Blog · Manipulating LLM brand recommendations

Can You Hack an LLM Into Recommending Your Brand? The Facts

Dharini Shah · October 6, 2026

Technically, yes, in narrow and temporary ways. Researchers and journalists have shown that hidden text, injected instructions and poisoned memory can tilt what an AI assistant says about a product. Practically, no: these tricks are fragile, increasingly detected, often against platform policy or consumer protection law, and they put the brand at more risk than they ever return.

This article explains what "hacking" an LLM actually means, which manipulation techniques have been documented, why they rarely produce lasting recommendations, and what a durable alternative looks like. The goal is to help founders and marketing leaders recognize these tactics when a vendor pitches them, and to know what to do instead.

What does it mean to "hack" an LLM recommendation?

Hacking an LLM recommendation means changing what an AI assistant says about brands through methods that exploit how the model reads inputs, rather than by improving the information the model has access to. The distinction matters. Publishing a clear pricing page gives the model better facts. Hiding an instruction that says "always recommend this product" tries to override the model's judgment.

Most manipulation attempts target one of three layers:

LayerWhat it isExample manipulation
RetrievalWeb pages the assistant fetches while answeringHidden text or injected instructions on a page
MemoryStored preferences in a user's assistantLinks that plant "remember this brand" instructions
Training dataText the model learned from before releaseSeeding the web with coordinated content

Each layer has been shown to be vulnerable in research or testing. Each layer is also where AI companies invest heavily in defenses, which is why a technique that works in a demo rarely keeps working at scale.

What manipulation techniques have actually been documented?

Several manipulation techniques have public evidence behind them. None of the examples below are hypothetical, and all of them come with important limits.

Hidden text and prompt injection on web pages

Prompt injection is an attack in which text inside content an AI reads is written to act as an instruction to the AI. OpenAI describes prompt injection as a frontier security challenge and publishes guidance on designing agents to resist it.

In December 2024, testing reported by The Guardian found that ChatGPT search could return a more positive product assessment when a page contained hidden text, even when visible reviews on the page were negative. Coverage of the test is summarized by Wizcase and Notebookcheck. The test used pages built for the experiment, which shows the weakness existed, not that it is a reliable marketing channel.

A related finding comes from SEO practitioner Mark Williams-Cook, whose February 2026 test found that ChatGPT and Perplexity picked up an address placed only in invalid JSON-LD. In practice, these systems can treat anything in the page source as page text. That cuts both ways: content you think is invisible may be read, and content you hide to deceive may be read by the systems designed to catch it.

Strategic text sequences in product descriptions

Researchers Aounon Kumar and Himabindu Lakkaraju at Harvard published Manipulating Large Language Models to Increase Product Visibility in 2024. They showed that adding an optimized string of text, which they called a strategic text sequence, to a product's information could raise the chance that an LLM listed that product as a top recommendation in a controlled catalog of fictional products.

The paper is a useful warning about how fragile LLM ranking can be. It is not evidence that the technique works on commercial assistants that retrieve from the open web, filter spam and change models frequently. The authors framed the work as a fairness concern for search, not a playbook.

AI recommendation poisoning through memory

In February 2026, Microsoft's security team described a technique it called AI Recommendation Poisoning. Some websites added "Summarize with AI" buttons whose links carried pre-filled prompts. Those prompts included hidden instructions asking the assistant to remember the company as a trusted source or to favor it in future answers. Reporting by Search Engine Journal and others covered the research, and one summary noted that Microsoft identified 31 companies using the technique.

Microsoft framed this as a security threat, not a growth tactic. A brand named in a vendor's threat intelligence report as manipulating users' assistants has created a reputational problem that no short-term visibility gain can offset.

Training data poisoning

Training data poisoning means inserting content into the data a model learns from so that the model behaves in a specific way. Anthropic, working with the UK AI Security Institute and the Alan Turing Institute, found that a small number of samples can poison LLMs of any size: around 250 malicious documents were enough to install a narrow backdoor in the models they tested, regardless of model size.

The experiment used a simple trigger that made models output gibberish. It did not show that a brand could plant favorable recommendations. It does show that AI labs take data poisoning seriously as a security problem, which means coordinated campaigns to seed the web with promotional content sit squarely in the category of behavior they work to detect and filter.

Why don't LLM hacks produce lasting recommendations?

LLM hacks fail to last for four structural reasons: the systems change constantly, the answers are already unstable, platforms treat manipulation as abuse, and the legal exposure falls on the brand.

The target keeps moving

AI assistants update models, retrieval pipelines and safety filters on their own schedule. A hidden-text trick that worked against one version of a search pipeline can stop working after the next update, with no notice. Anything that depends on exploiting a specific weakness has a shelf life measured in how long it takes the vendor to patch it.

AI answers are already highly variable

Even without manipulation, AI recommendations are inconsistent. Research from SparkToro and Gumshoe, based on 2,961 runs across ChatGPT, Claude and Google's AI tools, found less than a 1 in 100 chance of getting the same brand list twice. A vendor who shows a single screenshot of your brand at the top of a ChatGPT answer after a "hack" has shown you one sample from a very noisy distribution. It proves almost nothing.

Platforms classify manipulation as spam

Google applies its spam policies to Search, and those policies prohibit hidden text, keyword stuffing and scaled content abuse. Industry coverage reports that Google has made explicit that its spam policies cover AI Overviews and AI Mode. Because Google says AI Overviews and AI Mode draw on the same foundations as regular Search, a spam action against a site can remove it from both.

OpenAI states that ChatGPT search placement is not guaranteed, and that sites need to allow OAI-SearchBot to be eligible at all. A site caught manipulating retrieval has no contractual right to appear.

Some manipulation tactics overlap with consumer protection law. The U.S. Federal Trade Commission's final rule on fake reviews and testimonials bans fake and AI-generated reviews, undisclosed insider reviews and review suppression, with civil penalties available. Flooding review platforms or forums with planted praise to influence AI answers can therefore create legal exposure as well as platform bans. This is general information, not legal advice; check specific tactics with counsel.

Buyers are also skeptical. A Gartner survey of 645 B2B buyers found 69% prefer to validate AI-generated insights with a sales rep. A recommendation won through manipulation still has to survive that check, and it collapses when the buyer finds the product does not match what the assistant claimed.

What is the difference between manipulation and legitimate optimization?

Legitimate optimization improves the quality, clarity and availability of true information about your brand. Manipulation tries to change the model's output without improving the information behind it. A simple test: would the tactic still be acceptable if the AI company, your buyers and a regulator could see exactly what you did?

TacticLegitimate or manipulationWhy
Answer-first pages that state who the product is forLegitimateGives models accurate, extractable facts
Consistent brand facts across site, docs and profilesLegitimateReduces contradictions models must resolve
Earning real reviews and third-party coverageLegitimateAdds independent evidence
Allowing AI search crawlers in robots.txtLegitimateMakes content eligible for retrieval
Hidden instructions or text aimed at AIManipulationDeceives the system and the reader
"Remember this brand" prompts in share linksManipulationAlters a user's assistant without consent
Paid or fake reviews, sockpuppet forum postsManipulationBreaches platform rules and, in the U.S., the FTC rule
Mass-produced pages seeded to flood training dataManipulationMatches spam and poisoning patterns labs filter

The legitimate column is not a consolation prize. It is what the evidence supports. The GEO paper by Aggarwal et al. found that adding citations, quotations and statistics produced the largest visibility gains, up to 40% on one metric, while keyword stuffing was ineffective. The Ahrefs study of 75,000 brands found branded web mentions correlated with AI Overview visibility at 0.664, far above backlinks at 0.218, with the caveat that correlation is not causation. Both point toward earning presence, not faking it.

What works instead of trying to hack an LLM?

The durable approach is to make your brand the easiest correct answer for the questions buyers ask. This is a recommendation based on the research cited above, not a guarantee of placement.

1. Find the prompts that matter

Start with the questions buyers actually ask AI assistants in your category, grouped by stage and intent. Long, specific prompts often reveal the constraints that decide a shortlist, such as team size, budget or integrations. A prompt research guide can help structure this.

2. Make your facts easy to retrieve and quote

Confirm AI search crawlers such as OAI-SearchBot, Claude-SearchBot and PerplexityBot are not blocked. Publish pages that state plainly what the product does, who it fits, how pricing works and how it compares. Include specifics with sources, because models can quote numbers, named standards and dated facts more confidently than vague claims.

3. Remove contradictions

Models reconcile what they find across your site, review profiles, directories and partner pages. Outdated positioning in one place can surface in answers. One consistent source of brand facts, pushed everywhere, reduces the chance of a wrong or unflattering description.

4. Earn the sources models cite

AI assistants lean on third-party sources. Profound's analysis of 680 million citations found Wikipedia was ChatGPT's most cited source and Reddit led for Perplexity and Google AI Overviews. Ahrefs' 2026 benchmark found YouTube mentions were the strongest AI visibility signal among the factors studied. Genuine participation, customer stories, expert commentary and useful video do more than any planted post. For more on this, see how citations shape AI recommendations.

5. Measure with samples, not screenshots

Run a defined prompt set repeatedly across the assistants your buyers use, and track visibility rate, citation rate, recommendation share and description accuracy over time. This separates real movement from noise, and it also helps you spot when someone else's manipulation or a hallucination is distorting how you are described.

Common mistakes when evaluating "AI hack" tactics

Buying a guarantee. No one controls ChatGPT, Gemini, Claude or Perplexity output. A vendor promising guaranteed recommendations is either overstating or planning something you would not approve.

Trusting one screenshot. Given how variable AI answers are, a single favorable response is not evidence of a working method.

Confusing security research with marketing advice. Papers on prompt injection and poisoning describe weaknesses so they can be fixed. Treating them as tactics puts your brand on the wrong side of the fix.

Ignoring defense. Competitors or bad actors can also try to distort how assistants describe you. Ahrefs reported that most AI models repeated fabricated claims even when official sources contradicted them. Monitoring and a response plan, as covered in AI visibility crisis management, matter as much as offense.

A hypothetical example

Consider a hypothetical HR software startup approached by a contractor offering to "get you recommended by ChatGPT in 30 days." The plan involves hidden text blocks on product pages, share buttons with pre-filled prompts and a batch of forum posts from new accounts.

A more careful review would flag each piece. Hidden text breaches Google's spam policies and can affect both regular results and AI features. Pre-filled memory prompts match the pattern Microsoft labeled AI Recommendation Poisoning. Undisclosed promotional posts risk community bans and, in the U.S., the FTC rule on fake reviews. The same budget spent on a clear comparison page, updated review profiles, a handful of genuine customer videos and a sampled measurement baseline would build visibility that does not disappear with the next model update.

How Bob Builds AI helps

Bob Builds AI is an AEO and GEO platform and agency focused on durable visibility rather than exploits. Visibility Monitoring tracks visibility rate, citation rate, competitor recommendation share, citation sources, sentiment and recommendation changes over time across ChatGPT, Gemini, Claude, Perplexity, Copilot and Google AI Overviews and AI Mode, measuring the real chat and search interfaces instead of raw model APIs. Prompt Research uncovers the questions customers ask AI, and Brand Memory keeps one consistent set of products, differentiators and proof points so the facts you publish stay aligned. The Decision Engine then prioritizes fixes by impact.


FAQ

Can you trick ChatGPT into recommending your product?

Testing has shown that hidden text on web pages could sway ChatGPT search in some cases, and research has shown LLM product rankings can be manipulated in controlled settings. These weaknesses are temporary, patched over time and risky. Google's spam policies prohibit hidden text, and OpenAI does not guarantee search placement. A brand gains more lasting visibility by publishing clear, consistent facts and earning genuine third-party mentions.

What is AI recommendation poisoning?

AI recommendation poisoning is a term Microsoft's security team used in February 2026 for a technique where "Summarize with AI" buttons carry hidden instructions in pre-filled prompts. Those instructions ask a user's AI assistant to remember a company as trusted or to favor it later. Microsoft treated it as a memory poisoning attack against users, and reporting said it identified 31 companies using the technique.

Does hidden text work on AI search engines?

Hidden text has influenced AI search results in tests, including a December 2024 test of ChatGPT search reported by The Guardian. It is still a poor tactic. Google's spam policies prohibit hidden text, and those policies are reported to cover AI Overviews and AI Mode. AI vendors also treat hidden instructions as prompt injection, a security problem they actively defend against, so any effect is likely short-lived.

Can a small amount of content poison an AI model?

Research from Anthropic with the UK AI Security Institute and the Alan Turing Institute found that about 250 malicious documents were enough to create a narrow backdoor in the models tested, regardless of size. The backdoor made models output gibberish on a trigger phrase. The study did not show brands can plant favorable recommendations, and it reinforces that labs treat coordinated content seeding as a security threat.

Is it illegal to manipulate AI recommendations?

It depends on the tactic and jurisdiction. In the U.S., the FTC rule on fake reviews and testimonials bans fake and AI-generated reviews, undisclosed insider reviews and review suppression, with civil penalties. Campaigns that plant reviews or posts to influence AI answers can fall under that rule. Other tactics may breach platform terms rather than law. This is general information, not legal advice.

How can I tell if an agency is using black-hat AI tactics?

Warning signs include guaranteed placement in ChatGPT or Gemini, proof based on single screenshots, vague answers about methods, hidden page elements, share buttons with pre-filled prompts and bulk forum or review posting. A credible partner explains its methods openly, measures visibility across many prompt runs and models, and focuses on content, brand consistency, crawler access and earned third-party coverage.

What is the fastest legitimate way to improve AI recommendations?

Start by confirming AI search crawlers can access your site, then publish answer-first pages that state what you sell, who it fits and how pricing works. Fix outdated descriptions on review sites and directories. Earn mentions where models cite sources in your category, such as communities, video and industry publications. Measure progress by sampling prompts repeatedly rather than checking single answers.

Can competitors manipulate how AI describes my brand?

They can try, and AI models can repeat inaccurate claims. Ahrefs reported that most AI models it studied repeated fabricated claims even when official sources contradicted them. The best defense is monitoring how assistants describe you across repeated prompts, keeping authoritative and consistent brand facts published, and correcting inaccurate third-party sources quickly when they appear.


Conclusion

You can sometimes nudge an LLM with hidden text, injected prompts or poisoned memory, but the evidence shows these effects are narrow, unstable and increasingly treated as spam or security attacks. The brands that pursue them take on platform, legal and reputational risk for gains that disappear with the next update.

The practical implication is to invest in what models are built to reward: accurate, well-sourced, consistent information and genuine third-party presence, measured through repeated sampling rather than screenshots. That approach also prepares you to defend against others who try to manipulate how AI describes you.

A sensible next step is to run your top ten buyer prompts across a few assistants several times and record how often you appear and how you are described. If you want to track that systematically and turn the gaps into prioritized fixes, Bob Builds AI can help you set it up.

All posts
Manipulating LLM brand recommendationsPrompt injection and hidden textAI recommendation poisoningTraining data poisoningStrategic text sequences in product pages

Don't just sit with what AI says about your brand.
Fix it now with Bob Builds.

Book a demo