Here is the part that makes AI SEO feel like the wild early days of SEO again: the same mechanisms that let you earn a mention also let people fake one. I am describing these so you recognise them, not so you run them, because they are short-lived and increasingly treated as attacks.
The dark side: how people poison AI answers with thirteen words, and why it is a trap you should watch but not touch
Here is the part that makes this whole field feel like the wild early days of SEO again, because the same mechanisms that let you earn a mention also let people fake one. I am describing these so you recognise them, not so you run them: they are short-lived and increasingly treated as attacks. They also matter more now that you know how heavily both ChatGPT and Google's AI lean on Reddit.
- Thirteen words can steer an answer. Cornell researchers showed that a planted snippet as short as thirteen words on a user-generated site like Reddit, Wikipedia or Quora can push AI research agents to recommend fabricated products, with success rates reaching as high as 100% in controlled tests. Alarmingly, the agents treated a random Reddit comment as about as credible as a government website.
- Agencies are already seeding Reddit for money. At least one firm reported that its planted Reddit posts showed up in ChatGPT answers sometimes within a day, and that it continuously replaces posts that get removed. This is a live, paid industry, not a thought experiment.
- Hidden instruction injection is happening at scale. Microsoft's security team caught more than fifty attempts in sixty days to embed hidden instructions, in links, buttons, documents, so that an assistant would later recommend a particular vendor, with one tool literally marketed as an “SEO growth hack for LLMs”.
- Then there are content farms and cloaking. Using an LLM to mass-produce thousands of keyword-stuffed pages, or serving AI crawlers a different, keyword-loaded version of a page than humans see, are the AI-era descendants of old black-hat SEO.
Why I would not build on any of it:
- The platforms are hunting it. Reddit now runs automated detection that flags around 25,000 spammy posts a day and blocks tens of millions of spam views daily. The planted-snippet half-life is shrinking.
- It is increasingly classed as an attack, not marketing. Hiding instructions to manipulate an assistant is a security exploit, the kind of thing that gets tooling banned and domains penalised, not a growth channel.
- The effect is real but fragile. Even the research that proves these attacks work notes that production AI search resists the large majority of naive attempts, and behaviour shifts with every model update. You would be renting a result you do not own.
The useful takeaway from the dark side is defensive and strategic, not a licence to imitate it: it confirms that mentions on trusted community sites are unusually powerful, so the legitimate version, genuinely earning them, is exactly where your effort should go.