Home · Business · IT, Data & Security · Cybersecurity
As of 13 August 2026, AI cannot decide whether to pay a ransomware ransom.
This still needs a person who signs their name to it.
Can you do it?
5 minutesto a draft.
n/ait cannot be self-verified.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita professional
What the alternative costsNo price for a specialist incident-response service is supplied in the available tool data.
If this goes wrong, you may breach a legal restriction, fund further criminal activity, lose time on a false promise of recovery or make the incident more damaging.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface gets you a draft, but you cannot verify it yourself. That is the catch.
How to actually do it
- Open the NCSC ransomware guidance and your organisation's incident-response plan, then start an incident log with the time discovered, affected systems, suspected entry point and actions already taken.
- Contact your insurer, managed security provider or incident-response specialist through the agreed emergency route, and preserve the ransom note, wallet details, logs, images and other evidence without contacting the attacker yourself.
- Gather the facts the decision depends on: verified backup and rebuild options, systems and data affected, operational and safety impact, restoration time estimates, contractual duties, notification requirements and any insurer conditions.
- Paste the incident log, verified technical findings and relevant insurer or contract extracts into the prompt, removing unnecessary personal data and secrets.
- Ask the chatbot to produce the decision brief and mark every statement that needs confirmation from the NCSC, law enforcement, a solicitor, your insurer or the incident-response specialist.
- Send the brief and its unanswered questions to the incident-response specialist, solicitor and insurer, then ask the accountable decision-maker or board to record the decision, alternatives considered and approval.
- Compare the final decision record against the specialist's written advice and your insurer's instructions before authorising any payment, negotiation or recovery action.
Prompt
I am dealing with a possible ransomware incident affecting [organisation and sector] in the UK. Help me prepare an accountable decision brief, not a final decision. Use only the facts I provide and clearly label unknowns. Do not invent technical, legal or financial facts, and do not tell me that payment is safe or guaranteed to restore access. Structure the brief under: immediate containment and reporting actions; systems and data affected; backup and recovery position; business and public impact; evidence about the attacker and claimed decryptor; insurance and contractual constraints; UK legal, sanctions and regulatory questions that require confirmation; alternatives to payment; questions for an incident-response specialist, solicitor and insurer; and a decision log showing who must approve each step. Identify which claims need checking with the NCSC, law enforcement, our insurer, a qualified incident-response specialist or a solicitor. Separate facts, assumptions and recommendations. If the information is insufficient, say exactly what is missing. Here are the facts and documents: [paste incident timeline, technical findings, backup status, ransom message, insurer instructions and relevant contracts].
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot establish whether the ransom demand is linked to a sanctioned person or entity, or whether payment creates a legal problem for your organisation.
- AI cannot verify that the attacker has your data, can decrypt it or will delete stolen copies after payment.
- AI cannot investigate compromised systems, validate backups or estimate recovery safely from a short description.
- AI cannot carry the decision's legal, regulatory, financial or operational consequences.
- AI cannot replace coordinated work with your insurer, incident-response specialist, solicitor, law enforcement and accountable leadership.
What makes this a NO: legal accountability, verification cost and stakes of error.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 1 |
| Inputs | 1 |
| Verification | 0 |
| Liability | 0 |
| Effort delta | 1 |
| Total | 3 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Should I pay a ransomware ransom?
- Do not use an AI response as the decision. Involve your insurer, a qualified incident-response specialist and a solicitor, check legal and sanctions issues, and compare payment with verified recovery and containment options.
- Can AI tell me if a ransomware gang will decrypt my files?
- No. AI can organise evidence about the ransom note and the claimed decryptor, but it cannot verify the attacker's identity, capability or promise to restore access. Ask an incident-response specialist to assess the evidence.
- Is it illegal to pay a ransomware ransom in the UK?
- The answer depends on the circumstances, the recipient and the current legal and sanctions position, so a chatbot cannot clear the payment. This is not professional advice: ask a UK solicitor and your insurer to assess the proposed payment before anyone authorises it.
- What should I do before deciding whether to pay ransomware?
- Contain the incident through your incident-response plan, preserve evidence, contact your insurer and obtain an independent recovery assessment. Ask a qualified incident-response specialist and a solicitor to check backups, operational impact, reporting duties and sanctions exposure.
Nearby answers
- Can AI generate strong passwords for my business?PARTLY
- Can AI scan my business website for vulnerabilities?PARTLY
- Can AI help me secure Microsoft 365 for my business?PARTLY
- Can AI check my business firewall rules?PARTLY
- Can AI check my Microsoft 365 security settings?PARTLY
- Can AI choose offsite backup software for my business?YES
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.