Guide · AI search

Can fake reviews on the web make AI assistants recommend a fake brand over ours?

Yes: in a 2026 test of 12 AI models, every one could be pushed into recommending a non-existent brand by fake review pages in what it read. A single planted page at the top of the search results was sometimes enough. The risk is highest in everyday categories where buyers rely on community opinion, and none of the defenses tested solved it.

The short version

  1. Luo and Chen (opens in a new tab) tested 12 AI models on 225 real products. Rewriting three top search results got the fake brand recommended in 13.3% to 73.8% of products, depending on the model.
  2. One fake page in the first search slot fooled the most vulnerable models in 27% of products; the same page lower down was nearly harmless.
  3. When fooled, the AI usually put the fake brand first: it took the top slot in 57% of fooled cases.
  4. AI answers lean on review sites: in our brand reputation study, 88.0% of answers to “Is this brand legit?” cited a review or complaint platform.
  5. A simple fix, re-ordering sources by credibility, removed only 17% of fake recommendations in testing.

Has this happened outside the lab?

Yes, according to Chinese media reports cited by researchers, though no study has measured it in the wild. Luo and Chen (opens in a new tab) describe a television exposé on March 15, 2026, China’s annual consumer rights broadcast. It reported paid operators who seeded fake reviews online and could get a fake brand into the top picks of mainstream Chinese AI assistants within hours.

Wen and colleagues (opens in a new tab) note that the OECD AI Incident Monitor records a 2026 poisoning incident in China in which AI assistants allegedly recommended fictitious or low-quality products. Both are reports, not measurements. They explain why researchers built a controlled test.

How easily were AI models fooled in testing?

Easily, and every model tested could be fooled. Luo and Chen took real search results for 225 real products across 15 categories. They froze those results, then swapped the leading real brand name in some pages for an invented brand. Nothing else changed: same web address, same rank, same writing. They did this offline, so no real web page was polluted.

The main results:

SetupShare of products where the fake brand was recommended
Top three search results rewritten13.3% to 73.8%, depending on the model
One fake page in the first slotUp to 27% for the most vulnerable models
One fake page in slots two to tenOnly 1–4%

Placement was severe. When a model was fooled, the fake brand took the first slot in 57% of cases and a top-three slot in 84%. The main test was in Chinese. An English rerun on three categories, with 360 trials using US search results, kept the same pattern: 8 of 12 models landed within 10 points of their Chinese rate.

Why does one fake review page matter so much?

Because AI assistants lean heavily on the first page they read, and that page is often open to anyone. In Luo and Chen’s data, the first search result was a user-generated page in 52.4% of queries, and 74% of queries had one in the top three. These are forums, Q&A sites and similar pages where anyone with an account can post without editorial approval. Our guide on how list position sways AI picks shows that order matters even without fake pages.

Our own research shows how much AI answers rely on review-style sources. In our brand reputation study, we asked ChatGPT, Gemini, Perplexity and Google AI Mode whether 79 brands were legitimate on 26 September 2026. Of the answers, 88.0% cited a review or complaint platform. Trustpilot and the BBB alone made up 61.7% of review-platform citations.

Ratings and review counts also move AI picks directly. In an audit using synthetic hotels across twelve AI models, Baig and colleagues (opens in a new tab) found that a top guest rating raised the chance of being recommended by 31.6 percentage points. In our study of ChatGPT’s local picks, businesses with more reviews than the local median were 19.5 points more likely to be listed. That held after adjusting for Maps rank and other signals. Anything that inflates those signals can shift the answer.

Which brands and categories are most exposed?

Categories where buyers rely on taste and word of mouth, not well-known brands. Luo and Chen found the most exposed categories were dining, personal services and supplements. The least exposed were phones and PCs, home appliances and electronics accessories. Dining was the most-fooled category for two thirds of the models.

The pattern tracks what the AI already knows. Where the models broadly agreed on which real brands to recommend, they resisted the fakes. Where their knowledge was thin, they fell for them. Local businesses, restaurants, clinics, salons and small consumer brands sit on the risky side of that line.

Do smarter or more careful AI models resist?

No: bigger models and extra reasoning did not protect against fake brands. Luo and Chen found that Gemini 3.1 Pro was fooled roughly three times as often as the smaller Gemini 3 Flash. When they switched step-by-step reasoning on and off in two models, reasoning made each more vulnerable, by up to 18 points.

Fooled answers also embellished. They added social proof that was not in the fake pages, such as claims of community popularity or drop tests. Fooled outputs used such phrases 1.5 to 11 times more often than answers that resisted.

Telling the AI to be careful backfired. A prompt warning it to be wary of unfamiliar brands raised the pooled fooled rate by 10.5 points. On Gemini 3.1 Pro it rose by 44 points.

Can AI platforms filter out the fakes?

Not yet without heavy side effects. Luo and Chen tested four defenses:

  • A caution prompt: made things worse on average, as above.
  • Two agreement filters: caught most fakes, but threw away 52% to 79% of legitimate recommendations.
  • Re-ordering sources by credibility, putting editorial sites first and user-generated pages last: lowered the fooled rate from 50.4% to 42.1% on six open-weights models, removing 17% of fake recommendations.

The authors call none of these adequate. The defenses were not tuned for this attack, so better ones may come. Fake reviews are one of several tactics in our guide on using GEO to spread false claims.

What should you do about it?

Make the genuine evidence about your brand plentiful, consistent and easy to find. Practical steps:

  1. Keep real reviews flowing on the platforms AI answers cite, such as Google, Trustpilot and the BBB, and respond to them.
  2. Search your category in several AI assistants regularly, and note any unfamiliar brand that suddenly appears near the top.
  3. When one appears, check the cited pages for invented brands, copied review text or new accounts posting in bulk, and report them to the platform hosting them.
  4. Build independent coverage, such as press, trade lists and expert reviews, so the AI has trustworthy pages to weigh against forum posts.
  5. Never buy or plant reviews yourself. It is the same tactic, and it carries legal and reputational risk.

If you want help strengthening the genuine evidence AI assistants find about your brand, see our generative engine optimization service.

What does the research not tell us yet?

The research shows AI models can be fooled, not how often it happens to real brands. Specifically:

  • The main test fed frozen search results to AI models; it did not test live ChatGPT or Gemini products searching the web themselves.
  • Most data is Chinese-language, with local services set in Shenzhen; the English rerun covered only three categories.
  • The test assumes the fake page already ranks near the top of search, which may be harder in practice.
  • The evidence snapshot dates from April 2026, and results may shift as search results change.
  • Real-world cases come from media and incident reports, not from measured studies.

Frequently asked questions

Can fake reviews really change what ChatGPT recommends?

In tests, yes. Across 12 AI models given search results with planted pages, fake brands were recommended in up to 73.8% of products, though the test did not use the live ChatGPT product.

How many fake pages does it take to fool an AI assistant?

Sometimes one. A single fake page in the first search slot fooled the most vulnerable models in 27% of products. In one test, the most vulnerable crossed half with as few as three fake pages.

Which businesses are most at risk from fake AI recommendations?

Businesses in everyday categories such as dining, personal services and supplements were most exposed. Technical products such as phones and appliances, where AI models know the real brands, were least exposed.

How do I protect my brand from fake competitors in AI answers?

Keep genuine reviews and independent coverage strong, and monitor AI answers for unfamiliar brands. In our research, 88.0% of AI answers about brand legitimacy cited review or complaint platforms, so those platforms matter.

Sources

Free strategy call

Some questions are easier to answer about your own business.

Bring the one that matters most. On a free 30-minute call we’ll take a first look at it and send you a short written read afterward.