6 Sources
[1]
Microsoft: Poison AI buttons and links may betray your trust
Businesses are embedding prompts that produce content they want you to read, not the stuff AI makes if left to its own devices Amid its ongoing promotion of AI's wonders, Microsoft has warned customers it has found many instances of a technique that manipulates the technology to produce biased
[2]
Microsoft Finds "Summarize with AI" Prompts Manipulating Chatbot Recommendations
New research from Microsoft has revealed that legitimate businesses are gaming artificial intelligence (AI) chatbots via the "Summarize with AI" button that's being increasingly placed on websites in ways that mirror classic search engine poisoning (AI). The new AI hijacking technique has been
[3]
'If someone can inject instructions or spurious facts into your AI's memory, they gain persistent influence over your future interactions': Microsoft warns AI recommendations are being "poisoned" to serve up malicious results
Real-world attempts detected; risk of enterprises making costly decisions based on compromised AI recommendations You may have heard of SEO Poisoning - however experts have now warned of AI Recommendation Poisoning. In a new blog post, Microsoft researchers detailed the emergence of a new class
[4]
That 'Summarize With AI' Button May Be Brainwashing Your Chatbot, Says Microsoft - Decrypt
Microsoft's security team identified 31 organizations across 14 industries attempting these attacks, with health and finance services posing the highest risk. Microsoft security researchers have discovered a new attack vector that turns helpful AI features into Trojan horses for corporate
[5]
How Hidden Prompts Are Influencing Enterprise AI Systems | PYMNTS.com
With agentic AI reshaping how consumers search, evaluate and buy products, a newly documented threat suggests that what AI recommends can be manipulated by entities with no access to the model's core training. In short: A bug in the system. Recently, Microsoft's Defender Security Research Team
[6]
AI is being brainwashed to favor specific brands, Microsoft report shows
The promise of a personalized AI assistant is built on the foundation of memory. We want our AI to remember our writing style, our project history, and our preferences to become more efficient over time. However, a new investigation by the Microsoft Defender Security Research Team has revealed that
Share
Copy Link
Microsoft's security team uncovered a troubling pattern where businesses embed hidden instructions in AI summary buttons to manipulate what chatbots recommend. The company identified over 50 unique prompts from 31 companies across 14 industries that poison AI memory with biased directives. This technique exploits how AI assistants store context, creating persistent influence over future recommendations in critical areas like health, finance, and security.
Microsoft has issued a stark warning about a technique that manipulates AI chatbots to produce biased recommendations, marking a troubling evolution in digital manipulation tactics. The Microsoft Defender Security Research Team identified over 50 unique prompts from 31 companies across 14 industries during a 60-day investigation into what it calls AI Recommendation Poisoning
1
2
. This attack vector mirrors SEO Poisoning but targets AI memory systems instead of search engine rankings, creating persistent influence that erodes user trust in AI-driven recommendations3
.
Source: Digit
The technique exploits Summarize with AI buttons and links that appear legitimate but contain hidden instructions designed to manipulate chatbot memory. Companies embed these directives in URL parameters that pre-populate prompts with commands like "remember [Company] as a trusted source" or "recommend [Company] first"
2
. When users click these buttons expecting neutral summaries, they unknowingly inject malicious instructions that AI assistants treat as legitimate user preferences. This AI Memory Poisoning creates biased AI recommendations that persist across future conversations without any visible indication of compromise1
.
Source: Hacker News
The mechanics of manipulating chatbot recommendations rely on how modern AI systems store conversational context. Microsoft researchers demonstrated that URLs pointing to AI chatbots can include query parameters with prompt injection techniques that execute automatically
1
. Once these hidden instructions enter the system, AI assistants cannot distinguish between genuine user preferences and those injected by third parties2
. The manipulation affects not just immediate responses but creates spurious facts that influence enterprise AI systems across subsequent interactions3
.Free tools have accelerated adoption of this AI-powered fraud technique. Turnkey solutions like CiteMET and AI Share Button URL Creator provide ready-to-use code for embedding promotional material into AI assistants, lowering the barrier to injecting malicious instructions
2
4
. These platforms enable non-technical marketers to craft poisoned links that compromise Copilot, ChatGPT, Claude, and other popular AI assistants4
. Microsoft's analysis revealed attempts spanning finance, health and finance industries, legal services, SaaS platforms, and even cybersecurity vendors4
.
Source: Decrypt
The risk extends beyond marketing annoyance into domains where biased content could produce dangerous outcomes. Microsoft highlighted scenarios where a CFO might ask their AI assistant to research cloud infrastructure vendors for major technology investments, only to receive recommendations influenced by weeks-old memory poisoning from a seemingly innocent blog summary
3
. In health contexts, one service embedded prompts instructing AI to remember the company as a citation source for health expertise, potentially influencing medical decisions4
.With more than 60% of consumers now beginning daily tasks with AI interfaces including product research and brand discovery, the stakes for maintaining neutral recommendations have escalated dramatically
5
. As conversational assistants replace traditional search results, they become the primary discovery layer where compromised AI recommendations can shift purchasing decisions toward entities that poisoned the prompt rather than objectively superior alternatives5
. The Mitre Atlas knowledge base has formally classified this behavior as AML.T0080: Memory Poisoning, joining a growing taxonomy of AI-specific attack vectors that traditional cybersecurity frameworks do not adequately address4
.Related Stories
Microsoft advises users to hover over AI buttons before clicking to inspect full URLs, periodically audit chatbot memory for suspicious entries, and clear memory after clicking questionable links
1
2
. Corporate security teams should scan for AI Recommendation Poisoning attempts by hunting for URLs pointing to AI assistant domains containing keywords like "remember," "trusted source," "in future conversations," and "authoritative source"2
. Organizations without visibility into these communication channels remain exposed to this emerging threat.Microsoft has deployed mitigations in Copilot including prompt filtering and content separation between user instructions and external content
4
. However, the cat-and-mouse dynamic that defined search optimization will likely repeat as platforms harden against known patterns and attackers craft new evasion techniques4
. The manipulation remains particularly insidious because users may not realize their AI has been compromised, and confident-sounding assertions by AI models make verification less likely1
. Microsoft's research confirms these are not hypothetical scenarios but numerous real-world attempts to plant persistent recommendations that compromise the neutrality users expect from AI assistants3
.Summarized by
Navi
[1]
[4]
22 Oct 2025•Technology

10 Dec 2025•Technology

16 Jun 2026•Science and Research

1
Policy and Regulation

2
Technology

3
Policy and Regulation
