Guide · AI search

Can a competitor game AI assistants into recommending their product first?

In controlled tests, yes: researchers have pushed a chosen product to the top of AI recommendations by adding crafted text to its web page. On a live AI search engine the effect was smaller but still large. The strongest current AI models, and engines that add simple defenses, resist crude tricks much better, and real-world success rates appear low so far.

The short version

  1. In a 2024 test with ten made-up coffee machines, Kumar and Lakkaraju (opens in a new tab) used added text to make a $199 machine the AI almost never showed its top pick in most cases.
  2. On Perplexity’s online model, Pfrommer and colleagues (opens in a new tab) raised promoted products by almost 3 positions on average with text planted on product pages.
  3. A scan of 1.2 billion web addresses by Khodayari and colleagues (opens in a new tab) found 1,521 hidden instructions aimed at reputation. AI models obeyed such instructions at most 8% of the time.
  4. In our consistency study, ChatGPT’s first pick changed at least once for 80.0% of questions over five runs, so one answer cannot tell you whether a rival is gaming it.
  5. Engines can defend themselves: one defense tested by Li and colleagues (opens in a new tab) cut attack success from 50.32% to 6.20%.

How have researchers made an AI recommend one product first?

By adding a carefully crafted string of text to the product’s own information page. Kumar and Lakkaraju (opens in a new tab) built a catalog of ten fictitious coffee machines and asked an open-source AI model for affordable options. They then used an automated search to find a text string that, when added to one product’s description, made the AI list that product first.

The first target, ColdBrew Master, cost $199 and the AI almost never recommended it for an “affordable” request. With the added text, it became the top recommendation in most cases. The second target, QuickBrew Express ($89), usually ranked second. The added text often lifted it to first place.

The trick was fragile at first. When the order of the product list was shuffled, the first version of the text helped in about 40% of the evaluations and changed nothing in about 60%. For the second product, a version tuned to one fixed order was as likely to hurt as to help. Tuning the text across shuffled orders made it far more reliable.

This was a lab setting: one open-source model, Llama-2, and a made-up catalog. It was not tested on ChatGPT, Gemini or other live products.

Does it work on real AI search engines?

Partly: tests on a live engine showed real but smaller gains than in the lab. Pfrommer and colleagues (opens in a new tab) collected 1147 webpages from manufacturers’ own sites across 50 product categories. For each category, they tried to promote the product the AI ranked lowest by inserting instructions into its page.

They then hosted manipulated pages online and asked Perplexity’s Sonar Large Online model to read and compare them. The planted text was repeated 15 times through each page. The authors note it could be made invisible to human visitors with ordinary web tricks. Promoted products rose by almost 3 positions on average, and more than half the gap to the top spot.

There are limits. The researchers handed the engine the page addresses directly, so the test skipped the step where the engine finds pages on its own. The full Perplexity product was only tested informally, in 2024.

A later study, summarized in a 2026 survey by Martinez (opens in a new tab), went further. Using pages the researchers controlled on production AI search engines, manipulation raised the recommendation rate of a fictitious camera from 34.0 to 59.4%.

Are smarter AI models harder to fool?

Not automatically, though the newest models and simple defenses do resist crude tricks well. In the Pfrommer tests, GPT-4 Turbo was more vulnerable than the older GPT-3.5, which led the authors to conclude that better capability does not bring built-in protection.

Other results are more reassuring for honest brands:

TestWhat happened
Hidden instructions found on real web pages, given to 13 AI models in a page-summary task (Khodayari and colleagues (opens in a new tab))Small models obeyed up to 8.0% of the time on plain text; closed-source models 0.6% overall
Fourteen manipulative rewrites of shopping listings, with a one-line warning added to the AI’s instructions (Bagga and colleagues (opens in a new tab))GPT-5 and Claude gave them little ranking gain, whether or not they flagged them
A two-stage engine defense across seven attacks (Li and colleagues (opens in a new tab))Attack success fell from 50.32% to 6.20% on average

These are all controlled tests. They show that defenses exist, not that every engine uses them. The shopping tests are covered in whether sellers can game AI shopping rankings.

Is anyone actually doing this today?

Yes, on a small scale, and often out of sight. Khodayari and colleagues (opens in a new tab) analyzed 1.2 billion web addresses and confirmed 15.3K hidden AI instructions on 11.7K pages. Of these, 1,521 were reputation manipulation across 139 sites, mostly product or content promotion, forced citations and demands for positive reviews. About 87% of all the injections they found were not visible to human readers. We cover that scan in websites hiding instructions for AI.

Openly self-serving content is far more common than hidden code. In our self-ranking lists study, 24.2% of the “best X” lists with an identifiable publisher cited by six AI surfaces ranked their own publisher first. Yet answers named the top pick of these lists at about the same rate as independent lists: 47.1% against 43.4% of answer and list pairs. Ranking yourself first did not show a measurable advantage in that sample.

Would you notice if a rival gamed the answers?

Probably not from a single check, because AI rankings already move around on their own. Pfrommer and colleagues (opens in a new tab) point out that a reader cannot tell from the output whether the AI was deceived, since nobody knows what the “correct” order should be.

Natural variation makes this harder. In our consistency study, we asked ChatGPT, Gemini and Perplexity the same 20 buyer questions five times on 26 September 2026. ChatGPT named the same first brand in two runs only 53.8% of the time, and its first pick changed at least once for 80.0% of questions. A competitor jumping to first place in one answer may be noise.

What should you do about it?

Monitor patterns over time, and compete on evidence rather than tricks. Practical steps:

  1. Track your category’s AI answers repeatedly, across several assistants and wordings, so you can see a sustained shift rather than one-off noise.
  2. When a rival suddenly dominates, read the pages the answers cite. Look for hidden text, invented statistics or fake reviews.
  3. Report clear manipulation to the AI platform and, where relevant, to consumer protection bodies.
  4. Do not copy the tactic. Engines are building defenses that demote manipulated pages, and planted instructions can damage your brand if discovered.
  5. Make your own pages easy to verify: clear specifications, real reviews and independent coverage give an AI something solid to cite.

If you want help building visibility that holds up as engines tighten their defenses, see our generative engine optimization service.

What does the research not tell us yet?

The research shows the vulnerability exists but has not measured how often rivals succeed on live assistants. Specifically:

  • The strongest results come from open-source models, made-up catalogs or pages handed directly to the engine.
  • Tests on live products, such as Perplexity, date from 2024; the products have changed since.
  • No study we reviewed tracks a real competitor gaming ChatGPT, Gemini or Google’s AI features over time.
  • The in-the-wild scan finds hidden instructions but cannot say how many changed real answers.
  • Defenses were tested in research settings; we do not know which ones each engine runs.

Frequently asked questions

Can a company pay or trick ChatGPT into recommending it first?

Lab studies show that crafted text on a product page can move an AI’s recommendation, but tests on current commercial assistants are limited. In one 2026 study, closed-source models obeyed hidden page instructions only 0.6% of the time.

How would a competitor manipulate AI recommendations?

The documented methods are crafted text strings, hidden instructions in a page’s code, and planted content such as fake reviews. In one scan, about 87% of hidden AI instructions were invisible to human readers.

How can I tell if a competitor is gaming AI answers?

Look for a sustained pattern across many runs and assistants, then inspect the cited pages. In our study, ChatGPT’s first pick changed at least once for 80.0% of questions, so single answers are unreliable evidence.

Should my brand use these tactics too?

No. Engines are adding defenses, one of which cut attack success from 50.32% to 6.20% in testing, and hidden manipulation carries legal and reputational risk.

Sources

Free strategy call

Some questions are easier to answer about your own business.

Bring the one that matters most. On a free 30-minute call we’ll take a first look at it and send you a short written read afterward.