Field note

Can AI search be manipulated? What the 'gullibility' tests reveal for brands

An informal experiment seeded AI engines with made-up rankings. Some repeated them; some refused. The result isn't a manipulation playbook. It's the case for why corroboration, not clever content, is what earns durable AI visibility.

Buffy Editorial2026-06-12 · 3 min read

Can you trick an AI engine into repeating something untrue about a market, or a brand? An informal 2026 experiment says: sometimes, for a while. The more useful lesson is why it doesn't last, and what that tells brands about earning durable visibility.

What the experiment found

SEO practitioner Lily Ray ran an informal test in 2026: she invented absurd, never-before-searched questions. Like which SEO is "best at eating spaghetti". Published satirical rankings, and watched which engines repeated them. The reported pattern:

  • Google's AI Overviews, Gemini, and AI Mode stated the made-up answers, but flagged the source as "informal," "playful," or "lighthearted."
  • Claude and Perplexity were less likely to use the brand-new article, apparently because the questions were highly specific and lacked any consensus across sources.

It's a single, informal experiment on questions engineered to have no real answer, and engine behaviour shifts constantly, so treat it as directional. But the mechanism it exposes is the durable part.

Why the manipulation doesn't hold

The made-up rankings worked, where they worked, only because nobody else had answered the question. In a vacuum, an engine has one source to draw on, so it draws on that one. The moment a question has real coverage, that fragile advantage disappears.

A claim with no corroboration can fill an empty space, but it can't survive contact with other sources. The engines that refused the bait were the ones waiting for consensus, not a single confident voice.

This is the same retrieval filter behind why AI cites one brand and ignores a near-identical competitor: models weight corroboration across credible sources heavily, precisely because a lone assertion is easy to fake and hard to trust. Manipulation exploits the gaps; corroboration closes them.

What this means for your brand

The takeaway isn't "go seed claims about yourself", that's the fragile move the experiment exposes. It's that the thing protecting you from manipulation is the same thing that earns you citations: being corroborated.

If your goal is… The losing move The durable move
Get recommended Publish self-serving claims and hope Earn agreement from independent sources
Defend your reputation React to each bad mention Build entity strength so one voice can't overwrite consensus
Fix a wrong description Restate it on your own site only Get credible third parties to state it too

If an engine is repeating something wrong about you, the fix isn't to shout louder on your own pages. It's corroboration. (We cover the mechanics in what to do when AI gets your brand wrong.) And if a competitor is being described too generously on the strength of thin claims, that advantage is the unstable kind; the brand with broad, consistent third-party agreement wins over time.

The practical defense

  • Be consistent everywhere. State the same facts about yourself across your site, profiles, and listings. Engines lock onto consistent entities.
  • Earn corroboration. Reviews, independent roundups, and credible mentions that agree with your own claims are what survive scrutiny. How to get cited is mostly this.
  • Monitor across engines. Manipulation and errors both show up as something wrong in an answer. You can only correct what you can see.

The honest conclusion: AI search can be nudged in the gaps, but it can't be durably gamed where corroboration exists, so the winning strategy is to be the corroborated answer. Seeing what every engine currently says about your brand, and catching it when it drifts, is exactly what Buffy Intel monitors.

Frequently asked

Which AI engines were most likely to repeat unverified claims?

In an informal 2026 experiment by SEO practitioner Lily Ray, Google's AI Overviews, Gemini, and AI Mode repeated fabricated 'best at' rankings she'd published, though they flagged the source as informal or playful. Claude and Perplexity were less likely to use the brand-new, low-consensus article. It's one small test, and engine behaviour changes, so read it as directional, not a ranking of trustworthiness.

Can I just publish claims about my brand and get AI to repeat them?

Sometimes, briefly, for obscure questions nobody else has answered, a single source can fill the vacuum. But that advantage is fragile: more cautious engines require consensus across sources, and a lone, self-serving claim gets discounted or corrected the moment other sources disagree. You can't fabricate your way to durable AI visibility.

What actually protects a brand's AI visibility from manipulation?

Corroboration. When multiple independent, credible sources agree on what you do and how good you are, no single bad actor, and no single satirical post. Can easily overwrite it. The defensive and offensive move is the same: build entity strength and earn consistent third-party mentions so your story is the one the engines keep seeing.