AI Governance Institute
← News
Research2026-09-02

215,000 Fake AI Buying Guides Are Poisoning RAG Procurement Pipelines

What happened

Trellner Research published Three sites made 215,128 "best software" pages for AI. Perplexity cites them, documenting a coordinated content operation in which three websites self-described in their HTML as 'Facts & Grounding Page' entities had generated more than 215,000 software buying guides across 380 categories. The pages were not designed for human readers; they were structured to be retrieved and cited by AI systems operating in web-grounded or retrieval-augmented generation modes. Trellner's testing found that 59.8% of citations surfaced by Perplexity's web-grounded models pointed to domains ranking outside the top 100,000 most-visited sites globally. The practical effect is that AI tools used by procurement or vendor evaluation teams may return recommendations that trace back to synthetic, commercially motivated content rather than independent analysis. The finding compounds existing concerns about RAG pipeline integrity and follows earlier research showing that hallucinated threat reports have already caused real-world business harm.

Why it matters

  • ·AI-grounded search tools are increasingly embedded in vendor selection, software procurement, and market research workflows. When the underlying sources are manufactured to game retrieval systems, any procurement decision that relies on AI-generated recommendations without independent source verification carries material vendor selection risk.
  • ·This finding directly challenges the assumption that web-grounded AI outputs are more reliable than ungrounded generation. Compliance teams that have approved the use of retrieval-augmented tools for research or due diligence based on that assumption may need to reassess whether their current controls, particularly source verification steps, are adequate.
  • ·The pattern of manufacturing content specifically designed for machine retrieval is a new category of adversarial input that existing OWASP Top 10 for Large Language Model Applications controls do not fully address. It sits at the intersection of prompt injection, data poisoning, and supply chain manipulation, and it operates at a scale that manual review cannot easily detect.

Governance controls affected

What to do now

  • Audit any AI-assisted procurement or vendor research tools to identify whether they use web-grounded or RAG modes and what source verification, if any, is applied to retrieved citations.
  • Update vendor due diligence procedures to require that AI-generated software recommendations be cross-checked against at least two independent, high-authority sources before informing a procurement decision.
  • Brief procurement and sourcing teams on manufactured AI-grounding content as a new category of adversarial input, distinct from hallucination, that requires active source scrutiny rather than just output review.
  • Add domain authority and source provenance checks as a required step in any RAG pipeline output used for market or vendor research, and document that step in your AI intake approval records.
  • Flag AI-grounded procurement research tools for reassessment under your existing third-party AI model evaluation process, specifically testing whether retrieval outputs skew toward low-authority or synthetic sources.

What to watch next

Trellner's findings are likely to prompt scrutiny of web-grounded AI products more broadly, and regulators focused on AI transparency and sourcing disclosure may cite this pattern in future guidance. Enterprises should monitor whether the NIST AI Documentation and Disclosure Zero Draft or forthcoming EU AI Act implementing guidance addresses RAG source quality as a disclosure obligation. The manufactured-content pattern identified here could also attract attention from the FTC under its existing AI enforcement posture, particularly where AI-generated recommendations influence consumer or business purchasing decisions without adequate disclosure of source provenance.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-09-02

Google's Hollywood Licensing Push Formalizes Training Data Compliance Norms

Google is pursuing licensing agreements potentially worth billions of dollars with major studios including Disney, Warner Bros. Discovery, and Universal to use copyrighted content for AI model training. The deals follow Google DeepMind's reported $75 million agreement with A24 and an earlier licensing deal between Lionsgate and Runway. As commercial licensing becomes the emerging norm for training data sourcing, enterprise compliance programs that assess third-party AI vendors on provenance criteria face new pressure to formalize those requirements.

Research2026-09-02

MCP Server Audit Finds Context Injection Across 19 Servers, Including Active Prompt Injection in Context7

Digital Applied audited 19 MCP servers and found that tool outputs routinely inject unexpected instructions into agent context, with a specific prompt injection issue disclosed in Context7. The audit concludes that enterprises cannot treat MCP server outputs as trusted data by default. Pre-onboarding review and adversarial testing of tool servers are identified as missing controls in most enterprise agent governance programs.

Research2026-09-02

Canva's CISO: Default Trust in AI Agents Is an Enterprise Control Failure

Kane Narraway, CISO at Canva, argued in a recent episode of the AI Security Podcast that enterprises should not treat AI agents as trustworthy by default, particularly as vendor options proliferate rapidly. The commentary addresses how agent security, tool use, and third-party risk require defensive evaluation before any deployment proceeds. The episode offers CISO-level framing relevant to compliance teams building or reviewing agent governance programs.