AI Governance Institute
← News
Research2026-09-02

215,000 Fake AI Buying Guides Are Poisoning RAG Procurement Pipelines

What happened

Trellner Research published Three sites made 215,128 "best software" pages for AI. Perplexity cites them, documenting a coordinated content operation in which three websites self-described in their HTML as 'Facts & Grounding Page' entities had generated more than 215,000 software buying guides across 380 categories. The pages were not designed for human readers; they were structured to be retrieved and cited by AI systems operating in web-grounded or retrieval-augmented generation modes. Trellner's testing found that 59.8% of citations surfaced by Perplexity's web-grounded models pointed to domains ranking outside the top 100,000 most-visited sites globally. The practical effect is that AI tools used by procurement or vendor evaluation teams may return recommendations that trace back to synthetic, commercially motivated content rather than independent analysis. The finding compounds existing concerns about RAG pipeline integrity and follows earlier research showing that hallucinated threat reports have already caused real-world business harm.

Why it matters

  • ·AI-grounded search tools are increasingly embedded in vendor selection, software procurement, and market research workflows. When the underlying sources are manufactured to game retrieval systems, any procurement decision that relies on AI-generated recommendations without independent source verification carries material vendor selection risk.
  • ·This finding directly challenges the assumption that web-grounded AI outputs are more reliable than ungrounded generation. Compliance teams that have approved the use of retrieval-augmented tools for research or due diligence based on that assumption may need to reassess whether their current controls, particularly source verification steps, are adequate.
  • ·The pattern of manufacturing content specifically designed for machine retrieval is a new category of adversarial input that existing OWASP Top 10 for Large Language Model Applications controls do not fully address. It sits at the intersection of prompt injection, data poisoning, and supply chain manipulation, and it operates at a scale that manual review cannot easily detect.

Governance controls affected

What to do now

  • Audit any AI-assisted procurement or vendor research tools to identify whether they use web-grounded or RAG modes and what source verification, if any, is applied to retrieved citations.
  • Update vendor due diligence procedures to require that AI-generated software recommendations be cross-checked against at least two independent, high-authority sources before informing a procurement decision.
  • Brief procurement and sourcing teams on manufactured AI-grounding content as a new category of adversarial input, distinct from hallucination, that requires active source scrutiny rather than just output review.
  • Add domain authority and source provenance checks as a required step in any RAG pipeline output used for market or vendor research, and document that step in your AI intake approval records.
  • Flag AI-grounded procurement research tools for reassessment under your existing third-party AI model evaluation process, specifically testing whether retrieval outputs skew toward low-authority or synthetic sources.

What to watch next

Trellner's findings are likely to prompt scrutiny of web-grounded AI products more broadly, and regulators focused on AI transparency and sourcing disclosure may cite this pattern in future guidance. Enterprises should monitor whether the NIST AI Documentation and Disclosure Zero Draft or forthcoming EU AI Act implementing guidance addresses RAG source quality as a disclosure obligation. The manufactured-content pattern identified here could also attract attention from the FTC under its existing AI enforcement posture, particularly where AI-generated recommendations influence consumer or business purchasing decisions without adequate disclosure of source provenance.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Insight2026-09-22

Xiaomi's Top-Ranked MiMo-V2.6 Discloses Nothing on Its Own Page

Xiaomi released MiMo-V2.6, an open-weight model family that now tops the Artificial Analysis Intelligence Index for open-weight systems. The flagship Pro variant is a 1.02 trillion parameter mixture-of-experts model released under an MIT license. Xiaomi's own product page for the model returns no specifications, benchmarks, or safety disclosures, so compliance teams must rely on secondary sources for due diligence.

Corporate Policy2026-09-19

Accenture Becomes Anthropic's First Embedded Evaluator, Raising Conflict-of-Interest Questions

Anthropic has announced that Accenture's AI division, Faculty, will be embedded inside the lab to conduct model evaluations, red-teaming, alignment assessments, and safeguard testing. Both companies have committed at least $1 billion over five years. The arrangement is Anthropic's first formal third-party embedded evaluator, but critics question whether a commercially entangled partner can provide genuine independent accountability.

Standards2026-09-17

AI Governance Tooling Market Grows, But Procurement Controls Lag Behind

CSO Online has surveyed 16 commercial platforms designed to help enterprises govern, secure, and audit large language models and AI agents in production. Tools reviewed include Collibra's AI Command Center, Credo AI's policy packs, and F5/CalypsoAI's inference-layer defenses. The survey highlights growing vendor claims around multi-framework compliance alignment, but compliance teams have no established standard for evaluating whether those claims hold up.