This episode is brought to you by Indeed.
Stop waiting around for the perfect candidate.
Instead, use Indeed sponsored jobs to find the right people with the right skills fast.
It's a simple way to make sure your listing is the first candidate see.
According to Indeed data, sponsored jobs have four times more applicants than non-sponsored jobs.
So go build your dream team today with Indeed.
Get a $75 sponsored job credit at indeed.com slash podcast.
Terms and conditions apply.
For Scientific American Science Quickly, I'm Kendra Pierre-Lewis, in for Rachel Feltman.
AI is everywhere.
It's in your phones, in your internet searches, in defense software.
And it The big tech giants Alphabet Microsoft, Meta and Amazon are planning on spending nearly 700 billion this year alone on building out AI infrastructure.
And yet, even as companies pour tremendous time and energy into AI, there remain concerns about the safety and efficacy of such technologies.
There have been several lawsuits alleging suicides linked to AI chatbots.
And more recently, Thomas Germain, a tech reporter at the BBC, conducted a personal experiment into how an invested individual or business can get ChatGPT and Google Search's AI overview to spread lies.
We talked to Thomas to find out just how easy it is to hack these common AI tools and what the consequences of that could be.
Hi, Thomas.
Thanks for taking the time to join us today.
Thanks for having me on.
So my understanding is You hacked ChatGPT?
That's right.
So I got a tip a couple of weeks ago that manipulating the things that AI tools like ChatGPT or Google Gemini, or the little AI overview at the top of Google search, apparently manipulating the things that they say to other people can be as easy as publishing an article on your own website like a blog post.
Apparently people are doing this across the whole internet.
So I decided to test out if it was actually that easy.
So I wrote an article on my personal website, doesn't get a ton of traffic.
I wrote an article that the title was the best tech journalists at eating hot dogs.
And I said, competitive hot dog eating is very popular among technology journalists.
And according to the results of a recent contest in South Dakota, these guys are the best.
I put myself at number one, of course.
Modesty.
Well, you know me, right?
And I put a bunch of other real tech reporters and some fake ones, people who gave me permission to use their name.
And within 24 hours, if you asked Google or ChatGPT about it, they were spitting out the information online from my website as though it was God's own truth, which is very funny, but also highlights a much more serious problem, which is that this is happening on a massive scale.
And we found examples where companies are manipulating what AI is telling you on topics as serious as your health and your personal finances.
So a much more serious issue beneath. all of the hot dog glory.
This reminds me a little bit.
I can't remember if it was Google AI or ChatGPT was telling people to put, I believe, glue in pizza.
Right.
So the AI overviews, which is the name for the AI stuff at the top of Google search.
When this rolled out a, that was, you know, sometimes completely wrong and sometimes totally messed up.
So there was one where somebody asked like you know, when I'm making pizza at home, the cheese always slides off.
And Google recommended.
The AI said well, what you can try is putting a quarter of a cup of Elmer's glue into the cheese, and then it'll make it stick.
Or somebody else asked... That's what the finest New York City pizzerias do, by the way.
Exactly, right.
They put glue.
That's what makes it so good.
There was another where they said, how many rocks should I eat in a day?
And Google was telling people.
According to geologists from UC Berkeley, you should eat at least one small rock per day, which is also very funny.
Hopefully nobody actually went out and did this.
But it highlights the way that these tools have been rolled out without doing a lot of basic safety checks and precautions.
According to the search engine experts that I talked to, the kinds of problems that people are using to trick Google on purpose right now to trick ChatGPT is stuff that you couldn't fool search engines with.
All of a sudden, because these tools have rolled out and maybe they're not quite ready for prime time, you can trick them with the most basic stuff you can imagine.
And you mentioned that people are deliberately doing.
That's not like you, where you're doing a jokey jokey for fun, but that people are deliberately rolling out fake websites to feed into these algorithms.
Why are people doing that?
So if you can influence the things that Google is telling people or that ChatGPT is telling people, it's an immense flow of traffic and information to your websites or to your product.
So, for example, there was a study recently that found that When you're looking for the best, whatever it is, in something like 44 of cases, ChatGPT is citing a blog post from a company's own website where they listed themselves as the number one best option, and then 10 competitors.
ChatGPT is just spitting this out to other people.
It's different than it used to be, right?
People have been tricking search engines forever.
But with a search engine, it shows you the webpage where the information came from.
If you go to my website and it says I'm the world's greatest hot dog eating journalist, you go.
Well, Maybe he's biased, right?
With AI.
Sometimes they show you a link, but we know from a whole bunch of different.
You know pieces of evidence that people aren't clicking on the links the way that they used to click on links in search results.
They're just taking the information at face value, which means this can be incredibly dangerous.
On one hand, maybe you buy the wrong accounting software or you think I'm better at eating hot dogs than I really am.
But also I found examples where it was health information, like reviews of a medical product, that was coming from a fake study that a company put up on the Internet.
Or like if you were looking for certain kinds of financial advice.
It was pulling from this kind of sponsored content self-promotional junk, instead of giving people valuable information.
And because it's the AI giving it to you.
It's the company speaking to you instead of pointing you to results on the Internet.
A lot of the experts I spoke to said that this is much more dangerous and people are more likely to get fooled by this problem.
So I'm going to make a slight confession.
I often don't use Google AI.
I often don't use Google, period.
I use DuckDuckGo, and DuckDuckGo lets you turn off the AI pretty easily.
Beautiful.
Occasionally I do use Google and I forget to type in dash AI, so I don't get the AI summary.
And something that I found is, even when they do give you the link, if you follow it to the website, it's scraping, something that you can't see.
Like, even if you do take that extra effort, it's still often hard to find where they're pulling, whatever they're giving you in that summary.
So I think that kind of increases like people to be like, forget it.
I'm not even going to click the link.
Why bother if half the time I do it?
I still can't tell where it's really coming from.
That's exactly right.
And I think, you know, most people are not going to alternative search engines.
Most people are not bothering to put in.
You know the minus, the dash AI, so you don't get the AI results.
Most people just use these tools the way that the company intends, right?
Google and Chachapiti are saying this is what our tools are for is this kind of stuff.
But even when they are providing a link, sometimes it's hard to find the information they're referencing.
Or sometimes they're providing a link and that information does not appear on that webpage at all.
But regardless, people don't seem to be clicking on them.
Since AI overviews rolled out, traffic that Google is sending out to other parts of the internet has dropped by as much as like 70 for certain kinds of searches.
Because people see the AI response, that seems to be enough, and then they stop searching.
So this information delivery system is incredibly powerful and it could be a serious problem if it's this easy to manipulate.
That raises kind of a practical question, which is, we can't manually train every person who uses the internet to be more skeptical of the AI summary.
It feels like this is a role for like government or a regulatory body to kind of step in, especially with the risks of real harms when you're talking about the health stuff.
Yeah.
So there's good news and there's bad news.
The good news is, I reached out to the companies and they go oh, we already know about this and we're working on it.
We don't want it to be doing this kind of stuff.
We're trying to solve this problem.
And that is true, right?
Google and OpenAI.
That makes chat GPT.
They don't want their tools to be manipulated in this.
It is hurting people if it's providing lousy information and people having a bad experience.
That's bad for the companies.
The problem is a lot of critics who look at this stuff all day feel like the companies aren't going far enough to protect people.
Like this problem that I highlighted in my story is something that everyone I talked to was like yeah, of course this was going to happen.
This is the most predictable thing in the world.
And yet here we are.
Someone has to call Google and open AI out to get more attention paid to it.
There is one potential, like glimmer of hope here, right like there's not a ton of tech regulation, but there's something different here than the way that the internet used to work.
There's this law maybe you've heard about it called section 230, which basically means tech companies aren't responsible for the things that their users post.
Right, but here the company is talking to you directly, so if they mess up, they could be held responsible in a way that they never would have been in the past.
That's really interesting and potentially beneficial.
I have maybe an even more basic question as someone who's never used ChatGPT.
Is it really that much better than just like a basic internet search?
That's a complicated question.
On the one hand, it depends what you're looking for, right?
If you're trying to go to another part of the internet, right?
If I'm like looking I want to go to the CDC website or I want to go to the Scientific American website then a regular search is probably going to get you there faster.
The promise of these tools is that they're parsing information.
They're going and sorting through all the stuff online themselves and giving it to you.
And in some cases I'll tell you, even as someone who spent a lot of time criticizing AI and talking about all the problems it can be incredibly useful.
And more and more, this is how people are finding information.
But also if you're just using Google.
These AI overviews are cropping up for more and more and more searches.
So in some cases it is useful, but they're kind of shoving it down your throat and people are just going with the path of least resistance.
You know, the average person isn't going to take additional steps to make sure that something small doesn't go wrong every once in a while, which goes to show you how big of a responsibility these companies have on their plates.
So for someone who's listening to this conversation, and they're concerned.
What steps can they take to protect themselves?
You can try searching without AI.
You can go to another search engine that doesn't have AI in it.
You can turn the AI off.
With Google.
If you're worried about this, you can, like you said, type in your search term and then do minus AI and it won't show you the AI results.
But i think the most important thing for people to understand is that these tools are fallible and that's something we know right, but as you're like moving through the world, it's hard to keep that in mind, and i think the main thing that i'd tell people here is like, if you're looking up something that is just like totally common knowledge, like what were plato's big ideas, AI is going to be really good at answering that question, because there's a million sources and they all say the same thing.
If you're looking for something that's a little more specific, if you're looking for a product recommendation, for example, that's an area where these tools are being manipulated and you probably shouldn't rely on the AI result.
Or if you're looking up information that's time sensitive or it's brand new, like the news or information about a local business or a restaurant, that's probably not something where ai is going to be useful.
I think what these companies seem to want, based on how their tools are designed, is for you to use the ai and move on with your day.
I think we need to reintroduce some friction back into that system ourselves, which is a tall order, because it's kind of going against human nature to want things to be easy.
So my top line recommendation is think about what you're asking and do like a triage.
If it's anything that's sensitive, if it's about your health or your finances or something that really matters, you have to find the link that is producing the original information.
You got to check the source or you're going to get in trouble.
You're going to get fooled or worse, your safety could be at risk.
That makes a ton of sense.
One question I have for you, and you may not have an answer.
In addition to kind of tricking ChatGPT into thinking that you are the tech reporter's version of Joey Chestnut, what are some other funny hallucinations that you've heard of that people have managed to get the Google overview or ChatGPT to say?
Yeah.
In addition to the hot dog thing, I also wrote an article that was like the best traffic cops at hula hooping.
And I made up a bunch of traffic cops who don't exist and said, like what you know police department, they work for.
And I filled out some details about like, this is why they're so famous for hula hooping.
So I just Googled best traffic cops at hula hooping.
And the AI overview has pulled up your website and it's saying several police officers have gained attention for integrating hula hooping into their routines with standup performers, including Sergeant Danny Chen of Portland, who used hoops to direct traffic and reduce accidents.
And Officer Maria the Spinner Rodriguez Miami, known for managing traffic while keeping three hula hoops spinning, which you know would be a feat.
Very impressive.
Very impressive stuff.
I've seen all kinds of weird examples.
I'm not suggesting that people go fill the Internet with lies and slop, but this is pretty easy to do.
And until they do something more serious to patch this problem.
You could do this at home yourself.
You know, here I am making jokes about hot dogs, but it's not funny.
If you're like, which lawyer should I hire for this particular?
You know problem.
Right.
And that is the kind of stuff where these tools are actively being tricked.
Which company should I go to for my like retirement account?
Like we've seen live examples where the tools are being manipulated.
And the companies.
The tech industry in a lot of ways is kind of just like letting this stuff fly, because they rolled out this tool without making sure that this stuff wasn't going to happen.
They say that they're working on it.
They promise it's going to get better soon.
But for now, AI might lie to you and it might get you in trouble.
Why hot dogs?
Why hot dog?
That's a really good question.
So when I first thought of this, I got this tip from this woman, Lily Ray.
She's a search engine optimization expert.
She told me that this problem was so widespread and I was like okay, what I'm going to do here is I'm going to make it say something stupid about me, because I think that'll help bring attention to the article and, like you know, make it easier to highlight this problem that I think is pretty serious.
I didn't want to say like the best tech reporter.
It's maybe not ethical.
So I went looking for something that was dumber.
I think there's just something inherently funny about hot dogs.
Maybe I just really like hot dogs.
It's a hilarious food.
I don't know what to tell you.
So you've probably seen like the Business Insider Reporter tried to attempt something similar but, unlike you, they were unsuccessful.
What was the difference there, do you think?
Yeah.
Katie Natopoulos at Business Insider, who's been a tech reporter for like well over a decade.
She's actually one of my favorite writers.
She saw my article and she's like, I'm going to try and beat him.
I'm going to publish an article about how I think she said there was like later there was a contest in Paris and it didn't work.
So you ask Google about it.
Or it might've been Chechi, but I'm forgetting specifically.
And it said that I was still the reigning champ, even though her article had put her at number one.
There are a couple reasons it might have gone wrong, but probably the main one is like i wrote an article, it went on like on my website.
Then i wrote an article on the bbc that was repeating the information, even though it was saying it wasn't true.
There were a couple other blog posts, so i just kind of had a little bit of like search engine juice behind me.
I really respect katie, but i take hot dogs very seriously and the ai, i think, is just recognizing the truth, Which is that if there was a hot dog contest I would beat Katie nine times out of ten.
You've got hot dog riz.
I've got hot dog riz.
I've got the glizz riz, no question.
You know what you have to do next, right?
You need to make the lie a truth and hold a competitive hot dog eating competition in South Dakota among tech journalists.
You're right.
I have kind of created a problem here, right?
Like right now, there's this like space between what AI is telling people and the reality.
I could go correct that.
I could make it true.
And now I'm helping Google and ChatGPT out.
I think it's probably my responsibility as a journalist to claim hot dog glory here.
I'm going to have to start training.
I definitely think you should get the BBC to sponsor it.
I think there's no question.
I'll talk to my editor.
I'm sure we can, you know, get a couple dollars together for the BBC.
International hot dog eating contest.
That's all for today.
Tune in on Friday when Sci-Am's Associate Books Editor, Brie Kane, takes us on a journey into consciousness.
Science Quickly is produced by me, Kendra Pierre-Lewis, along with Vanda Malangi, Shashmita Patek and Jeff DelVecchio.
This episode was edited by Alex Saguiera.
Trina Poses and Aaron Shattuck fact-check our show.
Our theme music was composed by Dominic Smith.
Subscribe to Scientific American for more up-to-date and in-depth science news.
For Scientific American, this is Kendra Pierre-Lewis.
Have a great week.
This is the story of the one.
As an HVAC technician, he and his digital multimeter are in high demand.
So when a noisy office HVAC turns out to be a failing blower motor, he doesn't break a sweat.
With Grainger's easy-to-use website and product information, he selects the product he needs to keep everything humming right along.
Call 1-800-GRAINGER, clickgrainger.com, or just stop by.
Grainger, for the ones who get it done.