Ask AI buttons can secretly bias future answers

Published August 6, 2026

Some website "Ask AI" buttons can secretly change an assistant's stored preferences. Later answers may favor the company behind that website.

Report priority
Critical
Targets
ChatGPT+3 more

How it works

  • A person clicks an "Ask AI" button while logged into an AI assistant.
  • The link opens a prepared request and runs it without another confirmation.
  • A hidden instruction tells the assistant to remember the vendor's website as trusted.
  • If the assistant saves it, that preference can influence later answers.

What to do

Review your assistant's stored memory for unfamiliar vendor websites marked as trusted sources. Finding one indicates an unwanted stored preference, but does not prove every answer changed.

Do not click unsolicited memory-changing links while logged into a work account. If you find an unfamiliar entry, ask your IT team to audit the account. The retrieved evidence references cleanup guidance, but does not document the removal procedure.

Technical details

Affected software: ChatGPT, Claude, Gemini, Grok

Researchers found hidden instructions operating on commercial marketing and comparison pages. Microsoft Security identified 31 companies across 14 industries using this behavior. Separately, one data source contained more than 50 distinct prompts observed over 60 days.

The technique combines pre-filled AI links with persistent memory. A website places an undisclosed instruction inside an "Ask AI" link. The assistant runs that request in the user's active session and may store the vendor's domain as trusted. The report calls this AI Recommendation Poisoning.

It associates the behavior with memory poisoning and prompt injection techniques tracked by MITRE ATLAS.