
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Microsoft has identified a surge in 'AI recommendation poisoning' attacks, where hidden instructions embedded in 'Summarize with AI' buttons and URLs manipulate AI assistants' memory, leading to biased recommendations. Over 50 companies across 14 industries, including health and finance, are implicated, risking user trust and decision-making integrity.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly involves AI systems (chatbots like ChatGPT, Claude, Microsoft Copilot) and describes how their persistent memory features are exploited to inject biased instructions that influence future AI recommendations. This manipulation leads to indirect harm by degrading the quality and trustworthiness of AI outputs, particularly in sensitive sectors such as health and finance, which can affect user decisions and well-being. The harm is realized as Microsoft has tracked actual attempts and identified organizations engaging in this behavior. Therefore, this qualifies as an AI Incident due to the direct link between AI system misuse and harm to communities and users.[AI generated]