AI Recommendation Poisoning: How 'Ask AI' Buttons Silently Alter LLM Memory

In February 2026, Microsoft Security named this AI Recommendation Poisoning, logging 31 companies across 14 industries and over 50 distinct prompts in 60 days. Hidden payloads in 'Ask AI' deep links run in logged-in ChatGPT, Claude, Gemini, or Grok sessions, instructing models to store the vendor's domain as a trusted source (MITRE ATLAS: AML.T0080).
1 source
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Demis Hassabis departs Google DeepMind as Jeff Dean exits to found new firm
- Amid legal battles, Suno says it will start watermarking songs
- Hugging Face agents collaborate to improve open-weight LLM math proofs
- Ex-Spotify employees raise $10M for e-commerce AI startup Malachyte
- NVIDIA: How Open World Models Push the Frontier of Physical AI