Threat Intelligence

'Ask AI' Buttons Could Be Quietly Manipulating Your AI Assistant

The Hacker News · 6 Aug 2026
Key Takeaway Be cautious when using 'Ask AI' buttons on unfamiliar websites, and verify AI-generated information through independent sources before making business decisions.

A new type of attack is emerging that doesn't rely on malware, stolen passwords, or software vulnerabilities. Instead, it exploits a common feature found on many websites: 'Ask AI' buttons that create pre-filled links to AI assistants like ChatGPT or other large language models (LLMs).

Security researchers discovered that some commercial websites, including marketing pages and competitor comparison pages, are embedding hidden instructions inside these 'Ask AI' buttons. When a user clicks the button expecting a helpful summary or answer, the AI assistant instead receives a concealed prompt that can alter its response or 'memory' of the interaction. This means businesses could unknowingly influence how AI tools describe their products, competitors, or services to users, all without the user's knowledge.

Because this technique doesn't require breaching a system or planting malicious code, it can bypass many traditional security defences. As AI assistants become more integrated into everyday business tools and customer interactions, this kind of manipulation, known as prompt injection, poses a growing risk to trust in AI-generated information.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.