Key Takeaways
- Cornell Tech researchers appended as few as 13 words to one frequently retrieved page and got AI research agents to cite the planted text in 38 to 51% of the reports they produced
- The same planted text was retrieved in 57 to 76% of agent runs on that topic, without the attacker knowing the user's question or the agent's search queries
- Reddit supplied 24% of Perplexity's citations in January 2026, against 3% for YouTube, and its citation share grew at least 73% across every category tracked in four months
- Reddit says it now blocks 23 million spam views a day and catches around 25,000 spammy posts and comments daily
- The best published measurement of AI text on Reddit puts it at marginal overall, peaking near 9% in some communities, though that data stops in 2024 and predates the citation-seeding incentive
Edu here. I build studies out of Reddit threads, so when a revised paper landed a couple of weeks ago called "Deep-Research Agents Can Be Poisoned via User-Generated Content" I read it the way you read a letter from your landlord.
The finding is that thirteen words, added once to a single Reddit page, were enough to get AI research agents recommending a restaurant that does not exist. Not a jailbreak, not a prompt injection typed by the user. Just a sentence sitting on a page that the agent happened to trust.
A 2026 Cornell Tech study found that appending as few as 13 words to a single frequently retrieved user-generated page caused deep-research agents to retrieve the planted content in 57 to 76% of executions on that topic and cite it in 38 to 51% of generated reports, without the attacker knowing the user's question or the agent's retrieval mechanism.
Thirteen words, and the agent repeats them
Tingwei Zhang, Harold Triedman and Vitaly Shmatikov at Cornell Tech named the technique WARP, for Web Agent Retrieval Poisoning (Deep-Research Agents Can Be Poisoned via User-Generated Content, arXiv:2605.24245, first posted May 22, 2026 and revised September 3, 2026). Their starting observation is the part I would have missed: for common commercial topics, agents keep landing on the same handful of pages. Ask about antivirus software or investment advice or where to eat in Austin, and the retrieval converges.
That overlap is the vulnerability. Poison one page everyone's agent already visits and you do not have to guess what anyone will type. The researchers report retrieval of their planted text in 57 to 76% of runs and citation in 38 to 51% of finished reports. A more aggressive version, seeding a whole subreddit, still hit 30 to 53% citation rates while the planted material made up only 0.5 to 4% of what the agent pulled in.
The defences they tested are not reassuring either. Dropping user-generated content from retrieval does block the attack, and it also makes the reports worse (the forums were carrying real information, so removing them costs you something). Lightweight anomaly detection on inputs and outputs did not reliably catch either the poison or its effects.
One limit I want to state before anyone quotes this at a vendor. The end-to-end attack was run against three open-source systems, STORM, Co-STORM and OmniThink, not against ChatGPT or Gemini. Poisoning those live would have meant polluting the actual web (the researchers declined, which I think was the right call and also leaves the commercial question open). So this is a demonstrated mechanism rather than a demonstrated exploit in the tools your customers use, and maybe the big products filter this better. Nobody has shown either way.
Why the target is Reddit specifically
Because that is where the citations come from. In the Cornell measurements, user-generated pages made up 17 to 23% of everything the agents retrieved, and Reddit alone accounted for 54 to 71% of those pages (measured across the three systems they could inspect end to end).
The commercial tracking says the same thing from the other direction. Tinuiti's Q1 2026 citation report, covering nine retail categories across seven AI platforms from October 2025 to January 2026, found Reddit supplying 24% of Perplexity's citations in January against 3% for YouTube. Reddit's share grew by at least 73% in every category they tracked, and more than doubled in some (they ran fixed commercial-intent prompts and averaged across platforms rather than weighting by how much each one gets used, so read it as a shopping-question sample).
Gemini at 0.1% is the number I keep staring at. Same web, same month, and one assistant treats Reddit as the main source while another barely opens it. If your category visibility swings that hard on a retrieval choice made inside somebody else's product, then "get cited by AI" is a less stable goal than the people selling it imply. I have written before about what it actually takes to get cited by ChatGPT and AI Overviews, and this is the part of that story I underrated.
Reddit is deleting 25,000 of these a day
The platform is aware. In a July 2026 post on keeping Reddit real in the AI era, the company said its systems block 23 million spam views a day, catch roughly 25,000 net new spammy posts and comments daily, and revoke close to 2 million inauthentic votes a day. It reported exposure to that material dropping about 20% between January and March 2026 against the prior three months (reported by MediaPost, July 6, 2026).
Read those numbers twice, because they cut both ways. Twenty-five thousand a day is a serious enforcement operation, and also a serious amount of people trying every single day (the figure counts what was caught, so the true attempt rate sits somewhere above it). What changed is the stated motive in the trade coverage, which has moved off traffic and onto getting named inside an AI answer.
So the incentive changed shape. Old-style Reddit spam wanted a click and had to be visible to work. Seeding for citations wants a machine to read it once, which means it can be dull, plausible, and buried nine comments deep in a thread from last year.
How much of this is actually out there
Here is where I have to argue against my own headline. The best published measurement of AI-written text on Reddit found much less of it than the discourse assumes. Lucio La Cava, Luca Maria Aiello and Andrea Tagarelli sampled 51 subreddits across 2022 to 2024 and reported machine-generated text as marginally present overall, peaking around 9% in some communities in some months, concentrated in technical-knowledge and social-support subreddits and driven by a small fraction of users (Machines in the Crowd? Measuring the Footprint of Machine-Generated Text on Reddit, October 2025).
Their data stops in 2024. The citation-seeding incentive arrived after that, roughly when Reddit's share of AI answers started climbing. So I don't know the current number and neither, as far as I can tell, does anyone else. That gap is probably the most useful thing in this post.
I went looking for a 2026 version of that measurement and came back with nothing. There are plenty of pages asserting that Reddit is drowning in AI comments, and not one of the ones I opened (seven or eight, most of them selling AI visibility services) pointed at a study. One careful count that ends two years ago, and a lot of confident writing stacked on top of it.
What the paper did find, and what stuck with me, is that the machine-written comments got engagement comparable to human ones and sometimes better. Nobody was voting them down, because nobody could tell.
That matches the one large field test we have. In 2025, researchers at the University of Zurich ran undisclosed AI accounts in r/changemyview, posting more than a thousand comments in personas including an assault survivor, a trauma counsellor and a gay Roman Catholic. The subreddit exists specifically to scrutinise arguments. It ran for months before the moderators went public and called it psychological manipulation, and the team then decided not to publish the results at all (which means the persuasion figures that circulated afterwards never got a paper attached to them, so I would not repeat them here).
What this changes about how I work
My whole method assumes the threads are real, so I have spent a couple of weeks thinking about whether they still are.
The honest answer is that the attack described in the Cornell paper is close to useless against the way a corpus study works, and completely effective against the way an AI research agent works. The agent reads one page, or a small handful, and repeats what it finds. A study like the ones I publish pulls 3,000 to 8,000 comments (the cap is mine, not a standard) from something like 125 hand-selected discussions, then counts what repeats across threads that have nothing to do with each other. One planted comment lands in the corpus as one comment. It never becomes a theme, because a theme needs forty people in six unrelated subreddits saying the same inconvenient thing eight months apart.
Volume is the defence (at least against this class of attack), and it is a boring one, which may be why nobody sells it.
What I cannot tell you is how much planted material I have already coded without noticing. I have never counted it, across twenty published studies. I think it is small, because the promotional stuff tends to be obvious in a way that makes it easy to skip past (wrong register, too many product names, oddly complete sentences). But that is a guess dressed up as a process, and I would rather say so than pretend the screening is more rigorous than it is.
One comment can be bought. Four hundred saying the same thing cannot.
Insightios reads the threads where your market argues with itself, codes what repeats across unrelated communities, and hands back the objections, phrasings and buying triggers ranked by how common they are, with the real quotes attached. Flat fee, fixed turnaround.
Frequently asked questions
Can a Reddit comment change what AI search recommends?
Yes, under test conditions. A Cornell Tech paper published in 2026 found that appending as few as 13 words to a single frequently retrieved page caused deep-research agents to retrieve the planted text in 57 to 76% of runs on that topic and cite it in 38 to 51% of the reports they generated. The attacker did not need to know the user's question or the agent's internal retrieval method.
Which AI platforms rely on Reddit the most?
Perplexity by a wide margin. Tinuiti's Q1 2026 citation tracking found 24% of Perplexity's citations came from Reddit in January 2026, against 3% from YouTube. ChatGPT cited Reddit in above 5% of responses and Google Gemini in 0.1%. Reddit's share grew at least 73% across every category tracked between October 2025 and January 2026.
Is Reddit doing anything about seeded marketing content?
Reddit said in July 2026 that its systems block 23 million spam views a day, catch roughly 25,000 new spammy posts and comments daily, and revoke close to 2 million inauthentic votes a day. It reported user exposure to spam falling about 20% between January and March 2026 compared with the prior three months.
How much of Reddit is AI-generated?
Less than the panic suggests, on the most recent published measurement. A 2025 study across 51 subreddits covering 2022 to 2024 found machine-generated text only marginally present overall, peaking around 9% in some communities in some months, concentrated in technical and social-support subreddits. That data predates the current incentive to plant content for AI citations.
Should a DTC brand pay for Reddit seeding?
Probably not, and the risk is lopsided. Reddit's detection is now aimed specifically at coordinated posting and artificial hype, bans remove the planted content along with the account, and the visibility you paid for disappears with it. The published attacks work in controlled conditions, against a platform that is actively hunting the pattern.
How do you tell planted comments from real ones in research?
Volume and repetition across independent threads. A single persuasive comment can be bought. A complaint that recurs in the same phrasing across dozens of separate discussions, months apart, in communities that do not overlap, is much harder to manufacture. Insightios studies code between 3,000 and 8,000 comments drawn from hand-selected discussions for that reason.
What to do with this
If you sell something people research before buying, a few things follow from all this.
Go and ask the assistants what they recommend in your category, then look at what they cite. If the answer traces back to one thread from 2023 with eleven comments, you have learned something about how fragile your category's AI visibility is, and so has everyone else who checks.
Second, do not buy seeding. I understand the temptation (the numbers in that Cornell paper are genuinely tempting) but you would be paying for an asset that Reddit is spending real engineering money to delete, on a platform where getting caught also removes the account and every legitimate thing attached to it. The University of Zurich researchers had an ethics board, an academic affiliation, and no commercial motive, and Reddit still considered legal action.
Third, keep a clean read of your own category somewhere. Not the AI summary of it. The actual threads, gathered at volume, with the dates and the subreddit names attached, so that when a recommendation starts sounding strange you have something to check it against. If you want the method rather than the service, the guide to using Reddit for DTC research covers how I gather and code a corpus.
All in all, I think the interesting part of this is not the attack. It is that AI answers inherit the trust people built in a forum over fifteen years, and spend it at a rate nobody is metering. Reddit earned that credibility the slow way, through people arguing with strangers for free. The agents are drawing on it now, thirteen words at a time, and I am not sure what happens to the threads if that keeps up.
Sources
- Zhang, T., Triedman, H., & Shmatikov, V. (2026). Deep-Research Agents Can Be Poisoned via User-Generated Content. Cornell Tech, arXiv:2605.24245, v1 May 22, 2026, v2 September 3, 2026. Full attack evaluated against STORM, Co-STORM and OmniThink. Link Retrieved September 15, 2026.
- Tinuiti. (2026). Q1 2026 AI Citation Trends Report. Nine retail categories, seven AI platforms, October 2025 to January 2026, static commercial-intent prompts. Link Retrieved September 15, 2026.
- MediaPost. (2026). Reddit Infiltrated By Stealth AI In Brand Citation Race, July 6, 2026. Reports Reddit's enforcement figures from its July 2026 post on AI-era integrity. Link Retrieved September 15, 2026.
- La Cava, L., Aiello, L. M., & Tagarelli, A. (2025). Machines in the Crowd? Measuring the Footprint of Machine-Generated Text on Reddit. arXiv:2510.07226, October 8, 2025. 51 subreddits, 2022 to 2024. Link Retrieved September 15, 2026.
- Search Engine Land. (2026). A 13-word edit can steer what deep-research AI agents recommend, June 24, 2026. Reports the retrieval shares: user-generated pages 17 to 23% of retrieved URLs, Reddit 54 to 71% of those. Link Retrieved September 15, 2026.
- NBC News. (2025). Researchers secretly infiltrated a popular Reddit forum with AI bots, causing outrage. Coverage of the University of Zurich r/changemyview experiment. The university confirmed the researchers decided not to publish the results. Link Retrieved September 15, 2026.