Here is the part that makes AI SEO feel like the wild early days of SEO again: the same mechanisms that let you earn a mention also let people fake one. I am describing these so you recognise them, not so you run them, because they are short-lived and increasingly treated as attacks.
Thirteen words can poison an AI answer, and it is still a trap
Here is the part that makes this whole field feel like the wild early days of SEO again, because the same mechanisms that let you earn a mention also let people fake one. I am describing these so you recognise them, not so you run them: they are short-lived and increasingly treated as attacks. They also matter more now that you know how heavily both ChatGPT and Google's AI lean on Reddit.
- Cornell showed a planted snippet of thirteen words can steer an AI answer. Cornell researchers showed that a planted snippet as short as thirteen words on a user-generated site like Reddit, Wikipedia or Quora can push AI research agents to recommend fabricated products, with success rates reaching as high as 100% in controlled tests. Alarmingly, the agents treated a random Reddit comment as about as credible as a government website.
- Agencies are already seeding Reddit for money. At least one firm reported that its planted Reddit posts showed up in ChatGPT answers sometimes within a day, and that it continuously replaces posts that get removed. This is a live, paid industry, not a thought experiment.
- Hidden instruction injection is happening at scale. Microsoft's security team caught more than fifty attempts in sixty days to embed hidden instructions, in links, buttons, documents, so that an assistant would later recommend a particular vendor, with one tool literally marketed as an “SEO growth hack for LLMs”.
- Content farms and cloaking are the mass-produced version of the same attack. Using an LLM to mass-produce thousands of keyword-stuffed pages, or serving AI crawlers a different, keyword-loaded version of a page than humans see, are the AI-era descendants of old black-hat SEO.
Why I would not build on any of it:
- The platforms are hunting it. Reddit now runs automated detection that flags around 25,000 spammy posts a day and blocks tens of millions of spam views daily. The planted-snippet half-life is shrinking.
- Hiding instructions to manipulate an assistant is classed as a security exploit. Hiding instructions to manipulate an assistant is a security exploit, the kind of thing that gets tooling banned and domains penalised, not a growth channel.
- AI-answer manipulation works in the lab and is being patched in production. Even the research that proves these attacks work notes that production AI search resists the large majority of naive attempts, and behaviour shifts with every model update. You would be renting a result you do not own.
The useful takeaway from the dark side is defensive and strategic, not a licence to imitate it: it confirms that mentions on trusted community sites are unusually powerful, so the legitimate version, genuinely earning them, is exactly where your effort should go.
Use Camera to Clipboard to post a real photo of your product
Every technique in this article is a way of manufacturing evidence that a product exists and works, and every one of them is short-lived because the platforms now treat it as an attack. The durable version is dull by comparison: photograph the product doing the thing, and publish the picture under your own name. Camera to Clipboard, one of my own apps, is what I use for the awkward part, because the photo is always on a phone and the post is always being written on a computer.
- A photo you take inside Camera to Clipboard is sitting on your computer's clipboard by the time you put the phone down. There is no emailing it to yourself, no cable and no upload to a third party in between. The phone and the computer find each other over your own local network and send the picture directly.
- Pasting into Photoshop or GIMP arrives as a new layer or a new document, and Word and Google Docs take it inline. It arrives as an ordinary clipboard image, so anything that accepts a pasted picture accepts this one and nothing has to be saved, named or found again.
- A planted post has to be replaced as fast as it is removed, and a photograph of your own product working needs no maintenance at all. You can send several shots from the phone's library in one go, so a whole sequence of the product doing something arrives together and the post shows the thing instead of asserting it.
Conclusion: why gaming AI answers works but never lasts
- Gaming an AI answer means planting a short snippet on Reddit, Wikipedia or Quora, or hiding instructions inside a page, so an assistant later repeats a claim you wrote yourself. Content farms and cloaking are the mass-produced version of the same idea, and Microsoft's security team caught more than fifty hidden-instruction attempts in sixty days.
- Cornell researchers steered AI research agents with a planted snippet of only thirteen words, reaching as high as 100% success in controlled tests. The agents treated a random Reddit comment as about as credible as a government website, which is why a handful of planted sentences can move an answer at all.
- Earn your mentions on community sites instead of planting them, because Reddit's automated detection flags around 25,000 spammy posts a day and a removed post has to be replaced again and again. The one lasting lesson from all of these tricks is that a mention on a trusted community site is unusually powerful, so spend the effort on getting a real one.