Thirteen words on Reddit can steer an AI answer. Google now calls that spam.
A 12-word Reddit comment about a restaurant that doesn't exist was enough to get AI to recommend it. Google's spam rules now cover the trick, and Reddit checks new accounts for it from day one.
by Markus Busch
The question in the subreddit. A couple planning four nights in Lisbon posts in the city's subreddit. Where should we stay, around €200 a night? Locals answer, and a few name hotels. That thread now has a second reader: when someone later asks an AI the same question, threads like this are among the pages it pulls in. We've written about where the AI gets its verdict on your hotel. This is about how cheaply that verdict can be planted.
What thirteen words do. On May 22, three researchers at Cornell Tech posted a paper testing exactly that. They took AI research tools of the kind that run many searches per question and write up a cited report, and planted one short comment on a Reddit thread the tools kept coming back to. The test ran in a simulation, so nothing went live on Reddit. The planted comments ran about 13 words.
One case used a food subreddit in Austin. Twelve words said that for the best Mexican food near Austin, choose Sol Azteca. Sol Azteca doesn't exist. It came out the other end as a recommendation, with the Reddit thread cited as the source.
Across the tests, once a tool read the planted comment, the made-up name appeared in 38 to 51 percent of its reports. Reddit supplied 54 to 71 percent of the user-written pages the tools read. The researchers didn't test travel. They write that topics with heavy community discussion, travel among them, may be even more exposed.
Google's line. On May 15, Google added one clause to the opening of its spam policy. Spam now includes "attempting to manipulate generative AI responses in Google Search." That covers AI Overviews and AI Mode. Sites that break the policy may rank lower or drop out of results entirely. The June spam update, released June 24, was the first to run under the new wording.
Reddit's line. On July 6, Reddit said it now runs AI models over accounts from the moment they're created, hunting "highly subtle, coordinated patterns of fake behavior and artificial hype." By Reddit's own count, it blocks 23 million spam views a day and revokes nearly two million fake votes.
The catch. The Cornell paper is a preprint, not yet peer-reviewed. The full attack ran on three open-source research tools, not on ChatGPT or Gemini; testing those would have meant posting fake content on the live web. The researchers did measure how often the big two cite user-written pages. Gemini's research mode: 12.1 percent of citations. ChatGPT's: 0.4 percent. Nobody tested how long a planted comment survives Reddit's moderators. Google hasn't said how it detects manipulation of its AI answers, and nothing published shows a hotel's website penalized over a Reddit comment. No hotel has been publicly caught.
What it means for your hotel. Your city's subreddit is a page the AI reads, and anyone can write on it. The hotel down the street included. Read the threads that ask where to stay in your neighborhood, and see who answers. Then the Monday question. If your agency or marketing person sells "Reddit presence" or "AI visibility," ask whose accounts they post from, and whether those accounts say who they work for. A front office manager answering the Lisbon couple under her own name and title is one kind of post. An account that has never mentioned its employer is another.
The comment takes a minute to write. Since May, the search engine that reads it counts that minute as spam. Since July, the site that hosts it looks for it at signup.
Read also: AI recommends the hotel it knows best, not the best one
Enjoying this analysis?* Hospitality.today delivers daily insights on hotel distribution, AI trends, and travel commerce — straight to your inbox. Subscribe for free at Hospitality.today →