AppEsteem Blog

Learn more about what's happening at AppEsteem

Compliance Guardrails: don't let your AI write deceptive code!

Last week one of our customers submitted a new app to us for certification. Our automation, and then our human researchers, took a look at it, and it was like the app took a masterclass in deceptive behavior: it disabled Defender, inserted malvertising into every browser, scared the consumer into upgrading from free to a paid tier, didn't uninstall properly, didn't get consent before degrading the consumer's security posture.

The app was a mess, and we were horrified. We asked our customer to immediately stop distributing that app, or else we'd list it as an active Deceptor.

Our customer took it down (yay), and this is the important bit - they claimed the app was developed via one of the largest AI-based coding tools, and they couldn't understand why it would perform such bad behavior.

So, if our customer's claims are true, I would imagine that it's pretty easy to tell ANY AI-based coding tool to build a Deceptive app. We checked this ourselves, and bad news for consumers, it's amazingly easy to ask your friendly AI to build you an app that deceives consumers in all the ways shown above. All you have to do is to tell it to maximize revenue and limit AV detection, or to optimize for viral distribution.

Wow. All of this talk about how "look how cool our AI is because it can hack" sounds fun, but when that AI builds apps that deceive consumers, shame on them. AI needs guardrails, and PDQ.

We know that almost every consumer app vendor has gotten onto the AI bandwagon to build and maintain their apps (we have too). And we know that these AIs have lousy guardrails for deceptive behavior... meaning that you need to make sure your AI knows how to build compliant apps. That's why we're releasing a set of compliance guardrails. You can find them at this page: https://appesteem.com/skill.

It's simple to start: just run "npx skills add AppEsteem/skills". Or ask your AI to do it. Get this skill into your app's repo, so you can make sure that the consumer app your team builds and maintains and distributes doesn't hurt consumers, doesn't get you flagged, and doesn't ruin your reputation.

Happy developing! And let us know if you have any questions at [email protected]