Why 'AI Poisoning' Should Be on Every Brandโs Radar: A Looming Commercial Incentive
THEIR PRODUCT LAUNCH was performing right on plan.
A dairy manufacturer had invested heavily in a new premium Greek yogurt range. Distribution was expanding, retail partners remained supportive and consumer complaints remained low. Independent product testing was positive and social media sentiment showed little cause for concern. There was every indication that the brand was gaining momentum.
Then the numbers began to change.
Online sales softened. Not dramatically, but enough to warrant closer inspection. Marketing campaigns were performing as expected, pricing had not changed and there were no supply issues. Retailers had raised no concerns and customer service teams were reporting no meaningful increase in complaints.
Next Week: Part Two - Implications for Brands and Retailers
The answer emerged from an unexpected source.
When the company asked several AI shopping assistants to recommend the best high-protein yoghurt, its products still appeared in the responses but with subtle warnings attached.
- โSome shoppers report inconsistent texture.โ
- โThere are concerns over quality.โ
- โBuyers may prefer alternatives with stronger customer reviews.โ
None of the statements amounted to outright criticism, yet collectively they introduced just enough uncertainty to make consumers think twice.
The marketing team began investigating. It uncovered a growing collection of Reddit discussions, forum posts, Quora answers and obscure review websites all repeating remarkably similar themes. The wording varied from platform to platform, but the underlying message rarely changed. Many posts originated from recently created accounts while others appeared on websites with little evidence of genuine readership. Several even recommended the same competing brand.
Individually, none of these posts appeared especially significant. Together, however, they had become part of the evidence that AI systems were using to construct their recommendations.
This scenario is hypothetical, but the technology behind it is very real.
As consumer goods manufacturers and retailers embrace AI-powered shopping assistants, conversational commerce and generative search, a new competitive risk is emerging. Researchers have begun referring to it as AI poisoning, and while the term covers several different attack methods, one area deserves particular attention from the consumer goods industry: the manipulation of the information sources that large language models rely upon when recommending products.
From search rankings to AI narratives
Artificial intelligence is rapidly becoming a preferred route to product discovery. Consumers are increasingly asking ChatGPT, Gemini, Claude, Perplexity and retailer-owned assistants which products they should buy rather than relying solely on traditional search engines.
To answer those questions, many AI systems retrieve information from a wide range of online sources including product reviews, Reddit discussions, specialist forums, comparison websites and other forms of user-generated content. The underlying assumption is straightforward. If numerous independent sources reach similar conclusions, those conclusions are likely to be credible.
That assumption also creates vulnerability.
Rather than attempting to attack the AI model itself, bad actors can instead seek to influence the information ecosystem surrounding it. By distributing sufficient quantities of fabricated reviews, coordinated forum discussions or misleading comparison articles across platforms frequently consulted by AI systems, they increase the likelihood that those claims become incorporated into AI-generated responses.
This represents a significant departure from the search engine optimization strategies that have shaped digital marketing for the past two decades.
Traditional SEO sought to persuade Google that one webpage deserved to rank above another. Generative Engine Optimization, or GEO, focuses instead on influencing the evidence an AI model uses to formulate its answers.
Google ranked webpages. Large language models synthesize narratives.
That distinction is important because shoppers are increasingly receiving recommendations instead of lists of links. AI is beginning to compress the path between product discovery and purchase, placing far greater emphasis on which products appear within a small number of recommendations.
A commercial incentive is already emerging
The idea of manipulating AI recommendations may sound like science fiction, yet there is growing evidence that commercial organizations are already exploring exactly that.
Earlier this year, Chinaโs CCTV 3.15 Consumer Rights Gala exposed what it described as a black-market industry dedicated to influencing AI-generated recommendations. Investigators demonstrated how a fictional Apollo-9 smart bracelet was transformed into what appeared to be a legitimate product after a GEO platform generated fake reviews, promotional articles and supporting content distributed across multiple websites.
Within hours, AI systems began repeating the fabricated claims. After several days of additional content, some models were recommending the non-existent product to users.
Perhaps the most revealing aspect of the investigation was not the technology itself but the commercial rationale behind it. One GEO operator reportedly argued that companies spending substantial sums on conventional advertising could achieve similar visibility by investing a fraction of that amount in influencing AI recommendations because only a limited number of products are surfaced within AI-generated responses.
Whether or not that proves commercially effective over the long term, it demonstrates how some marketers are already viewing AI as the next battleground for digital visibility.
Nor is the issue confined to China.
Researchers at Cornell Tech recently demonstrated that retrieval-based AI systems could be influenced by surprisingly small amounts of strategically placed user-generated content. Their work suggested that platforms such as Reddit are particularly influential because they appear frequently among the sources retrieved by AI systems when answering questions.
Beyond theory
Meanwhile, investigative reporting by 404 Media documented companies flooding Reddit communities with promotional discussions designed specifically to influence ChatGPT and Google AI Search. UK authorities have also warned that poisoned AI recommendations have directed consumers towards fraudulent shopping websites.
Taken together, these incidents suggest that AI poisoning has moved beyond theory. As AI assumes a greater role in product discovery, attempts to influence its recommendations are likely to become increasingly sophisticated.
Next week: Implications for Brands and Retailers
Howard Lake is a retail commentator with over 14 yearsโ experience and writes extensively on the retail industry at his Retail Slop Substack. howardlake@virginmedia.com