Black-hat operators are making a claim that sounds like science fiction: that they can make AI search say whatever they want. Poison the answer. Hijack the attribution. Erase a person or a brand from results entirely.
Some of that is real and documented. Some of it is bravado. The useful skill — for anyone whose revenue depends on what an AI says about them — is telling the two apart. This post does that, then gives you the defence.
To be clear about what this is: it’s the defensive side. No tutorials, no tooling. What’s actually happening in AI search manipulation, which claims hold up under scrutiny, and how a brand protects itself across ChatGPT, Perplexity, Gemini, Claude, and Google’s AI answers.
The short version: AI search is gameable right now, and the research proves the barrier is low. The headline case — the Pravda network “grooming” chatbots — is real but overstated, and a Harvard study reframes the mechanism as data voids rather than mind control. A brand faces five distinct threats: narrative poisoning, attribution hijacking, crawler cloaking, entity suppression, and impersonation. The “white hat is a scam” pitch collapses once you count detection, recoverability, and legal exposure. The defense is four parts: monitor your entity, own the authoritative answer, watch for process abuse, and have a response path before you need one.
This is real, and it’s not magic

Start by deflating the mystique, because the mystique is doing work for the people selling this.
AI search engines are retrieval systems. Most of them go and read the web — some on every query, some on a fraction — pull a handful of sources, and synthesise an answer with a level of confidence that reads as authority. They are, at bottom, deciding which web pages to believe. And a system that decides which pages to believe can be fed pages designed to be believed.
That’s not a hack. That’s the ordinary weakness of any retrieval system, and it’s the same weakness classic search spent twenty years hardening against. The difference is that AI search is early, its trust signals are still crude, and — critically — its answers feel more authoritative than a list of ten links. Users don’t see a ranking they can evaluate. They see a confident answer. That asymmetry is exactly what an attacker exploits.
Why AI search is gameable right now
This isn’t opinion. The research is unusually direct about it.
A 2024 paper by Kumar and Lakkaraju demonstrated that large language models could be manipulated to increase a specific product’s visibility in their recommendations through content designed for the model rather than the reader. The KDD 2024 paper that coined “generative engine optimisation” (Aggarwal et al.) showed that relatively simple content changes can materially increase how often a source is cited. And a June 2026 position paper on GEO governance argued the field carries under-examined risks precisely because the barrier to influencing AI answers is low and the accountability is thin.
The pattern across all of it: AI retrieval currently lacks the provenance validation and cross-referencing that would catch a planted source. When an engine retrieves a page, it tends to treat that page as ground truth. No human verifies it. No warning flags it. If the content is shaped to be extracted and quoted, it gets extracted and quoted — whether it’s true or not.
That’s the vulnerability. Now the case everyone cites.
The Pravda case: substantiated vs theatrical
If you’ve read anything about AI search poisoning, you’ve seen this one. It deserves both halves of the story, because most coverage only gives you the alarming half.
What’s substantiated. The Pravda network is a Moscow-linked disinformation operation — part of the broader “Portal Kombat” network identified by France’s VIGINUM — running somewhere between 150 and 180 domains across dozens of countries, publishing at industrial scale (around 3.6 million articles in 2024). In March 2025, NewsGuard audited ten leading AI chatbots and found they repeated narratives laundered through the Pravda network roughly 33% of the time, and that seven of the ten cited Pravda sites directly as sources. The operation’s own propagandists have openly described the goal as shaping “worldwide AI.” The network is real, the volume is real, and the fact that chatbots have surfaced its content is documented.
The counter-finding that keeps it honest. A study published in the Harvard Kennedy School’s Misinformation Review — titled, pointedly, “LLMs grooming or data voids?” — tested the same thesis with a broader prompt set and found something quite different. On their prompts, chatbots produced false claims only around 5% of the time, not 33%. Just 8% of outputs referenced Pravda sites at all — and most of those did so to debunk the content. And crucially, the Pravda references clustered in queries with thin mainstream coverage. The researchers also noted that NewsGuard’s design skewed the result: two-thirds of its prompts were explicitly crafted to provoke falsehoods, and responses that merely urged caution were counted as disinformation.
The Harvard conclusion is the one to carry with you: the outputs look less like successful “grooming” and more like a symptom of data voids — topics where reputable information is scarce, so the engine reaches for whatever exists.
Why does this matter for your brand? Because it reframes the threat from something mystical into something you can act on. AI systems aren’t being hypnotised. They’re filling gaps. If the authoritative answer about you doesn’t exist, the engine will use whatever does — and an attacker’s job is simply to make sure something does. That’s the whole game, and it points directly at the defence.
The threat map: five ways a brand gets hit
Stripped of the theatre, AI search attacks on a brand fall into five patterns. Recognise them and you can catch them early.
1. Narrative poisoning. Seeding a false or damaging story about a brand across enough sources that engines retrieve and repeat it — the Pravda pattern, pointed at a company. In a regulated space like iGaming or finance, a fabricated licensing problem or a planted “scam” narrative repeated by an AI answer does damage before anyone can respond.
2. Attribution hijacking. Making an engine credit someone else — a competitor, a clone, an impostor — for your content, your expertise, or your brand’s positioning. The citation goes to the wrong source; the trust flows to the wrong entity.
3. Crawler cloaking. This one is documented, not theoretical. In October 2025, researchers at SPLX demonstrated “agent-aware cloaking” against ChatGPT’s Atlas browser, Perplexity, and Claude: a site serves ordinary content to human visitors and a different, manipulated version to AI crawlers, which then cite the manipulated version as fact. Their tests reshaped AI-generated product recommendations and even hiring rankings. The unsettling part is how cheap it is — it requires no exploitation, only serving different content depending on who’s asking. It’s the classic cloaking violation from our post on black hat techniques to stop using, reborn for the AI layer.
4. Entity suppression. The inverse of visibility: pushing a brand or a person out of AI answers, by crowding the relevant queries with alternative sources until the engine simply stops retrieving you. The “erase people from results” claim lives here — and it’s the one with the most bravado attached, because reliably suppressing an established entity across five engines is far harder than the operators selling it imply.
5. Impersonation. Fake sites, fake profiles, cloned brand pages built to be retrieved as you. In classic search this was a phishing and trademark problem. In AI search it’s an answer-integrity problem: the engine cites the impostor, and the user never sees a URL to question.
Notice the pattern. Three of the five (narrative poisoning, entity suppression, impersonation) are the AI-layer versions of attacks we’ve long defended against in classic search — we covered the classic-search side in how competitors attack your rankings from the outside. The playbook is old. The surface is new.
Why “white hat is a scam” is the wrong frame
There’s a pitch circulating alongside these techniques, and it goes roughly: the engines are gameable, everyone’s gaming them, playing clean is naive. It’s persuasive if you don’t count all the columns.
Count them. Any tactic has to be evaluated on detection, recoverability, and legal exposure, not just on whether it works today.
- Detection is rising fast. The same research that exposed agent-aware cloaking proposed the countermeasures — anti-cloaking crawlers, cross-referencing, provenance checks — and the engines are motivated to ship them, because manipulated answers destroy the product. What works this quarter is being engineered against next quarter.
- Recoverability is worse than in classic search. In Google, a penalty is a state you can exit. In AI search, a poisoned narrative persists in citations, in cached answers, and potentially in training data. There’s no reconsideration request for a model.
- Legal exposure is real. Narrative poisoning is defamation with extra steps. Impersonation is trademark and fraud. Cloaking in a regulated vertical is a compliance problem. The “clever tactic” and the “cause of action” are frequently the same act.
The honest frame is the one we apply to every technique across the spectrum: it’s a risk-and-recoverability scale, not a moral one. We’ve operated across the full spectrum and we’ll always give you the straight risk maths. Here, once you add detection, recoverability, and legal exposure to “does it work,” the maths on the offensive side goes sharply negative — and the maths on the defensive side is the best it’s been, because the attacks are loud, cheap, and increasingly traceable.
The four-part defence
Everything above resolves into four things. They’re not glamorous, and they work.
1. Monitor your entity
You cannot defend an answer you never look at. Build the habit: take your top 20 category questions — including the ones an attacker would want to poison (“is [brand] legit,” “[brand] scam,” “[brand] licence”) — and run them through ChatGPT, Perplexity, Gemini, Claude, and Google’s AI answers. Note what each says, and which source domains it cites. Then repeat monthly, because as this year has shown, the map moves in weeks. A planted narrative or an impostor site shows up first in the sources an engine cites — long before it shows up in your revenue.
2. Own the authoritative answer
This is the direct counter to the data-void mechanism the Harvard study identified. If an engine fills gaps with whatever exists, the defence is to make sure the authoritative answer exists, is yours, and is easy to retrieve. Clear, specific, well-sourced reference pages that directly answer the questions people — and attackers — care about: who you are, what you’re licensed for, what you actually offer. Corroborate them off-site through editorial coverage, review platforms, and consistent entity signals. An engine that finds a strong, corroborated authoritative source has no void to fill. That’s the substance of a real content strategy, and it’s why we’ve written separately about where AI engines actually get their citations — the off-page half is most of the defence.
3. Watch for process abuse
Some attacks don’t target the engine directly — they abuse the processes around it. False takedown notices aimed at your authoritative pages. Impersonation accounts claiming your brand on the platforms engines read. Fake review campaigns on the platforms engines treat as validation. These are the AI-era versions of the false-DMCA and impersonation attacks we defend against in classic search, and they’re caught the same way: evidence preservation, timestamping, and monitoring the places an attacker has to touch. A structured site audit is where most brands first discover their entity has already been tampered with.
4. Have a response path before you need one
The brands that get hurt worst are the ones improvising on the day. Decide in advance: who monitors, who escalates, how you document (screenshots, timestamps, source URLs), and what your escalation routes are — platform abuse desks, engine feedback channels, registrars, and where warranted, legal counsel. A poisoned AI answer is a crisis with a paper-trail requirement; the paper trail has to already exist. This is the crisis-response layer of a full brand protection stack, and it’s the part that turns an attack from a disaster into an incident.
Watch the video
This post accompanies our full video breakdown of what’s real in AI search poisoning, the five-threat map, and the defense.
Where to go next
AI search is gameable, and the barrier is low — that part is documented. The dramatic version is overstated: the Pravda case is real but the mechanism is data voids, not mind control, which is good news, because a void is something you can fill. A brand faces five recognisable threats, and the defence against all of them is the same discipline: know what the engines say about you, make sure the authoritative answer exists and is yours, watch the processes an attacker has to abuse, and have your response ready.
That defensive work — across classic search and the AI layer — is core to what we do in brand protection, and it’s inseparable from the AI search visibility work that builds the authoritative answer in the first place. See how the two fit together across the GrowifyLabs solutions catalogue, or start at growifylabs.com.
Run your own brand’s “is it legit” questions through the five engines and find something you didn’t expect? That’s exactly the kind of result worth comparing notes on — and worth acting on quickly.
FAQ
Can AI search results really be manipulated?
Yes. AI search engines are retrieval systems that decide which web pages to trust, and research (Kumar & Lakkaraju 2024; Aggarwal et al., KDD 2024) shows that content designed for the model rather than the reader can increase how often a source is cited. AI retrieval currently lacks strong provenance validation, so a planted source can be quoted as fact. The barrier is low, which is why monitoring matters.
What is LLM grooming, and is the Pravda network really poisoning AI?
“LLM grooming” describes flooding the web with content intended to shape what AI models learn and cite. The Pravda network — a Moscow-linked operation running ~150–180 domains — is the headline case: a March 2025 NewsGuard audit found ten leading chatbots repeated its narratives about 33% of the time. But a Harvard Kennedy School Misinformation Review study found false claims only ~5% of the time on broader prompts and concluded the effect reflects data voids — topics with scarce reputable coverage — rather than successful grooming.
What is agent-aware cloaking?
A documented technique, demonstrated by SPLX researchers in October 2025, in which a website serves ordinary content to human visitors but a different, manipulated version to AI crawlers such as ChatGPT Atlas, Perplexity, and Claude — which then cite the manipulated version as fact. It’s the classic cloaking violation adapted to the AI layer, and it’s notable for requiring no technical exploitation.
How do I protect my brand from AI search manipulation?
Four parts: monitor your entity by regularly running your key questions through the major engines and noting which sources they cite; own the authoritative answer with clear, corroborated reference content so engines have no void to fill; watch for process abuse such as false takedowns, impersonation, and fake reviews; and have a documented response path — monitoring, evidence, escalation routes — ready before an incident.
Is “white hat is a scam” a fair take on AI search?
No. It ignores three columns: detection (countermeasures to techniques like agent-aware cloaking are already being built), recoverability (a poisoned narrative can persist in citations and training data with no “reconsideration request” to exit it), and legal exposure (narrative poisoning, impersonation, and cloaking map onto defamation, trademark, and compliance liability). Counted fully, the risk-adjusted return on offensive manipulation is sharply negative.