Answer poisoning is the deliberate planting of false or manipulated content into the web sources an AI engine retrieves, so that the model repeats the falsehood in its synthesised answer. It targets the retrieval corpus — the pages an engine gathers to build an answer — rather than the model itself, and it works because answer engines lean on agreement across sources far more than they verify any single claim. Seed enough independent-looking sources saying the same false thing and a model can adopt it, sometimes even against an official denial on the affected brand's own site.
It is distinct from neighbouring terms. Prompt injection smuggles hidden instructions into a model's input; astroturfing fakes grassroots praise for yourself; a citation hallucination is an honest model error with no attacker. Answer poisoning is adversarial and corpus-level: real (false) sources, an honest engine, a corrupted answer.
For brands it matters because a single first-party correction is often outweighed by the poisoned sources — most AI mentions of an established brand come from third parties. The durable defence is the same signal that earns citations: corroboration from independent, credible earned media, plus correcting the false content at its source so it drops out as the cited pool churns.