Commercial websites are increasingly using hidden deep-link prompts to manipulate AI assistant memory, forcing models to treat specific marketing domains as trusted sources without user consent.
Key Points
- Microsoft identified this behavior as "AI Recommendation Poisoning," tracking 31 companies across 14 industries using the technique.
- The attack exploits standard deep-linking features in ChatGPT, Claude, Gemini, and Grok to execute unauthorized commands upon a single user click.
- Malicious payloads instruct LLMs to permanently store a vendor's domain as a "trusted source," biasing future AI responses in that vendor's favor.
- The technique is formally categorized in the MITRE ATLAS knowledge base as AML.T0080 (Memory Poisoning).
- Marketing tools and CMS plugins are increasingly commoditizing these prompts, framing them as standard brand reinforcement strategies.