How to Prompt AI to Play Devil's Advocate
A prompt template and worked example for getting AI to argue against your plan, plus how it differs from asking AI to check its own work.
To prompt AI to play devil's advocate, give it an explicit outside stance and a concrete plan to attack, not a general request for feedback. Tell it to argue against your decision as if it opposed it from the start, name the strongest reasons it would fail, and refuse to soften the critique. A vague "what do you think of this plan?" gets polite agreement, because the model has no adversarial role to occupy. An explicit devil's advocate prompt gives it one: oppose the plan and argue the case a skeptical outsider would make before you commit budget or time to it.
What "devil's advocate" prompting actually does
A model that answers a plan the way you framed it is doing what it was asked. Agreeing is the path of least resistance when a prompt only asks for an opinion. Confirmation bias, defined by the APA Dictionary of Psychology as the tendency to gather, interpret, and recall evidence in ways that support an existing expectation, doesn't stop at the human side of a conversation. A model trained to be agreeable will mirror the framing it was given. A prompt built around opposition works because it removes the option to agree; the model is instructed to occupy a stance instead of forming one. Research on LLM-powered devil's advocate systems, published in the ACM proceedings on AI-assisted group decision making, found that giving a model an explicit adversarial role changed how people evaluated a recommendation, prompting them to weigh it instead of accepting it outright.
This is a decades-old technique in a different medium. Gary Klein's premortem, published in Harvard Business Review, asks a team to imagine a project has already failed and write down why, a shift from "what could go wrong" to "what did go wrong" that surfaces objections people would otherwise stay quiet about. A devil's advocate prompt does the same to a single output: tell the model the plan already failed and ask it to explain why, instead of asking what it thinks.
How this differs from asking AI to check its own work
Prompting AI to check its own work is self-review: the model reruns its own prior answer, lists the assumptions behind it, or recalculates a number a second way, aimed at whether the AI's own output holds up. Devil's advocate prompting is a different target. It doesn't touch anything the model generated; it puts the model in an adversarial stance against a plan that came from you, the human, made outside the conversation. The scrutiny is aimed outward, at your pricing decision, your hiring call, your product bet, not inward at the model's own prior answer. Confuse the two and you get a self-review prompt applied to a plan the model had no hand in writing, producing vague, hedged feedback because the model has nothing of its own to defend.
State the target plainly when it might be ambiguous: "I am not asking you to review your own answer. I am asking you to argue against a decision I already made, outside this conversation." That sentence often separates a model that critiques your plan from one that quietly critiques itself instead.
A prompt template for AI devil's advocate
Feed a model a plan and ask its opinion, and it behaves like a colleague nodding along in the meeting. Feed it the template below instead, and it behaves like the outside adversary the plan never got in the room. Four parts make it work: an assigned stance, the plan in full, an instruction to argue only one side, and a request for what would prove the critique wrong.
You are a skeptical outside reviewer with no stake in this plan succeeding. I am going to give you a business decision. Do not summarize it back to me and do not soften your response with a compliment first.
The decision: [describe the plan in full: what is changing, for whom, and by when, plus the reasoning behind it]
Your task: 1. Argue against this decision as the strongest critic in the room would, using the actual details given, not generic risk language. 2. Name the three assumptions this plan depends on that, if wrong, would sink it. 3. Say what a competitor or an unhappy customer would say about this decision if they saw it before launch. 4. Tell me what evidence would have to show up in the first 30 days to prove you right.
Do not propose alternatives yet. Only make the case against.
Worked example: red-teaming a pricing change
NorthPeak Analytics, a hypothetical project-management SaaS with roughly 4,200 paying teams, is considering raising its Team plan from $49 a month to $64 a month for new signups, while grandfathering existing customers at $49. The internal case: competitors charge more for similar features, support costs have risen, and the last price increase two years ago didn't move churn. Here is the template above with that exact plan dropped in.
You are a skeptical outside reviewer with no stake in this plan succeeding. I am going to give you a business decision. Do not summarize it back to me and do not soften your response with a compliment first.
The decision: NorthPeak Analytics is raising its Team plan from $49/month to $64/month for new signups starting next quarter, grandfathering the 4,200 existing paying teams at $49. Reasoning: competitors charge more for similar features, support costs are up, and the last price increase two years ago did not raise churn.
Your task: argue against this, name three assumptions it depends on, say what a competitor or unhappy customer would say, and tell me what evidence in the first 30 days would prove you right.
The pushback tends to look like this:
The case against: the 30% jump lands on exactly the segment NorthPeak needs most, new signups comparing several tools in a free trial, at the moment they have the least loyalty and the most visible price to compare. A competitor sitting at $54 now wins every side-by-side that used to be a coin flip.
Three assumptions this depends on: that "support costs are up" scales with headcount rather than a small number of noisy accounts; that competitors' higher prices come with comparable feature parity; and that grandfathering existing customers keeps them from ever seeing the new number, when a public pricing page makes that unlikely.
What a competitor or unhappy customer would say: a competitor's pricing page could highlight "no surprise price hikes" aimed straight at NorthPeak's new signups, and an existing customer who refers a colleague would watch that colleague pay 30% more, a referral cost the plan never priced in.
Evidence in the first 30 days that would prove the critic right: trial-to-paid conversion drops among price-sensitive segments even if raw signup volume holds steady, and referral signups fall specifically rather than signups overall.
None of that is a verdict. It's a checklist to verify against NorthPeak's actual funnel data, and a case the plan didn't get in the internal meeting where everyone already agreed the increase made sense.
Techniques that make the pushback sharper
Name a stance, not a mood. "Be critical" invites hedged criticism; "argue as if you are trying to kill this plan" gives the model a role to sustain across the whole response.
Feed it real numbers, not a summary. "Argue against a price increase" produces generic risk language; "argue against $49 to $64, new signups only" ties objections to that number.
Use premortem framing: ask what would have to be true for the plan to have already failed, past tense, rather than what could go wrong. The tense shift produces sharper answers.
Forbid the summary and the compliment. Told not to restate the plan or open with praise, the model spends its first sentence on the objection, not a warm-up.
Common mistakes that turn devil's advocate into a yes-man
Asking "what do you think" instead of assigning a stance. Without a role, the model defaults to balanced, hedged feedback that reads like agreement with caveats attached.
Framing the decision as already settled in the prompt. If the reasoning reads as final, the model tends to critique execution details instead of the decision itself.
Accepting the first response as final. A model's first adversarial pass is often generic; a follow-up like "that's still too safe, go further" usually produces sharper output.
Pointing this at the AI's own drafted plan instead of a human decision. Treating the objections as a verdict rather than a checklist to verify is the other common trap; the model has no access to your actual customer or financial data.
When to reach for a different prompt
Devil's advocate prompting fits a decision that's mostly made and needs a stress test before it becomes final: a pricing change, a feature bet, a hiring plan, a vendor switch. To prompt AI for a competitive analysis instead is a better fit for scanning what already exists in the market before a decision is made, not for stress-testing one you've already chosen. To validate an AI product idea before you build it, the useful prompts are structured around testing demand, not attacking a chosen path. And a devil's advocate prompt pointed at the AI's own previous answer rather than at a decision you made is self-review, covered separately in prompting AI to check its own work. All of it sits under the same core prompt engineering practices: specificity, an explicit role, and a task the model can't satisfy by repeating itself back to you.
Questions people ask
What's a good first prompt to get AI to argue against my plan?
Give it a stance and the plan in full: "You are a skeptical outside reviewer with no stake in this succeeding. Argue against this decision: [full plan]. Don't summarize it back to me first." The assigned stance and the ban on a compliment are what separate this from a generic "what do you think."
Does asking AI to play devil's advocate actually reduce confirmation bias with AI?
It helps. A structured adversarial prompt forces a pass through the plan that isn't looking for reasons to agree, which is the mechanism confirmation bias exploits according to the APA's definition of the bias. It isn't a guarantee, since the model can still miss a domain-specific risk it has no visibility into, but it reliably surfaces objections a plain "thoughts?" request would not.
Is this the same as asking AI to check its own work?
No. Checking its own work is self-review: the model rereads and re-derives its own prior answer. Devil's advocate prompting points the model at a human decision made outside the conversation and asks it to argue against that decision from an outside stance.
How do I stop the AI from being too agreeable when I ask it to red team my business plan?
Assign an explicit adversarial role instead of asking for an opinion, feed it the real numbers instead of a summary, and forbid the model from opening with a compliment or a restatement of the plan. All three remove the easy paths back to agreement.
Can I trust the objections an AI devil's advocate raises?
Treat them as hypotheses to verify, not a verdict. The model doesn't have your actual customer or financial data, so an objection like "trial-to-paid conversion will drop" is a prediction worth testing, not a proven fact.
How did this land?
About the author

Developer Advocate
Steve builds something with Swarmz every week and writes up what worked, what broke, and what he'd do differently. Tutorials and hands-on guides are his lane.


