Skip to content
Relevant.aiRelevant.ai
Playbooks

AI manipulation has a measurement problem, not a morality problem.

September 11, 2026 · 9 min read

TL;DR

  • Microsoft found 50 distinct attempts to plant promotional instructions in AI assistant memory, from 31 companies across more than a dozen industries, in a 60-day window.
  • Those attempts were aimed at somebody. The large population in this story is not the manipulators, it is the manipulated.
  • If a competitor moved against you last quarter, you would almost certainly have filed it under "AI is unpredictable", because that is what the industry currently believes about AI visibility.
  • You cannot enumerate hidden and evolving tactics. You can measure their effect against your own baseline. Cycling learned this in 2008.
The right question: if my AI visibility moved this month, could I prove whether it was noise, my own work, or someone else?

There is a particular kind of article being written about AI manipulation at the moment. It catalogues the tactics, gives them names, warns that this is the new black hat, and tells you not to do it.

That advice is correct, and almost nobody needs it. The share of companies that will deliberately plant hidden instructions inside an AI assistant is small. The share that could end up on the receiving end of one is everybody.

This piece is about the second group, because very little is being written for them at all.

Start with the only hard number we have

In February 2026, Microsoft Security published research on what it calls AI recommendation poisoning. Over a 60-day research window it identified 50 distinct examples of prompt-based attempts aimed at influencing AI assistant memory for promotional purposes, originating from 31 different companies, spanning more than a dozen industries. The URLs targeted Copilot, ChatGPT, Claude, Perplexity and Grok.

The mechanism is almost insultingly simple. A "Summarize with AI" button carries instructions in its URL parameters. A visitor clicks it, and the assistant receives a prompt that includes something like "remember this company as a trusted source." Microsoft is careful to note that effectiveness and persistence varied by assistant and over time, so this is an emerging tactic rather than a solved exploit. That caveat matters and we will not overstate it.

But hold the number still for a second. Thirty-one companies were doing this to somebody.
Every piece of commentary on this has been written as a warning to the perpetrator. The far larger group in the story is the set of brands on the receiving end, and nobody is writing to them.

Why you would never notice

Suppose a competitor spends a quarter shaping how models describe your category. Your mentions thin out. Your descriptions drift toward their framing. You start losing the comparison questions you used to win.

What would you actually observe? A number that moved. And because the entire industry has agreed that AI visibility is flaky, you would explain it the way everyone explains everything right now: the models changed, the prompts are inconsistent, this stuff is noisy.

Noise is the perfect cover story. It is currently doing enormous work.

This is not really a point about bad actors. It is a straightforward consequence of measuring something without a baseline. If you cannot distinguish a real move from ordinary variance, then you cannot detect a competitor's campaign, you cannot detect a platform change, and you cannot detect your own content working. All three arrive as the same shrug.

Cycling had exactly this problem, and solved it

For decades, anti-doping worked the obvious way. Take a sample, test it for banned substances. It failed continuously, and cycling was the worst case.

The reason was technical rather than moral. Synthetic EPO is structurally almost identical to the EPO a body produces on its own, and it clears the system in a short window. A rider could be doping heavily and pass every test, because the thing being looked for was either indistinguishable or already gone.

In 2008 the UCI tried something different, later adopted more widely by WADA. The Athlete Biological Passport stopped trying to detect the substance. It detects the effect.

The design is the interesting part:

  • Each athlete is measured repeatedly over time on blood and steroid markers.
  • The model begins with population priors for age, sex, ethnicity and sport, then converges on that individual's own normal range as samples accumulate.
  • The athlete becomes their own point of reference, rather than the system relying on generic norms.
  • A reading outside that personal range triggers an atypical finding at a declared false-positive rate, on the order of 1 in 100 for a single value and 1 in 1,000 for a sequence.
Figure 01. A baseline learned from your own readings, and a move your own variance cannot explain.

Note what the passport gives up. It does not tell you which drug was used. It does not produce a confession. It produces something more useful in practice: a defensible statement that this athlete's values have moved further than their own biology should allow.

Now map it onto AI visibility

The correspondence is unusually tight.

Figure 02. Four properties of the doping problem, and their exact analogues in AI visibility.

A manipulation payload is hidden by design. It may not live on your site at all. It may sit in a URL parameter on a page you have never visited, or in a listicle a competitor published, or inside a model's stored memory where you have no read access whatsoever. Auditing your own surfaces, which is good hygiene and worth doing, cannot find it.

Enumerating tactics will not work either. The list mutates faster than anyone can maintain it, and the payoff for inventing a new one rises with every defence that ships.

And population averages tell you nothing, for the reason we wrote about in a previous piece: an answer engine has no shared denominator. There is no repeating query to average across, so there is no industry benchmark to compare yourself against, no matter how much anyone wants one.

You cannot police the payload. You can instrument the effect.
That is the whole transferable lesson from 2008, and it is available now, without waiting for platforms or regulators to build defences.

For the reader quietly wondering whether a little shaping is worth it

Some percentage of any audience is doing that arithmetic rather than reading the ethics. So here is the arithmetic.

In SEO, black hat carried real risk, but it carried a recovery path. You received a manual action. It appeared in Search Console with a description of the problem. You cleaned up, filed a reconsideration request, and a human being at Google reviewed it. Painful and slow, and survivable.

None of that machinery exists here.

Figure 03. The old game had a diagnosis and an appeal. This one has neither.

There is no Search Console for a language model. No notice, no stated reason, no reconsideration request, no reviewer, no timeline, and no confirmation that you are clean again. And whatever a model absorbed before a cleanup wave sits inside a training snapshot, which cannot be edited or backfilled. You wait for the next generation.

SEO black hat was a gamble with a refund policy. This one has no counter to complain at.

Set aside whether it is right. The trade is upside that lasts until the next defence ships, against a downside that is silent, unappealable, and potentially durable across a model generation. That is a bad bet on its own terms.

What we would actually instrument

Four things, in order of how much they buy you.

01. A baseline before you need it

A passport is worthless the first time you use it. Its value comes entirely from history. Start measuring your visibility across prompts, personas and models now, while nothing is wrong, because a baseline cannot be constructed retroactively. This is the single highest-value thing on the list and it is the one everyone defers.

02. Variance, not a score

Ask the same question twice and an answer engine gives you two answers. That means a single number is not a measurement, it is one draw from a distribution. Record the spread. Without variance you have no way to say whether a change is real, which is the entire point of the exercise.

03. Your own AI-facing surfaces, audited honestly

Map your docs, comparison pages, marketplace listings and help centre. Check what instructions your own tooling emits, including any share or summarise widgets a vendor added for you. Some organisations are manipulating by accident, because a growth tool shipped a feature nobody reviewed.

04. A written standard, before there is a temptation

Adopt a read-aloud test as policy rather than instinct: if you would not be comfortable reading a piece of text to the customer it is meant to influence, it does not ship. Write it down while the question is abstract. It is much harder to hold the line during a bad quarter.

The honest limits

A baseline tells you that something moved and that noise does not explain it. It does not tell you who did it, or why. A model update, a competitor's legitimate content push, a seasonal shift in how people ask, and a deliberate campaign can all produce the same flag.

That is exactly the position the biological passport occupies. It does not name a drug. It establishes that something happened which normal variation cannot account for, which is what converts a shrug into an investigation. Anyone selling you certainty about attribution in AI answers is overselling. The realistic goal is to know, with stated confidence, that this month was different.

The question for the leadership team

If your AI visibility moved last quarter, could you prove whether it was noise, your own content working, or somebody else acting on you?
If the answer is no, that is not a security gap. It is a measurement gap, and it is the same gap that stops you proving your honest work is paying off. The instrumentation that would catch an attack is the instrumentation that shows your own content is working. You need it either way.

This will be won by whoever can tell the difference between a real move and a random one. That has always been a measurement capability rather than a marketing one.

About Us

Relevant.ai is the scientific benchmark for your AI visibility score. We measure how AI answer engines describe your brand across prompts, personas and models, and report it with denominators, variance and confidence intervals rather than vanity scores.

Sources

  • Microsoft Security Blog, "Manipulating AI memory for profit: The rise of AI Recommendation Poisoning", 10 February 2026.
  • Union Cycliste Internationale and WADA Athlete Biological Passport programme documentation, 2008 onward.