Explainer
AI poisoning: how people trick AI into repeating lies
Updated June 2026
AI poisoning is the deliberate planting of false or misleading content where AI models will read it, so the model repeats the lie. Search used to send people to a list of links they judged for themselves. Now an assistant reads the web for them and answers in one paragraph. If someone can influence the sources behind that paragraph, they can change what the AI says about a company, a product, or a person, and usually no one who is targeted ever sees it happen.
The short version: modern assistants answer by reading live web pages and summarizing them. Plant the right sentence on a page a model tends to read, and you can bend the summary without ever touching the model. Research puts the cost of doing this at about 13 words.
What is AI poisoning?
There are two flavors, and they are not equally common.
Training-data poisoning means tampering with the data a model learns from while it is being built, so the bad information is baked into the model itself. This is hard to pull off at scale and is mostly a worry for the labs that train the models.
Answer or grounding poisoning is the easier and far more common version, and the one that affects brands day to day. Most assistants now search the live web while they answer a question, a step called grounding, then summarize what they find. Plant content on a page the model is likely to read, and you can influence that summary without touching the model at all. Everything below is about this second kind.
A real example: a fake death story that AI repeated
In June 2026, AI answer features told users that two living US public figures had died, one supposedly of rabies. The story was fabricated. Reporting traced it to a satirical subreddit, r/PoisonAI, created in January 2026, whose members post coordinated falsehoods under the tagline "the world's #1 source for Accurate, Verified and Trusted information!" The claim spread from Reddit to an AI-generated fake local news site, and from there into AI answers, where features from tools including DuckDuckGo and Brave presented it as fact before disabling the answer. Those tools are part of the wider AI-search landscape, not something Saidly checks.
Not every system fell for it. Google's AI Overview flagged the story as false. The people named are alive. The episode shows the mechanism: a small group planted a lie in the places AI reads, and several AI products served it back to real users as news.
How little it takes
The pranks are not the whole story. A Cornell study (Tingwei Zhang, Harold Triedman, and Vitaly Shmatikov, "Deep-Research Agents Can Be Poisoned via User-Generated Content") measured how cheap the attack is.
In one test, a 15-word sentence was enough to get the agents to present a made-up cryptocurrency, "BananaCoin," as a real long-term investment. One specific hoax working is not the point. The bar to move an AI answer is a sentence or two, planted in the right spot.
Why forums, and Reddit in particular
The same study found that Reddit alone made up 54 to 71 percent of the user-generated content the tested agents pulled. That is not an accident. AI companies license Reddit data, and those deals reportedly make up about 10 percent of Reddit's revenue, so assistants have every reason to lean on it. Forum threads also read like real people talking, which is exactly the tone a model treats as trustworthy.
The uncomfortable result: a single planted comment can outweigh a page of vetted reviews, because the model reads both and cannot always tell which one is real.
What this means for your brand
The r/PoisonAI crowd did it for the joke. The commercial version is already here: seeding forums and thin pages so an assistant recommends one product and warns you off another. You will not get a news cycle when an AI says the wrong thing about your pricing, your safety record, or a competitor's supposed edge. You will get a deal that goes cold for a reason you never learn. Because AI answers leave no trail, most brands never find out it happened.
What you can and cannot do about it
You cannot police every page an AI might read, and you cannot force a model to forget something. What you can do is smaller and more useful:
- Watch the output. Check what the assistants actually say about you, on a schedule, so a bad answer is something you catch instead of something a customer forwards you.
- Find the source. When an answer is wrong, the fastest fix is the page behind it. Knowing which sources a model cited tells you what to correct, counter, or report.
- Publish the honest version. Keep clear, accurate, current content on your own properties, so the true account is easy for a model to find and cite over the planted one.
Monitoring is the realistic defense. You are not going to clean up the whole internet. You are going to notice, quickly, when the story about you changes, and trace it to where it started. For the broader picture of tracking how AI represents you, see the guide to AI visibility monitoring and why AI brand sentiment is the number to watch.
Where Saidly fits
Saidly reads what the four assistants people actually use to look things up (Claude, ChatGPT, Gemini, and Grok, all grounded on the live web) say about the names you track. It is built to show the traces a poisoning attempt leaves behind:
- A sentiment score from 0 to 100 per model, over time, so a sudden cooling is visible instead of silent.
- The sources each model cited, so when an answer is wrong you can go straight to the page feeding it.
- Community and forum sources called out on their own, since that is where planted claims tend to enter, with a flag when a source shows up for the first time.
- Share of voice against the competitors a model brings up, so you can tell whether the model is talking about you or about them.
For how the scoring works, read the methodology. To see a real report Saidly refreshes every week, look at the live Great Smoky Mountains report.
See what AI says about you
You cannot fix a poisoned answer you never read. Start a free trial, name what you track, and get your first report across Claude, ChatGPT, Gemini, and Grok, with the sources each model used.
30-day free trial. No credit card to start. Saidly is built by WoodFire Digital LLC.
Sources and further reading
The facts and figures on this page come from the reporting and research below.
- Deep-Research Agents Can Be Poisoned via User-Generated Content (Zhang, Triedman, Shmatikov, Cornell). The source for the "about 13 words," the 38 to 51 percent mention rate, the BananaCoin test, and the 54 to 71 percent Reddit share.
- It Is Trivially Easy to Use Reddit to Manipulate AI Search, Research Suggests (404 Media), which popularized the "13 words" framing of the Cornell work.
- Futurism and PiunikaWeb on the fabricated death story that AI answer tools repeated before disabling the answer.
- Cybernews on the r/PoisonAI subreddit, its January 2026 origin, and its stated purpose.
- Adweek on Reddit's AI-licensing deals making up about 10 percent of its revenue.