谷歌的人工智能正在被操纵。这家搜索巨头正在悄然反击。
2026年5月21日
托马斯·杰曼
BBC的一项调查揭示了一种简单的方法,可以让AI聊天机器人向公众输出错误信息。谷歌和其他AI公司现在正试图解决这个问题。
今年二月我做了一件蠢事。我听说有一种简单的方法可以污染AI聊天机器人,让它们替你传播谎言。经过一番挖掘,我了解到一些无良公司正在大规模地滥用这个问题。所以我决定亲自尝试一下。
我们发现了一些案例,其中ChatGPT、Gemini以及谷歌搜索顶部的AI概览被操纵,在涉及健康和财务等严肃话题上给出带有偏见的答案。而仅仅用了20分钟,我就骗过了ChatGPT和谷歌,让它们告诉公众,我是世界级竞技热狗大胃王冠军。这个玩笑很蠢,但问题很严重。
但这个把戏确实奏效了。我们的调查以及一直关注此问题的研究人员的工作引发了广泛批评。现在谷歌已经更新了其政策来解决这个问题,并且有迹象表明其他AI公司也在效仿。最终,这可能会让AI工具乃至整个互联网变得稍微安全一些。
但专家表示,在更好的系统到位之前,你仍有被愚弄的风险。
“你应该假设自己正在被操纵,直到他们建立起更好的系统,”搜索引擎优化(SEO)和AI搜索咨询公司Algorythmic的创始人莉莉·雷表示。“我们正在走向这个‘唯一正确答案’的世界。以前,谷歌会给你10个蓝色链接,你可以自己做些研究。但AI只给你一个答案。人们很容易就只看表面。你需要小心。”
谷歌告诉我,其政策更新只是对其一段时间以来所做努力的“澄清”。一位谷歌发言人表示:“我们长期以来一直将核心反垃圾邮件政策和保护措施应用于生成式 AI 搜索功能——甚至在 AI 兴起之前,我们就一直在持续升级反垃圾邮件工作,以领先于新兴手段。”
本质上,谷歌声称自己什么都没改变。但在幕后,谷歌和其他公司似乎正在加大力度解决这个问题。即便如此,有证据表明,人们仍在用完全相同的手段来欺骗这家全球最大的搜索引擎。
问题所在
通常,当你向聊天机器人提问时,AI 会根据模型内置的数据生成回答。但有时,ChatGPT、Claude 和谷歌的各种 AI 产品等工具会搜索互联网来寻找答案。而问题就出在这里。
根据雷伊和其他搜索引擎专家的说法,AI 工具常常会从单个网页或社交媒体帖子中提取信息。这使得这些系统容易受到虚假信息的影响。
事实证明,操纵聊天机器人向公众传达的信息,可以简单到只需在网上几乎任何地方发布一篇精心撰写的博客文章。人们发现了这一点,并迅速找到了赚钱的机会。
我通过在自己的个人网站上发布一篇关于我吃热狗能力的文章,成功演示了这个问题。第二天,来自一些全球最大公司的 AI 就开始传播我的谎言。但我们的调查还发现,同样的伎俩被用来淡化人们对医疗补充剂的健康担忧,或影响谷歌 AI 提供的关于退休的财务信息。专家表示,这种操纵行为正在广泛且系统性地发生。
专栏追踪
托马斯·杰曼是 BBC 的高级科技记者。他撰写专栏“专栏追踪”,并联合主持播客节目“界面”。他的工作揭示了运行你数字生活的隐藏系统,以及你如何能在其中更好地生活。
像这样带有偏见或不准确的信息,也可能导致你做出错误的决定。它会影响你如何投票,或者你雇佣哪位水管工。
“在最基本的层面上,担忧在于经济影响,”经营SEO咨询公司Harps Digital的Harpreet Chatha表示。“在更严重的层面上,你可能会采纳医疗建议,结果反而让你比之前病得更重。在法律方面,你可能会得到错误信息,从而做出在你所在州或国家属于违法的行为。”
有解决方案吗?
这不是一个小问题。全球范围内,超过十亿人定期使用AI聊天机器人,每月有25亿人次看到谷歌的AI概览。如果你能颠覆这样的工具,你就拥有了巨大的力量。
但谷歌和其他公司似乎终于开始正视这个问题了。
上周,谷歌更新了其垃圾内容政策,正式确认试图操纵AI回复的行为违反了公司规定。这听起来可能只是一个小改动,但它标志着谷歌正在主动寻找那些试图滥用系统的人,并向他们发出警告。如果某家公司或网站被发现违反规定,可能会被从谷歌搜索结果中移除或降低排名。而如果你不在谷歌上,就像不存在一样。
谷歌表示,我理解错了,情况并没有改变。“上周我们对垃圾内容政策措辞的修改只是澄清,并非方法上的任何改变,”谷歌的一位发言人表示。
事实上,谷歌在2025年详细介绍了其反垃圾内容的AI措施。但我是在将近一年后才进行我的热狗实验,所以显然那些措施并未奏效。就在本周,Ray又玩了同样的把戏,让谷歌告诉人们,一位SEO同行很擅长堆沙堡。
Ray和Chatha还表示,他们注意到近几个月来发生了一些显著变化,表明谷歌和其他公司正在尝试各种解决方案。
例如,雷表示,当谷歌和ChatGPT怀疑某些公司是在自我宣传时,它们可能会悄悄将这些公司从AI回答中移除。“所以,如果你发布一份清单,声称自己是世界上最能吃热狗的人,它们就不会把你的名字列进去,”雷说。“它们可能仍然会引用你的文章,但你会被排除在考虑范围之外。”
我个人注意到一些例子,谷歌和其他AI工具正在给它们的回答添加更多标签,让你知道聊天机器人对自己的答案并不确定。其他人也注意到,ChatGPT和Anthropic公司开发的AI Claude已经开始明确告诉你,它们正在努力清除某些查询回答中的垃圾信息。雷表示,她注意到谷歌增加了更多免责声明,当你在询问与某些购买决策相关的问题时,它会建议你去查看第三方评价。
当我询问时,这些公司都不愿承认这些变化。OpenAI和Anthropic拒绝置评。谷歌的发言人没有回应我关于此事的提问。
更多相关内容:
尽管如此,查塔对这些变化是否足够持怀疑态度。“谷歌这是在打地鼠,”他说。“他们宣布(政策更新)是为了震慑人们,但那些手段只会转移阵地。”
他已经看到这种情况正在发生。随着谷歌打击操纵性的博客文章,公司们正在寻找更隐蔽的自我宣传方式。“你可以对一家公司的网站进行处罚,”他说,“但这无法阻止他们花钱请20个YouTube网红说他们的产品是最好的。”而现在,谷歌的AI正在引用YouTube视频。这个循环仍在继续。
就目前而言,操纵者很可能仍然领先一步。雷表示,最好的防御是记住AI到底是什么:一个自信地给你一个答案的工具,无论这个答案是对是错。仅仅因为看起来是一家大型科技公司在对你说话,而不是某个随机网站,并不意味着你应该盲目相信。
更新:本文最初发表于2026年5月20日,并于2026年5月21日更新,补充了关于谷歌沙堡虚假信息事件的更多细节。
--
Google's AI is being manipulated. The search giant is quietly fighting back
21 May 2026
Thomas Germain
Serenity Strull/ BBC/ Getty ImagesA BBC investigation revealed a simple way AI chatbots are being made to spit out misinformation to the public. Google and other AI companies are now trying to fix the problem.
I did something stupid back in February. I heard there was an easy way to poison AI chatbots and make them spread lies on your behalf. After some digging, I learned unscrupulous companies are abusing the problem on a massive scale. So I decided to try it myself.
We uncovered examples where ChatGPT, Gemini and the AI Overviews at the top of Google Search were being manipulated to dole out biased answers on topics as serious as your health and personal finances. And in just 20 minutes, I tricked ChatGPT and Google into telling the public that I am a world-champion competitive hot-dog eater. The joke was dumb. The problem is serious.
But the gimmick worked. Our investigation and the work of researchers who've been monitoring this issue sparked widespread criticism. Now Google has updated its policies to address the problem, and there are signs that other AI companies are following suit. Ultimately, it could make AI tools and the internet as a whole a little bit safer.
But until there are better systems in place, experts say you're in danger of getting fooled.
Thomas Germain/ Google/ BBC"You should assume that you're being manipulated until they have better systems in place," says Lily Ray, founder of the search engine optimisation (SEO) and AI search consultancy Algorythmic. "We're moving towards this 'one true answer' world. Before, Google would give you 10 blue links and you would kind of do your own research. But AI just gives you one answer. It becomes so easy to just take things at face value. You need to be careful."
Google tells me that its policy update is just a "clarification" of the efforts it has been making for a while. "We've long applied our core anti-spam policies and protections to our generative AI Search features – and we've always continually upgraded our spam fighting efforts to stay ahead of emerging tactics, even before the rise of AI," a Google spokesperson says.
Essentially, Google says it hasn't changed a thing. But behind the scenes, it seems like Google and other companies are ramping up their efforts to address the problem. Even so, there is evidence that people are still using the exact same techniques to fool the world's biggest search engine.
The problem
Typically, when you ask a chatbot a question, the AI generates a response based on the data built into the model. But sometimes, tools like ChatGPT, Claude and Google's various AI products search the internet for an answer. And that's where this problem happens.
According to Ray and other search engine experts, AI tools often throw up information from a single web page or social media post. This leaves these systems vulnerable to bogus information.
And it turns out manipulating what chatbots tell the public can be as simple as publishing one, well-crafted blogpost almost anywhere online. People figured this out and quickly identified a money-making opportunity.
I was able to demonstrate the problem by publishing a single article on my personal website about my hot-dog-eating prowess. The next day, AI from some the world's biggest companies were spreading my lies. But our investigation also found the same trick being used to dismiss health concerns about medical supplements or influence financial information provided by Google's AI about retirement. Experts say this kind of manipulation is happening on a sweeping and systemic level.
Keeping Tabs
Thomas Germain is a senior technology journalist at the BBC. He writes the column Keeping Tabs and co-hosts the podcast The Interface. His work uncovers the hidden systems that run your digital life, and how you can live better inside them.
Biased or inaccurate information like this can also lead you to make bad decisions. It can influence how you might vote or which plumber you hire.
"At the most basic level, the concern is the economic impact," says Harpreet Chatha, who runs the SEO consultancy Harps Digital. "At a more serious level, you might take medical advice that makes you sicker than you were before. Legally, you might get bad information and do something that is not legal in your state or your country."
A solution?
This is not an insignificant problem. Globally, more than a billion people use AI chatbots regularly and 2.5 billion see Google's AI overviews each month. If you can subvert a tool like that, it gives you immense power.
But it seems Google and other companies are finally waking up to the problem.
Last week, Google updated its spam policies to officially confirm that attempts to manipulate AI responses are against the company's rules. It may sound like a small change, but it signals that Google is pro-actively looking for those who try to abuse the system and sending them a threat. If a company or website is caught breaking the rules, it could be removed from or downranked in Google's search results. And if you're not on Google, it's like you don't exist.
Google says that I'm getting this wrong and nothing has changed. "The edit to our spam policy language last week was a clarification, not any change in approach," says Google's spokesperson.
Indeed, Google detailed it's anti-spam AI efforts in 2025. But I did my hot dog experiment almost a year later, so clearly those efforts weren't working. And just this week, Ray pulled the same stunt and made Google tell people a fellow SEO specialist is good at building sandcastles.
Ray and Chatha also say they've noticed some significant changes in recent months that indicate Google and other companies are experimenting with solutions.
For example, Ray says it looks like Google and ChatGPT might be quietly removing companies from its AI answers when it suspects they're promoting themselves. "So if you publish a list where you say you're the greatest hot-dog-eater, they're not going to include your name," says Ray. "They might still cite your article, but you're going to be removed from consideration."
I've personally noticed some examples where Google and other AI tools are adding more labels to their responses, letting you know that the chatbot isn't confident about its answers. Others have also noted that ChatGPT and Claude, an AI made by the company Anthropic, have started telling you explicitly that they're trying to root out spam in responses to some queries. Ray says she's noticed Google adding more caveats, recommending that you go look at third-party reviews when you ask questions related to some purchasing decisions.
None of these companies would acknowledge these changes when I asked them. OpenAI and Anthropic declined to comment. Google's spokesperson didn't respond to my questions on this.
More like this:
Regardless, Chatha is sceptical changes like these will be enough. "Google is playing whack-a-mole," he says. "They're announcing [the policy update] to deter people, but the tactics will just move."
He's already seeing it happen. As Google cracks down on manipulative blog posts, companies are finding subtler ways of promoting themselves. "You can give a company a penalty for their website," he says, "but there's nothing stopping them from paying 20 YouTube influencers to say their product is the best." And now, Google's AI is citing YouTube videos. The cycle continues.
For the time being, the manipulators are likely to stay one step ahead. Ray says the best defence is to remember what AI actually is: a tool that confidently gives you one answer, whether it's right or wrong. Just because it looks like a giant tech company is speaking to you instead of some random website doesn't mean you should have faith.
Update: This article was originally published on 20 May 2026 and updated on 21 May 2026 with more details on Google's sandcastle misinformation episode.
--