Logo
FrontierNews.ai

How AI Answer Engines Like Perplexity Are Becoming Targets for Influence Campaigns

Artificial intelligence answer engines like Perplexity, ChatGPT, and Claude are increasingly vulnerable to coordinated influence campaigns designed to shape their responses on geopolitical topics. According to a report published by Drop Site News, Israel funded a $46.5 million digital campaign that created a network of websites intended to influence how AI systems respond to questions about the Gaza war, marking one of the first documented large-scale attempts to manipulate AI training data at scale.

What Is "LLM Poisoning" and How Does It Work?

The campaign, allegedly managed by Brad Parscale, former campaign manager for President Donald Trump, and his firm Clock Tower X, operated under a simple but effective principle: create content that search engines and AI training systems would index, even if humans rarely visited the websites. The strategy exploited a critical vulnerability in how large language models (LLMs), which are AI systems trained on vast amounts of internet text, absorb information from the web.

According to Drop Site's investigation, Clock Tower X produced hundreds of articles across multiple websites covering Israel's military operations, US-Israel relations, and the Gaza conflict. The websites, including Allyvia.org, FactSignal.org, and Paxpoint.org, were designed to promote Israeli narratives and defend Israel's military campaign. Although these sites attracted minimal direct human traffic, they were engineered to be crawled by search engines and incorporated into AI training datasets, a practice sometimes called "LLM poisoning".

The report documented that Perplexity, an AI answer engine that competes directly with ChatGPT and Google's AI Overviews, already cited one of these websites when answering a question about US military cooperation with Israel. Microsoft's Copilot also referenced websites linked to the Clock Tower X network, demonstrating that the campaign had already influenced real-world AI outputs.

Why Common Crawl Makes AI Systems Vulnerable to Manipulation?

A major vector for this influence campaign was Common Crawl, a massive web archive that developers worldwide use to train large language models. Between January and June, the 10 websites connected to Clock Tower X were crawled by Common Crawl hundreds of times, potentially amplifying their prominence in AI-generated responses.

"Common Crawl is widely used in the world of data science for training LLMs, which also means that actors want to manipulate the answers in their favour, which some studies have indicated are fairly easy to do," said Herve Letoqueux, chief executive officer of Check First, an organisation that combats digital disinformation.

Herve Letoqueux, Chief Executive Officer at Check First

Letoqueux further noted that the moderate, sourced presentation of the Clock Tower websites made them particularly effective at influencing AI outputs. Because chatbots often present multiple perspectives on contested topics, these websites could provide what appears to be a legitimate counterargument.

"These websites could probably be quite useful at doing damage control on questions such as 'Is Israel committing a genocide?' because they provide the Israeli narrative, which chatbots can then repeat as representative of one side of the debate," Letoqueux explained.

Herve Letoqueux, Chief Executive Officer at Check First

How Content Creators Can Protect AI Systems From Manipulation

As AI answer engines become more central to how people research information, the integrity of their training data has become a critical concern. The emerging field of Answer Engine Optimization (AEO) and Generative Engine Optimization (GEO) offers both opportunities and risks. AEO structures content so that AI systems extract and cite it directly, while GEO builds entity authority so brands are referenced by large language models.

  • Verify Source Credibility: Content creators and AI developers should prioritize websites with established editorial standards, transparent ownership, and verifiable author credentials when training models, rather than accepting all indexed content equally.
  • Audit Training Data Provenance: AI companies should regularly audit which websites contribute to their training datasets and flag suspicious patterns, such as newly created domains with minimal organic traffic but high crawl frequency.
  • Implement Transparency Standards: AI answer engines should disclose which sources they cite and allow users to evaluate the credibility of those sources, similar to how traditional journalism attributes claims to named sources.
  • Monitor for Coordinated Campaigns: Platforms should develop detection systems to identify networks of websites created specifically to influence AI outputs, rather than serving genuine audience needs.

The broader implication is that as content writers transition into AI content strategy roles, they must understand not only how to optimize for AI visibility but also the ethical responsibilities that come with that knowledge. According to industry guidance, content professionals moving into AI strategy roles should master Answer Engine Optimization and Generative Engine Optimization alongside traditional SEO, but with an emphasis on creating genuine, authoritative content rather than engineered influence.

The Clock Tower X campaign reveals a fundamental tension in the AI era: the same techniques that allow legitimate businesses to ensure their content reaches AI systems can also be weaponized by well-funded actors to manipulate public discourse. As Perplexity and other answer engines become primary research tools for millions of users, the stakes of controlling their training data have never been higher. The question facing the AI industry is whether current safeguards are sufficient to prevent future influence campaigns at scale.