Search & AI poisoning

AI Answer-Engine Poisoning

ChatGPT, Gemini, Perplexity and Claude start summarizing the damaging narrative as the dominant answer about you.

Speed to damage
Weeks to months
Typical targets
Founders, executives, public companies, public figures, and political organizations.
Typical attackers
Sophisticated operators — dark PR firms, activist shorts, politically motivated groups — with the budget to sustain index flooding.
What this attack is

Summary

AI answer-engine poisoning engineers the information environment so that generative models — ChatGPT, Google AI Overviews, Gemini, Perplexity, Claude, Copilot — retrieve and synthesize the damaging narrative as the dominant answer to queries about you. Because model outputs are treated as authoritative and cited without source links, a successful poisoning converts a temporary news cycle into a permanent, repeated answer that compounds every time someone asks. This is the fastest-growing category of negative PR.

The mechanics

How the attack works

  1. Operators flood the crawl-and-index layer with a consistent negative narrative across many sources.
  2. The narrative is repeated in new packaging — articles, Reddit threads, AI-generated posts — so it dominates retrieval.
  3. Models trained on and retrieving from the open web begin surfacing the damaging synthesis as the answer.
  4. The AI answer is then quoted in posts and articles, which are re-ingested, reinforcing the narrative in the corpus.
  5. Because answers regenerate on each query and across engines, the damage is persistent and self-reinforcing.
Detection

Tell-tale signs you're under this attack

  • ChatGPT, Gemini, Perplexity or Claude returns predominantly negative summaries about you
  • Google AI Overviews begins surfacing the damaging narrative for your name or brand
  • The same narrow claim recurs across multiple engines
  • Answers cite the same small set of negative sources
  • Answers persist or worsen even after the original news cycle fades
Channels used
ChatGPTGoogle AI OverviewsGeminiPerplexityClaudeMicrosoft Copilot
First 72 hours

First-line defense

Audit what every major model actually says about you across ChatGPT, Gemini, Perplexity, Claude, and Google AI Overviews, capture the answers and cited sources, and begin correcting the index with retrievable factual counter-content — fighting individual answers is not durable; correcting the index is.

Counter-strategy

The defense playbook

  1. 1

    Run a baseline audit across all major engines and capture answers, sources, and citations for each.

  2. 2

    Identify the seed sources each engine retrieves and prioritize correcting or deindexing them.

  3. 3

    Publish structured, factual counter-content that models are likely to retrieve (authoritative domains, clear corrections).

  4. 4

    Deindex demonstrably false or defamatory source URLs through publisher, platform, and legal channels.

  5. 5

    Monitor model answers continuously — models retrain and re-retrieve, so drift returns and must be caught early.

  6. 6

    Escalate platform policy violations for synthetic media and coordinated inauthentic behavior feeding the synthesis.

Lawful levers

Legal & platform options

  • Defamation action against publishers of fabricated statements feeding the synthesis
  • Right-to-be-forgotten delisting for outdated personal data
  • Platform policy enforcement against synthetic media and coordinated amplification
  • Source corrections and right-of-reply to publishers whose content drives the answers
Recovery

Recovery outlook

Slower than classic SEO (8–16 weeks) because models re-retrieve on their own schedules, but durable once the index is corrected and monitored. A defense built only for Google leaves half the problem untouched.

Facing this pattern right now?

Speed in the first 72 hours is the single biggest determinant of outcome. We triage, attribute, and deploy the matching playbook — confidentially.

Message us