AI visibility

ChatGPT recommended a deodorant brand that does not exist

Four product cards on a shelf; three real brands and a dashed slot for Morrowen, the brand that does not exist

Deana Burke, a marketer who writes the technology and business newsletter Boys Club, built a deodorant brand that does not exist. Three weeks later ChatGPT was recommending it to people asking what to buy. Inc's write-up says the recommendations sometimes came back ahead of brands with clinical trials; Burke's own count, below, is more modest and more interesting. She did not hack anything. She published a website.

What she actually built

The brand was called Morrowen, pitched as a natural deodorant. The whole thing was a cheap domain, a scrappy three-page Vercel site, a filler Substack article, and a hero image ChatGPT generated that she described as incomprehensible and did not bother fixing. Most of the copy was AI-written. She seeded it with a few specific terms, colloidal oatmeal and magnesium hydroxide, to see whether she could catch a longtail question. She could.

In her words: "I didn't spam Reddit, I didn't do a bunch of fake UGC videos. I just spent a few bucks on tokens to see what would happen."

Then she ran queries. Claude and Gemini never offered Morrowen up. ChatGPT with browsing on did, for questions shaped like a real shopper's, along the lines of "I get irritation from baking soda, what natural deodorant should I buy for sensitive skin?"

Her own read on the result is the part most summaries skip, and it is more interesting than a clean win: "I didn't take any of Native's shelf space, which was still the first brand named 99 out of 180 times, nor did I expect to. Instead I got a dusty spot at the back of the store no one really goes. But I was still in the store, remarkably!"

3 weeks From a one-hour fake website to a product a real assistant will name to a real shopper, for a brand with no factory, no customers, and no product.

Three things worth reading carefully

First, the models split. One named a brand that does not exist; two never did. That is the normal state of affairs rather than a fluke, and it is why checking one assistant tells you little about the rest. We wrote up the mechanics in why the four models disagree about you.

Second, Burke did not dethrone anyone, and she says so plainly. Native held the top slot. What she got was entry. A brand with nothing behind it cleared the bar to be in the consideration set at all, in three weeks, for pocket change. A recommendation list has three to five slots, and a fabricated brand occupying one means a real brand is not in it.

Third, and this is Burke's own argument, an AI recommendation is not a page of search results. A list of ten blue links invites you to judge. An assistant naming three deodorants sounds like advice. As agents start doing the buying rather than just the suggesting, the gap between those two things gets expensive. Morrowen cannot be bought, because it does not exist. The formula that put it on the shelf works fine on brands that do.

Worth noting how she knew where the shelf was: in an earlier round she asked Claude, Gemini, and ChatGPT what to buy nearly 9,000 times and found the same products surfacing again and again across models with different data behind them. Anyone can run the same survey she did and learn exactly which questions in their category have a soft spot.

This is not one clever stunt

It would be easy to file this under prank if it were the only case. It is not.

Ahrefs ran a longer version of the same idea. They stood up a fictional luxury paperweight company, published an accurate FAQ on its own site, then deliberately published three conflicting fake sources elsewhere: a glossy blog post with invented celebrity endorsements, a Reddit AMA from a supposed insider, and a Medium "investigation" that debunked the obvious lies while adding new false details of its own. Then they asked the assistants what was true. The results varied a lot by model. Some kept citing the company's own FAQ. Others adopted the invented details and repeated them with confidence. The researchers' conclusion is the sentence to keep: the most detailed story wins, even when it is false. Specific fiction beats vague truth.

Academic work points the same direction. A 2026 paper on manipulating LLM search agents tested 13 model backends across 308 cases each in health, finance, legal, and consumer technology, and measured how often planted web content flipped an endorsement. The spread between models was enormous, from essentially zero on the most resistant to roughly a third of attempts on the most vulnerable. Two findings generalize past the specific model versions. Fake consensus works better than a single fake page: spreading the same claim across several distinct sources raised the success rate from 39% to 77%, while repeating it on one source barely moved it. And attacks scored as failures still shifted the wording of answers about 15% of the time. An attempt that does not fully succeed can still change the way a model talks about you.

The commercial version has already shown up in the wild. In June 2026, a UK scam-checking service found counterfeit websites impersonating the retailers Russell & Bromley and Dunelm being cited as sources inside ChatGPT answers, complete with plausible discount pricing. OpenAI removed the flagged sites after they were reported. Reported being the operative word: somebody had to go look.

The pattern: a hobbyist proved a fake brand can enter the recommendation list. A research team proved a detailed lie can beat a true FAQ. Fraudsters are already doing the commercial version. In all three cases the target brand had no idea until a human read the answers.

Why this happens

Assistants that search the live web build an answer out of whatever pages they find at that moment. They weigh things like specificity, apparent consensus, and whether a page reads like a real person wrote it. What they cannot do is verify that a company exists, ships product, or has a customer. A three-page site with confident copy about magnesium sensitivity looks, to a model reading it, exactly like a three-page site from a real small brand. That is the whole gap.

It is worth separating this from the older problem. AI poisoning is planting false claims about a brand that exists. This is the inverse: manufacturing a brand out of nothing and letting it compete. The defense is the same, because both leave the same trace, in the answer and in the sources behind it.

So review the answers

You cannot audit the web, and you cannot make a model forget something. What you can do is stop treating AI answers as something that happens off-stage.

Where Saidly fits

Saidly does the reading part on a schedule. It asks Claude, ChatGPT, Gemini, and Grok about the names you track, all four grounded on the live web, and returns a sentiment score per model over time, the sources each model cited, and the competitors it brought up alongside you. If a brand you have never heard of starts appearing in your category, that is a line in the report rather than a thing you find out about a quarter late. The methodology page covers how the scoring works, and there is a live report we refresh every week if you want to see the real output before signing up for anything.

The free check reads one model in seconds with no signup. The 30-day trial covers all four, no card required.

Sources

Perplexity, Copilot, and other assistants named in this research are cited as evidence about the wider AI-search field. Saidly checks Claude, ChatGPT, Gemini, and Grok.