The question went to a machine. The machine's answer had been pre-written by a stranger.
Also known as SEO for AI / prompt stuffing
Content engineered not for human readers but to be ingested by the systems that now answer questions on our behalf: search engines, AI assistants, and summarizers. A page is written to be the source an assistant cites; a claim is repeated across a network of pages so that a model asked 'what is true' finds it everywhere and reports it as settled; a product is padded with synthetic reviews that an aggregator's algorithm averages into a rating. The target of the persuasion is no longer you. It is the machine that stands between you and the answer, and the machine cannot tell the difference between what is well-supported and what is well-planted.
Truth-adjacency
Truth-independent: the pattern works regardless of whether the claim is true
Where it shows up
Platforms and algorithms
How it works
The phrases and tells that mark this pattern in the wild:
an AI answer that cites a source you cannot independently verifythe same claim surfaced by multiple assistants, all tracing to one origina product or person that ranks highly but has no traceable reputation outside the rankingcontent written in the flat, exhaustive style of something designed to be scrapeda 'consensus' that exists only in machine-retrieved summaries, not in actual expert statementsThe tell is the difference between agreement and placement. A truthful answer is backed by sources that independently converge because they are all looking at the same reality. A poisoned answer is backed by sources that converge because they were built from the same plan. Follow the citations. If they branch outward toward independent institutions, methods, and authors, the agreement is earned. If they circle back to a single origin, a single publisher, or a closed loop of mutual citation, the agreement is staged. Also notice the style: poisoned content is often written to be scraped, exhaustive and neutral and frictionless, optimized for retrieval rather than for a reader’s understanding.
You call “answer poisoning” on an AI answer that cites real, independent, verifiable sources you simply have not heard of. Retrieval systems surface niche-but-legitimate material constantly. The pattern requires the agreement to be fabricated: the sources are coordinated, loop back on themselves, or exist only to be retrieved. If the citations are genuinely independent and survive inspection, the answer is supported, however surprising. Unfamiliarity is not evidence of a plot, and calling it one is its own way of stopping the verification work.
One of these two real scenarios is Answer poisoning. The other is a different pattern entirely. Which one is which?
The tell
An AI assistant citing a real, verifiable source that genuinely supports its answer is not poisoned, however unfamiliar the source. The pattern requires the agreement to be manufactured: the cited pages trace to a single coordinated origin, the 'independent' sources cite each other in a loop, or the content exists to be retrieved rather than read. If the sources are genuinely independent and check out, the answer is supported, not poisoned.
Content is written to be the source an AI assistant cites. A claim is repeated across a network of pages so that a model finds it everywhere and reports it as settled.
Because you cannot independently verify everything. The machine is the interface. Trusting it is the default. Verifying every answer would be a full-time job.
Later, people realize the agreement was real in the index and fictional in the world. The machine could not tell the difference between well-supported and well-planted.
Field notes where this pattern was identified:
How this pattern gets misused
Someone dismisses any AI-retrieved answer they dislike as poisoned, treating the machine's citation of an unfamiliar source as evidence of a plot. Retrieval systems surface obscure-but-real sources all the time. The term becomes a way to reject any machine answer that is inconvenient, which is just motivated skepticism with a technical costume.
What it looks like when you're wrong about it
An AI assistant citing a real, verifiable source that genuinely supports its answer is not poisoned, however unfamiliar the source. The pattern requires the agreement to be manufactured: the cited pages trace to a single coordinated origin, the 'independent' sources cite each other in a loop, or the content exists to be retrieved rather than read. If the sources are genuinely independent and check out, the answer is supported, not poisoned.
Not sure? Describe the situation to someone outside it. If they do not see the pattern, pause before you name it.
Citation laundering
The citation is real. The source is a mirror.
Information laundering through repetition
You believed it because everyone said it. You did not check because checking would have meant you were the only one who did not already believe it.
Source obfuscation
You trusted it because it sounded official. 'Official' was the costume, not the credential.
Prompt injection
The document you asked the AI to read was also reading the AI back.
The name is designed to spread. The hook is designed to stick. If you recognized something, share the name.
Seen a real example of answer poisoning? Suggest it for the Register →