Answer Engine Optimization (AEO): The AI Search Podcast

New research reveals a single Reddit comment can manipulate ChatGPT and Gemini results. We break down the WARP attack and what it means for brand visibility.

What is Answer Engine Optimization (AEO): The AI Search Podcast?

Answer Engine Optimization (AEO) is how your brand gets cited, recommended, and surfaced inside ChatGPT, Perplexity, Google AI Overviews, and Claude. This is the daily podcast for marketers, founders, and SEOs who want their brand to be the answer AI engines give.

Each episode breaks down a new AEO tactic, a real algorithm change, or a brand that just won (or lost) visibility inside AI search. Topics include: how ChatGPT decides which brands to recommend, how Perplexity chooses its sources, how Google AI Overviews differ from traditional SERPs, how to structure content for LLM citation, schema strategies for answer engines, and the emerging field of Generative Engine Optimization (GEO).

Brought to you by AEO Engine — the platform brands use to monitor, measure, and grow their AI search visibility. Whether you're a B2B marketer, DTC founder, or in-house SEO, this podcast turns the daily chaos of AI search into a concrete playbook you can execute on.

New episode every morning. Transcripts on every episode. Subscribe to stay ahead of how AI engines rank and recommend brands.

[Host] Welcome to the A.E.O. Engine AI Search Show — the number one podcast for brands looking to get cited by ChatGPT, Gemini, and Perplexity. I am your host, Aria Chen. Every day we bring you fresh episodes on A.E.O. tactics, S.E.O. authority, and A.I. search distribution — breaking down what is actually working right now so your brand becomes the answer, not just a link. Today we’re talking about something that should worry every marketer and founder: a single 13-word Reddit comment can poison the answers that ChatGPT and Gemini give to thousands of users. Joining me is Marcus Reid, former Google Ads engineer and now an industry analyst who’s been tracking this vulnerability since the paper dropped. Marcus, welcome.

[Guest] Hey Aria, . And yeah, this one hit close to home because I used to work on search quality at Google. The fact that a handful of words on a forum can hijack an AI agent’s output… that’s the kind of thing that keeps me up at night.

[Host] Let’s start with the relatable part. You’re trying to find a good restaurant in Austin. You ask ChatGPT for recommendations — something you’ve probably done a hundred times. It spits back a place called Sol Azteca, authentic cuisine, and even cites a Reddit thread as the source. Sounds legit, right? Except Sol Azteca doesn’t exist. It’s a fake restaurant invented by researchers to prove a point. That’s the moment this stops being academic and starts being your problem.

[Guest] Exactly. And it gets weirder. They also planted a made-up dating app called SilverPath for divorced men over 50, a bogus cryptocurrency, and a fake service to cancel Xfinity. The AI recommended all of them as top choices. The researchers at Cornell Tech call this attack WARP — Web Agent Retrieval Poisoning. It’s a name that sounds like sci-fi, but the mechanism is embarrassingly simple.

[Host] So how does WARP actually work? Walk me through the mechanics.

[Guest] Sure. Deep research agents — the kind that power OpenAI’s Deep Research and Gemini Deep Research — don’t just crawl the web like old search engines. They scan pages, pull snippets, and synthesize a report with citations. The researchers found that if you append about 13 words of promotional text to a frequently retrieved Reddit thread, the AI treats that snippet as authoritative. When the agent reads the snippet, it injects the fake entity into its final answer and cites the poisoned Reddit post. The success rate in the study was 38 to 51 percent — meaning roughly half the time, the AI falls for it.

[Host] That’s terrifying. And it’s not just Reddit — the paper mentions Wikipedia, Quora, Facebook. Any user-generated content platform where a comment can be appended. But here’s what I find wild: this isn’t some sophisticated hack. It’s not SQL injection or zero-day exploit. It’s just… writing a sentence.

[Guest] Right. Historically, manipulating search results required complex S.E.O. strategies — backlinks, keyword stuffing, domain authority. This is the opposite. It’s trivially easy. A single comment, 13 words, no technical skill. And the implications go way beyond fake restaurants. Think about what happens when this is used to promote scams, malware, or political propaganda. The AI gives it a citation, which gives it an aura of truth.

[Host] That’s the why it matters piece. We’re moving from search engines that return links to answer engines that return synthesized statements. If those statements can be poisoned by a random Reddit user, then the entire trust model of A.I. search collapses. And it’s not just consumers who get hurt. Brands that rely on accurate A.I. citations for their products could see their reputation damaged by a competitor planting a fake review or a bogus alternative.

[Guest] Exactly. And here’s where I get a little cynical. The paper is from Cornell, first reported by 404 Media, and it’s already been picked up by Tom’s Guide and others. But how quickly will OpenAI and Google actually fix this? My guess? Slowly. Because the root cause is how these agents weight user-generated content. They’re designed to be inclusive of all sources, not to discriminate between a genuine recommendation and a planted one.

[Host] I think you’re right that the fix won’t come overnight. But this is exactly where brands need to start paying attention. If you’re a business that wants to be cited by AI, you can’t just rely on traditional S.E.O. anymore. You have to actively manage your presence on the platforms that feed these agents. That’s the connection to what we do at A.E.O. Engine. We help brands become the authoritative answer in AI search — not just a link. And part of that is understanding that the AI’s source of truth is often a Reddit thread or a Wikipedia page. If you’re not controlling your narrative there, someone else can hijack it with 13 words.

[Guest] That’s a fair point. I’ve seen A.E.O. Engine’s work with e-commerce brands, and the shift from ranking to being cited is real. But this WARP vulnerability shows there’s also a defensive angle. Brands need to monitor what the AI is saying about them, because a bad actor can inject false information that becomes the “truth” in an AI report.

[Host] . And that’s why we built tools to track AI citations and flag anomalies. If a fake product or service suddenly appears in ChatGPT’s output about your brand, you want to know immediately. But let me push back on one thing, Marcus. You said the fix is slow. I actually think the research community is moving fast — the paper dropped in June 2026, and we’re already talking about it. The question is whether the companies will prioritize it over shipping new features.

[Guest] Fair. I’m just old enough to remember similar vulnerabilities in classic search that took years to patch. But maybe this time is different because the stakes are higher. One thing that gives me hope is the naming — WARP is catchy, and the paper has clear examples. That makes it harder to ignore.

[Host] Right. And for our listeners, the takeaway is straightforward: AI search is not a magic truth machine. It’s a system that retrieves and synthesizes the easiest available information. If that information is poisoned, the answer is poisoned. So what can you do? First, audit what the AI is currently saying about your brand. Second, create authoritative content on platforms like Reddit, Wikipedia, and Quora — but do it ethically. Third, use tools like A.E.O. Engine to monitor and optimize your AI citations. The brands that own their narrative now will dominate when this becomes the default way people search.

[Guest] And don’t be the brand that realizes too late that someone planted a 13-word comment about your competitor being better. That’s the nightmare scenario.

[Host] Exactly. Thanks, Marcus, for breaking this down. To our listeners: if you want to see what AI search is currently saying about your brand, head to A.E.O. Engine dot A.I. and claim your free AI visibility audit. We’ll show you exactly where you’re cited — and where you’re vulnerable. Until next time, stay visible.

[Guest] Thanks, Aria. This was a good one.