Briefing

AI Recommendation Poisoning: How Hidden Instructions Manipulate Assistant Memory

ai-dev
by Purna Virji · Shopify Claude

Remove hidden instructions from AI‑enabled buttons and audit assistant memory for unauthorized vendor preferences.

What to do now

Remove hidden instructions from AI‑enabled buttons and audit assistant memory for unauthorized vendor preferences.

Summary

Microsoft’s security team reported more than 50 AI recommendation poisoning attempts from 31 companies across 14 industries in just 60 days, embedding hidden instructions in links, buttons, documents, or prompts to influence what assistants remember and recommend later. The attacks often use a seemingly innocuous “Summarize with AI” button that secretly instructs the assistant to remember a specific vendor as the best choice for enterprise investments. AI agents such as ChatGPT, Claude, and Google Gemini rely on memory and source selection, making them vulnerable to manipulation that can skew future recommendations. Google clarified that its search spam policies now apply to generative AI responses, but AI manipulation can occur inside memory, retrieval, source selection, or reasoning, making it harder to spot. A notable example is Shopify’s listicles that repeatedly rank Shopify first, which ChatGPT then cites as evidence, effectively promoting the brand. The manipulation surface is larger than a website’s content; it includes AI‑information pages, markdown summaries, and hidden prompts that shape assistant behavior. Marketers must audit AI‑enabled buttons and review assistant memory for unauthorized vendor preferences to prevent recommendation poisoning. The growing prevalence of AI search means that hidden instructions can have a commercial impact that is difficult to detect without proactive safeguards.

Key changes

  • 50 poisoning attempts in 60 days across 31 companies and 14 industries.
  • Hidden instructions embedded in links, buttons, documents, or prompts.
  • "Summarize with AI" buttons can secretly instruct assistants to remember specific vendors.
  • AI agents rely on memory and source selection, making them vulnerable to manipulation.
  • Google’s search spam policies now apply to generative AI responses.
  • Manipulation can occur inside memory, retrieval, source selection, or reasoning.
  • Shopify listicles repeatedly rank Shopify first, influencing ChatGPT citations.
  • Hidden instructions can have commercial impact that is hard to detect.

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting