to act right now, the more it has earned a pause and a check. That small pause is where the scam falls apart.

Why it works. The proof.

This is not advice you have to take on faith.

Think First, Verify Always was published in MIT Sloan Management Review, in the article “A Three-Minute Protocol to Reduce AI Manipulation Risk” (2026). Their editors chose to run it.

It was tested in a randomized controlled trial. A single session of about three minutes measurably improved how well people resisted AI-driven manipulation, a gain of 7.87 percentage points over a control group (n=151). One short lesson, a real and measurable difference.

Since publication, the protocol has been referenced and recommended by companies and media around the world, from technology press such as DevDiscourse and ZDNet Korea to security and training firms including Global Learning Systems, CybeReady, and Cogent Info.

The full evidence, the trial, and the link to read it in MIT Sloan Management Review live on the evidence page.

Take it, use it, teach it.

Think First, Verify Always is openly licensed under CC-BY 4.0. You are free to use it, teach it, translate it, and adapt it, whether you are protecting your own family, briefing a newsroom, or training ten thousand employees. There is nothing to buy and nothing to sign up for. The strongest protection is the kind that spreads, so we made this one impossible to gatekeep. Learn it in three minutes, then pass it on.

It was created by Yuksel Aydin, an AI-security researcher and the founder of HCSK, a nonprofit.

Cite this: Yuksel Aydin, “A Three-Minute Protocol to Reduce AI Manipulation Risk,” MIT Sloan Management Review (2026). Think First, Verify Always by HCSK, licensed under CC-BY 4.0.