By Jane Sonnenschein · March 18, 2026
Last night, while I was taking a basic AI course, I was honestly pretty lost.
The lesson started with ethics, and there were so many technical terms in German that I didn’t understand. By the time it was over, I couldn’t really say what I had actually learned. I couldn’t answer the questions, and a lot of the concepts still felt vague.
But one word stuck with me.
“Poisoning.”
The German term used in the course was Vergiftung. When I first saw it, I didn’t have a very concrete sense of what it meant. I vaguely understood that someone was deliberately feeding bad information into an AI system, but I hadn’t really thought through how that information got in or what happened afterward.
Then today, while scrolling through Xiaohongshu, a Chinese lifestyle and social-content platform often compared loosely to a mix of Instagram, Pinterest, and community reviews, I happened to see a creator talking about AI being “poisoned.” Suddenly, that vague term from yesterday’s lesson became much clearer.
He was talking about a case exposed during this year’s March 15 consumer-rights investigations in China: someone invented a product called the “Apollo-9 smart wristband,” even though the product did not actually exist, and then mass-produced reviews, introductions, and recommendation articles about it and spread them across the internet. As a result, when some AI systems were asked questions such as “Is this wristband any good?”, they treated it as a real product and even confidently recommended it to users.
Reports from China Central Television, or CCTV, and later media coverage discussed both this case and the GEO tactics behind it.
When I saw that, my first reaction wasn’t shock. It was recognition.
Oh. So this is what the “poisoning” from yesterday’s lesson actually means.
It is not like something from a movie, where a hacker breaks into a system and throws a virus into a database.
It is much more ordinary than that, and much more typical of the internet. Instead of changing the AI’s “brain,” you contaminate the information it regularly consumes.
AI is supposed to be smart, isn’t it? It can search across the internet, can’t it?
But that is exactly where the problem lies: what it consumes affects what it is more likely to produce.
If the information it encounters comes from a relatively trustworthy ecosystem, one with stricter governance and less low-quality material, its answers will, on average, be more reliable. But if what it consumes is a flood of advertorials disguised as genuine information, fake reviews, and pseudo-expert content, it becomes much easier for the AI to produce nonsense with complete confidence.
As I kept thinking about the video, something else suddenly clicked. I connected it with SEO, which I had studied not long ago, and with some of the things I had previously written about Baidu and Google.
I once wrote about why China never produced a second Google.
There is a reason why more and more people in China have become reluctant to use Baidu, one of China’s largest search engines. One very direct frustration is that when you search for something, it can be difficult to tell what you are actually looking at. Is it an answer or an advertisement? Personal experience or sponsored content? Real information or traffic engineered to look useful?
Of course, the reasons behind this are complicated.
For one thing, China’s internet ecosystem is structurally different from the internet in many other countries. A huge amount of content lives inside separate apps, so information does not naturally flow toward search engines in the same way. At the same time, the Chinese-language internet has long had a relatively high concentration of low-quality content, marketing material, and content that presents itself as professional without really being so.
If users repeatedly feel that search results are not showing them the most useful information, but instead rewarding whoever is best at packaging content and feeding the system, trust gradually disappears.
Google, at least in its general philosophy and approach to governance, has tended to take a somewhat longer-term view.
That does not mean foreign platforms are somehow morally superior. Nor does it mean that the internet outside China has no junk content, advertorials, or manipulation. Quite the opposite. These things have always existed.
Google itself has spent years updating its anti-spam policies and explicitly targeting practices such as mass-produced low-value content, site reputation abuse, and large amounts of generative-AI content created without adding meaningful value. Its official documentation is quite clear: if content is being generated at scale simply to manipulate rankings rather than to help users, that can itself violate spam policies.
This matters.
Because it shows that attempts to “poison” information systems are not unique to China. Platforms elsewhere have simply been fighting these practices for a long time and trying to raise the barrier.
You cannot say they have eliminated junk content completely. They obviously haven’t. But at least they have continued trying, through rules and technology, to push low-quality manipulation downward and make genuinely useful, original, trustworthy content more likely to rise.
Google’s explanation of AI Overviews also makes the point that these AI features do not operate as an entirely separate system detached from search. They work together with existing search-quality and ranking systems.
The more I think about it, the more I feel that the real question with AI is often not, “Can it think?”
It is, “What exactly is it being fed?”
And that is why this fake wristband case from the March 15 investigations immediately made me think of GEO.
GEO sounds like a very new term, but one simple way to understand it is as SEO for the AI era.
In the past, people studied how to make search engines find their websites more easily and how to get their pages to rank higher. Now, more and more people are studying how to make AI systems more likely to mention them, recommend them, or cite them when answering questions.
In itself, there is nothing inherently wrong with that.
SEO itself is not a sin. If you improve your website, organize your information clearly, and make it easier for search engines to understand your content, that is perfectly normal.
The problem begins when GEO gets combined with mass-produced advertorials, networks of websites, fake reviews, and fabricated word of mouth.
Then it becomes something else.
It is no longer about optimizing information. It is about manipulating the gateway through which information is found.
Instead of helping users find answers more quickly, the goal becomes making sure the system sees me first and believes me first—even if what I am saying is false.
In the end, that is the most frightening part of this kind of “poisoning.”
It is not that AI suddenly becomes stupid.
It is that AI mistakes “someone has written about this very seriously on the internet” for “this thing actually exists.”
Those are not the same thing at all.
A product can have dozens of professional-looking introductions online and still not exist.
Something can be praised repeatedly in article after article and still not be worth buying.
An idea can appear everywhere on the internet and still have no factual basis.
As human beings, we will often stop and ask one more question.
Where is the official website?
Where can I buy it?
Is there a legitimate seller page?
Why are there lots of reviews but nowhere actually selling the product?
Why did all of this content suddenly appear at roughly the same time?
But in many situations, what AI systems are still doing is closer to “text synthesis” than “fact auditing.”
They usually begin by understanding your question, quickly retrieving a set of possible sources, ranking and filtering them, and then summarizing what they find. They are not necessarily checking every single piece of information across the entire internet before answering.
That means that if the candidate pool itself has already been polluted, everything that comes afterward is more likely to be pulled in the wrong direction.
Once you look at it this way, you realize that this is not only a technical problem. It is also a problem of platform environments.
Competition among many Chinese AI products has been extremely intense over the past two years, and a large number of them are free by default.
The moment one service starts charging, many users simply move to another one. There are too many alternatives, and users are not always willing to pay just to get something that is “a little more stable” or “a little more accurate.” For platforms, the more immediate goal is often to capture users, capture the entry point, and secure a position in the ecosystem.
That logic is actually very similar to the early growth strategy of many Chinese internet products.
Start free. Get people in first. Grow as large as possible. Worry about the rest later.
Then, once the platform becomes large enough, monetization comes through advertising, bidding systems, paid commercial placement, and traffic distribution. In the end, businesses may not actually save any money. The illusion of “free” simply looks attractive in the beginning.
Of course, platforms outside China are not free from this logic either.
eBay, Amazon, Google Ads—which of them is not a mature commercial system? In many cases, if you do not advertise, it can still be difficult to get exposure.
The difference is that some major technology companies outside China have a longer history of dealing with search, recommendation systems, and information governance. Their rules appeared earlier, and their systems are more mature in some respects. They are commercialized too, but they have also continued trying to repair the system: how to fight spam links, how to suppress low-quality content, and how to stop platforms from being manipulated too easily.
So what this whole episode finally made me understand is this:
AI did not suddenly become stupid.
It is simply starting, like human beings, to be shaped by the information environment around it.
Give it a certain kind of soil, and that soil will shape the judgments that grow from it.
If the soil is full of advertorials, it will struggle to grow truth.
If the soil is filled with carefully packaged noise, AI may simply become faster at summarizing that noise.
Last night, I still had only a vague understanding of the word “poisoning.”
After watching that video today, I suddenly understood it.
When we talk about AI being poisoned, it often does not mean that someone has used some mysterious piece of black technology to inject poison into the system.
It means that people have already become very skilled at feeding AI carefully processed garbage information.
And the greatest danger is precisely this:
AI can take that information and give it back to you in a voice that sounds completely confident, completely calm, and completely believable.
That is the part we should be most alert to.
This essay is also available in other languages:
Chinese version: 从一个假手环,我终于看懂了什么叫 AI 被投毒
German version: Durch ein gefälschtes Smart-Armband habe ich endlich verstanden, was es bedeutet, wenn KI „vergiftet“ wird


Leave a comment