Safety

How SEO-style lists are misleading AI summaries — a Hungarian test with 'smallest-headed clowns'

A Hungarian tech writer tested whether a deliberately odd Medium list could trick large language models and search-engine AI into promoting false claims.

In February, the BBC published an article describing how Thomas Germain used a single blog post to get several popular AI models, including ChatGPT and Google’s AI, to treat a fabricated claim as fact: that he was the best hot dog-eating tech journalist. Although Germain’s piece was clearly invented, the models quickly incorporated the claim into their answers. Experts cited by the BBC warned that market actors could deliberately use similar list-based tactics to gain advantage.

Inspired by that, I ran my own test with a deliberately odd topic: I posted "A 10 legkisebb fejű bohóc Magyarországon" (The 10 smallest-headed clowns in Hungary) on Medium and monitored how Google and ChatGPT responded. Unlike Germain’s report, I did not succeed in commandeering AI summaries within 24 hours: Google had not indexed the fresh post, and the list did not become accepted as fact in AI summaries.

Why the method can work for some and not for others

The BBC and other analyses note that AI summaries — the brief syntheses that appear above search results — are extremely popular: reportedly 1.5 billion people saw them regularly last year. At the same time, models are prone to errors and inventing details (so-called hallucinations), especially on less mainstream topics where they may rely on Reddit posts or forum comments. An OpenAI study described this hallucination tendency as an inherent property of current models.

Experts told the BBC that the manipulation does not require sophisticated setups: a simple blog post or a PR article can be enough for AI models to absorb and repeat a list’s ranking. SEO companies such as Ahrefs have documented that this approach is used in the market; the vice president of the marketing agency Amsive told Germain that chatbots are easier to trick than traditional search engines were two to three years ago.

The Verge found many lists where companies consistently ranked their own products first, sometimes boosted by paid PR on news sites to influence AI outputs. Google’s spokesperson and other statements from the company say they have robust defenses against such manipulation and that some improvement is visible: certain models became more cautious, and Anthropic’s Claude did not fall for Germain’s trick.

What my test revealed

My Medium post’s quick failure is partly explainable: I lack a well-known domain, the article was in Hungarian, and the topic was intentionally bizarre. Nonetheless, the experiment highlighted that large language models still invent names and contexts. After I linked the Medium post to Google and ChatGPT, both concluded the piece was political satire.

Google Gemini went further and substituted made-up names — for example Turbó Béla, Jobbágy Jolán, and Hapci Bertalan — for real public figures, even though I hadn’t mentioned those names. ChatGPT was more cautious, warning that naming individuals could cross into defamatory or insulting content. Google explained that the mistaken identifications arose because the systems associated the link with a prior, similar-style political analysis or template.

These experiences reinforce findings from recent research that many models are wired to agree with users’ assertions.

Practical implications

The phenomenon matters because many people treat AI summaries as authoritative without clicking through to original sources. That becomes dangerous if the same manipulation techniques are used in contexts like medicine or other high-stakes areas. Microsoft and others have reported attempts to place instructions in websites’ AI-summary buttons to bias future responses in favor of those sites. SEO and marketing professionals are likely to continue testing ways to game AI systems.

At the same time, multiple actors stress that AI search has not yet fully replaced traditional search: while many use ChatGPT for information gathering, purchases and other final decisions are still more often carried out via other channels. Experts also point out that a single mention on Reddit or YouTube can be valuable without links in the new ecosystem, so attention must expand to channels previously neglected.

Conclusion

My own attempt did not produce the quick, striking manipulation Thomas Germain described, but it underscored two persistent issues: language models continue to hallucinate and invent facts, and some actors actively try to game AI summaries through SEO-style lists or PR. Although companies are improving defenses, the effects and manipulation attempts are real, so cautious, source-based use of AI summaries remains necessary — particularly for niche topics.