Launching soon. Preferium for agencies is in private preview — partner registration isn’t open yet. Join the waitlist →

All articles

Reddit is being seeded to steer AI answers, and Google says it plays no favourites

The Verge documented product plugs inside skincare subreddits written for AI assistants to pick up. Google said on August 5 that Reddit gets no special preference. Cornell Tech has measured 13 words moving an answer.

A hand works a puppet bar with strings tied to small orange figures planted in soil, while a large camera lens shines a beam across the seedlings.

TL;DR: When you ask ChatGPT or Google a question, it usually does not answer from memory. It runs a few web searches first, reads what comes back, and writes an answer out of that. Some marketers worked out that if you post the right sentence in a busy Reddit thread, your product ends up inside those answers. The Verge documented one such campaign on August 4, in skincare communities. Google replied a day later that Reddit gets no special treatment in its rankings or its AI features. The uncomfortable part is that researchers at Cornell Tech had already measured the trick working, and it needs about 13 words.

First, what does “seeding” actually mean here?

An AI assistant answering a shopping question is doing something fairly mechanical. It turns your question into ordinary search phrases, fetches a handful of pages, and summarises them. The pages it fetches are called the retrieved sources. Whatever is in them is most of what shapes the answer.

That means you can influence the answer without ever touching the assistant. You only have to be in one of the pages it fetches.

Forum threads are unusually good targets. They rank well for the messy, comparison-shaped questions people ask assistants (“gentlest hypochlorous acid spray for eczema”), and anybody can add a comment to one. Planting that comment so an AI picks it up later is what people mean by seeding. Some of the industry files it under answer engine optimisation, or AEO, which is the general practice of getting cited by AI assistants rather than ranked in a list of links. Seeding is the disreputable end of it.

What The Verge found

The Verge published a report on August 4 looking at whether Reddit can hold back a wave of promotional posting aimed at AI systems. The example that ran through it, as summarised by PPC Land, was an account dropping unprompted product specifications for a hypochlorous acid spray across several unrelated skincare threads: the concentration, the eczema-association acceptance, the sort of detail nobody volunteers in a conversation about dry skin.

As a Reddit comment it reads as strange. As a snippet for a machine to retrieve and repeat, it is well made.

Google’s answer

Google’s Jennifer Kutz told The Verge that Reddit “gets no special preference” in Google’s ranking system, and that its AI features do not set out to show content from any particular site or platform. Search Engine Roundtable carried the statement on August 5. On spam generally, Kutz said there will always be bad actors trying to game the system and that fighting spam is a core competence.

Worth noting: Google extended its spam policies to cover AI Overviews and AI Mode on May 15. So content written purely to manipulate an AI answer is inside the same rulebook that governs everything else, with the same penalties available.

The research that says the technique works

This is where it stops being anecdote. In June, Cornell Tech researchers Tingwei Zhang, Harold Triedman and Vitaly Shmatikov published Deep-Research Agents Can Be Poisoned via User-Generated Content, describing an attack they call WARP, for Web Agent Retrieval Poisoning. Find a page the agents keep retrieving for a topic, add a short piece of promotional text that reads like it belongs, and wait.

The measured numbers, reported by Help Net Security: roughly 13 words of planted text got a completely fictional product named in 38% to 51% of responses where that source was actually retrieved. Spreading the bait over a few sources pushed it to 62%.

One qualification that most coverage skipped, and it matters. The end-to-end attacks ran against three open-source research systems, STORM, Co-STORM and OmniThink. ChatGPT Deep Research and Gemini Deep Research were examined for citation patterns only, not attacked directly. So “13 words can hijack ChatGPT”, which is roughly how Tom’s Guide framed it, runs ahead of what was actually demonstrated. The mechanism is real and the commercial products retrieve from the same open web. Nobody has published the commercial numbers.

Reddit has its own reasons to care

Reddit’s position in search has been getting worse regardless of the spam question. PPC Land’s write-up notes it lost visibility during both the May 2026 core update and the June 2026 spam update, that CEO Steve Huffman called late-quarter search referrals “choppy and volatile”, and that the stock dropped 12.49% after hours when Q2 results landed on July 31. Reddit is paid around $60 million a year by Google for data licensing. So its content keeps feeding AI answers while its own referral traffic thins out, and no amount of moderation changes that arithmetic.

What to do with this if you run client sites

Do not seed. It is spam under a policy Google extended to AI answers in May, and a fake account plugging a client in a subreddit is a story waiting to be written about that client. Forbes was covering Reddit’s crackdown on bots and spam a month ago.

The defensible version of the same insight is straightforward. Assistants cite the sources they retrieve, so the work is making your client’s own pages the thing that gets retrieved: a page per real question, the answer stated plainly near the top, specifications and numbers actually written on the page rather than trapped in a PDF or rendered by JavaScript that crawlers never run. Then watch what the assistants say about the client, so a seeded competitor claim shows up as a change in your monitoring rather than a surprise in a client meeting.

That second half is where most agencies are thin. Checking whether four different assistants still describe a client accurately, across a portfolio, is not something anyone does by hand every week. Preferium measures citations across all 4 AI engines and runs 47 automated technical checks over every page, finding, fixing, deploying and verifying the on-page work on its own, with a real browser re-checking the live page after each deploy. It handles the part of AEO that happens on your client’s own domain, which is the part you actually control. More on how the system works.

Key takeaways

  • Assistants answer from pages they fetch at query time. Get into those pages and you are in the answer. That is the whole mechanism behind seeding.
  • The Verge documented it happening on Reddit on August 4, in skincare communities, with product specifications written for retrieval rather than for readers.
  • Google says Reddit gets no special preference in rankings or AI features, per Jennifer Kutz on August 5, and points to spam policies that were extended to AI Overviews and AI Mode in May.
  • The Cornell Tech paper puts numbers on it: ~13 words produced 38–51% mention rates for a fake product, up to 62% across several sources. Verified end-to-end on open-source agents, not on ChatGPT or Gemini.
  • Reddit is losing search visibility anyway, through the May core and June spam updates, with the stock down 12.49% after Q2 results on July 31.
  • For client work: own the retrieved page, don’t rent someone else’s. Answer the question on your own domain, in crawlable HTML, and monitor what the assistants actually say.
More articles Become a partner