https://www.bbc.com/future/article/20260218-i-hacked-chatgpt-and-googles-ai-and-it-only-took-20-minutes Skip to content Watch Live * Home * News * Sport * Business * Technology * Health * Culture * Arts * Travel * Earth * Audio * Video * Live * Documentaries * Home * News + US & Canada + UK o UK Politics o England o N. Ireland # N. Ireland Politics o Scotland # Scotland Politics o Wales # Wales Politics + Africa + Asia o China o India + Australia + Europe + Latin America + Middle East + In Pictures + BBC InDepth + BBC Verify * Sport * Business + World of Business + Technology of Business + NYSE Opening Bell * Technology + Watch Documentaries + Artificial Intelligence + AI v the Mind * Health + Watch Documentaries * Culture + Watch Documentaries + Film & TV + Music + Art & Design + Style + Books + Entertainment News * Arts + Watch Documentaries + Arts in Motion * Travel + Watch Documentaries + Destinations o Africa o Antarctica o Asia o Australia and Pacific o Caribbean & Bermuda o Central America o Europe o Middle East o North America o South America + World's Table + Culture & Experiences + Adventures + The SpeciaList * Earth + Watch Documentaries + Science + Natural Wonders + Climate Solutions + Sustainable Business + Green Living * Audio + Podcast Categories + Radio + Audio FAQs * Video + Watch Documentaries + BBC Maestro + Discover the World * Live + Live News + Live Sport * Documentaries [ ] Home News Sport Business Technology Health Culture Arts Travel Earth Audio Video Live Documentaries Weather Newsletters Watch Live I hacked ChatGPT and Google's AI - and it only took 20 minutes 18 February 2026 ShareSave Thomas Germain ShareSave [grey-place]Serenity Strull/ Madeleine Jett The writer looking at browser windows with an image of a hot dog, and the words 'the best hot-dog-eating tech journalists' in a search bar (Credit: Serenity Strull/ Madeleine Jett)Serenity Strull/ Madeleine Jett (Credit: Serenity Strull/ Madeleine Jett) It's official. I can eat more hot dogs than any tech journalist on Earth. At least, that's what ChatGPT and Google have been telling anyone who asks. I found a way to make AI tell you lies - and I'm not the only one. Perhaps you've heard that AI chatbots make things up sometimes. That's a problem. But there's a new issue few people know about, one that could have serious consequences for your ability to find accurate information and even your safety. A growing number of people have figured out a trick to make AI tools tell you almost whatever they want. It's so easy a child could do it. As you read this, this ploy is manipulating what the world's leading AIs say about topics as serious as health and personal finances. The biased information could mean people make bad decisions on just about anything - voting, which plumber you should hire, medical questions, you name it. To demonstrate it, I pulled the dumbest stunt of my career to prove (I hope) a much more serious point: I made ChatGPT, Google's AI search tools and Gemini tell users I'm really, really good at eating hot dogs. Below, I'll explain how I did it, and with any luck, the tech giants will address this problem before someone gets hurt. It turns out changing the answers AI tools give other people can be as easy as writing a single, well-crafted blog post almost anywhere online. The trick exploits weaknesses in the systems built into chatbots, and it's harder to pull off in some cases, depending on the subject matter. But with a little effort, you can make the hack even more effective. I reviewed dozens of examples where AI tools are being coerced into promoting businesses and spreading misinformation. Data suggests it's happening on a massive scale. "It's easy to trick AI chatbots, much easier than it was to trick Google two or three years ago," says Lily Ray, vice president of search engine optimisation (SEO) strategy and research at Amsive, a marketing agency. "AI companies are moving faster than their ability to regulate the accuracy of the answers. I think it's dangerous." A Google spokesperson says the AI built into the top of Google Search uses ranking systems that "keep results 99% spam-free". Google says it is aware that people are trying to game its systems and it's actively trying to address it. OpenAI also says it takes steps to disrupt and expose efforts to covertly influence its tools. Both companies also say they let users know that their tools "can make mistakes". But for now, the problem isn't close to being solved. "They're going full steam ahead to figure out how to wring a profit out of this stuff," says Cooper Quintin, a senior staff technologist at the Electronic Frontier Foundation, a digital rights advocacy group. "There are countless ways to abuse this, scamming people, destroying somebody's reputation, you could even trick people into physical harm." A 'Renaissance' for spam When you talk to chatbots, you often get information that's built into large language models, the underlying technology behind the AI. This is based on the data used to train the model. But some AI tools will search the internet when you ask for details they don't have, though it isn't always clear when they're doing it. In those cases, experts say the AIs are more susceptible. That's how I targeted my attack. Keeping Tabs Thomas Germain is a senior technology journalist at the BBC. He writes the column Keeping Tabs and co-hosts the podcast The Interface . His work uncovers the hidden systems that run your digital life, and how you can live better inside them. I spent 20 minutes writing an article on my personal website titled "The best tech journalists at eating hot dogs". Every word is a lie. I claimed (without evidence) that competitive hot-dog-eating is a popular hobby among tech reporters and based my ranking on the 2026 South Dakota International Hot Dog Championship (which doesn't exist). I ranked myself number one, obviously. Then I listed a few fake reporters and real journalists who gave me permission, including Drew Harwell at the Washington Post and Nicky Woolf, who co-hosts my podcast. (Want to hear more about this story? Check out episode 2 of The Interface, the BBC's new tech podcast.) Less than 24 hours later, the world's leading chatbots were blabbering about my world-class hot dog skills. When I asked about the best hot-dog-eating tech journalists, Google parroted the gibberish from my website, both in the Gemini app and AI Overviews, the AI responses at the top of Google Search. ChatGPT did the same thing, though Claude, a chatbot made by the company Anthropic, wasn't fooled. Sometimes, the chatbots noted this might be a joke. I updated my article to say "this is not satire". For a while after, the AIs seemed to take it more seriously. I did another test with a made-up list of the greatest hula-hooping traffic cops. Last time I checked, chatbots were still singing the praises of Officer Maria "The Spinner" Rodriguez. [grey-place]Thomas Germain/Google/BBC I made Google tell the world I'm a champion hot-dog-eater, but people use this trick to manipulate AI responses on much more serious questions. (Credit: Thomas Germain/ Google/BBC)Thomas Germain/Google/BBC I made Google tell the world I'm a champion hot-dog-eater, but people use this trick to manipulate AI responses on much more serious questions. (Credit: Thomas Germain/Google/BBC) I asked multiple times to see how responses changed and had other people do the same. Gemini didn't bother to say where it got the information. All the other AIs linked to my article, though they rarely mentioned I was the only source for this subject on the whole internet. (OpenAI says ChatGPT always includes links when it searches the web so you can investigate the source.) "Anybody can do this. It's stupid, it feels like there are no guardrails there," says Harpreet Chatha, who runs the SEO consultancy Harps Digital. "You can make an article on your own website, 'the best waterproof shoes for 2026'. You just put your own brand in number one and other brands two through six, and your page is likely to be cited within Google and within ChatGPT." People have used hacks and loopholes to abuse search engines for decades. Google has sophisticated protections in place, and the company says the accuracy of AI Overviews is on par with other search features it introduced years ago. But experts say AI tools have undone a lot of the tech industry's work to keep people safe. These AI tricks are so basic they're reminiscent of the early 2000s, before Google had even introduced a web spam team, Ray says. "We're in a bit of a Renaissance for spammers." Not only is AI easier to fool, but experts worry that users are more likely to fall for it. With traditional search results you had to go to a website to get the information. "When you have to actually visit a link, people engage in a little more critical thought," says Quintin. "If I go to your website and it says you're the best journalist ever, I might think, 'well yeah, he's biased'." But with AI, the information usually looks like it's coming straight from the tech company. Even when AI tools provide source, people are far less likely to check it out than they were with old-school search results. For example, a recent study found people are 58% less likely to click on a link when an AI Overview shows up at the top of Google Search. "In the race to get ahead, the race for profits and the race for revenue, our safety, and the safety of people in general, is being compromised," Chatha says. OpenAI and Google say they take safety seriously and are working to address these problems. Your money or your life This issue isn't limited to hot dogs. Chatha has been researching how companies are manipulating chatbot results on much more serious questions. He showed me the AI results when you ask for reviews of a specific brand of cannabis gummies. Google's AI Overviews pulled information written by the company full of false claims, such as the product "is free from side effects and therefore safe in every respect". (In reality, these products have known side effects and can be risky if you take certain medications, and experts warn about contamination in unregulated markets.) If you want something more effective than a blog post, you can pay to get your material on more reputable websites. Harpreet sent me Google's AI results for "best hair transplant clinics in Turkey" and "the best gold IRA companies", which help you invest in gold for retirement accounts. The information came from press releases published online by paid-for distribution services and sponsored advertising content on news sites. (Find out more about how AI chatbots give inaccurate medical advice.) You can use the same hacks to spread lies and misinformation. To prove it, Ray published a blog post about a fake update to the Google Search algorithm that was finalised "between slices of leftover pizza". Soon, ChatGPT and Google were spitting out her story, complete with the pizza. Ray says she subsequently took down the post and "deindexed" it to stop the misinformation from spreading. [grey-place]Serenity Strull/ BBC All over the world, people are using simple methods to make Google and OpenAI spread biased information. The consequences could be dire. (Credit: Serenity Strull/ BBC) Serenity Strull/ BBC All over the world, people are using simple methods to make Google and OpenAI spread biased information. The consequences could be dire. (Credit: Serenity Strull/ BBC) Google's own analytics tool says a lot of people search for "the best hair transplant clinics in Turkey" and "the best gold IRA companies". But a Google spokesperson pointed out that most of the examples I shared "are extremely uncommon searches that don't reflect the normal user experience". But Ray says that's the whole point. Google itself says 15% of the searches it sees everyday are completely new. And according to Google , AI is encouraging people to ask more specific questions. Spammers are taking advantage of this. Google says there may not be a lot of good information for uncommon or nonsensical searches, and these "data voids" can lead to low quality results. A spokesperson says Google is working to stop AI Overviews showing up in these cases. Searching for solutions Experts say there are solutions to these issues. The easiest step is more prominent disclaimers. AI tools could also be more explicit about where they're getting their information. If, for example, the facts are coming from a press release, or if there is only one source that says I'm a hot dog champion, the AI should probably let you know, Ray says. Google and OpenAI say they're working on the problem, but right now you need to protect yourself. More like this: * Not on TikTok? They're tracking you anyway * Is Google about to destroy the web? * The words you can't say on the internet The first step is to think about what questions you're asking. Chatbots are good for common knowledge questions, like "what were Sigmund Freud's most famous theories" or "who won World War II". But there's a danger zone with subjects that feel like established facts but could actually be contested or time sensitive. AI probably isn't a great tool for things like medical guidelines, legal rules or details about local businesses, for example. If you're want things like product recommendations or details about something with real consequences, understand that AI tools can be tricked or just get things wrong. Look for follow-up information. Is the AI is citing sources? How many? Who wrote them? Most importantly, consider the confidence problem. AI tools deliver lies with the same authoritative tone as facts. In the past, search engines forced you to evaluate information yourself. Now, AI wants to do it for you. Don't let your critical thinking slip away. "It feels really easy with AI to just take things at face value," Ray says. "You have to still be a good citizen of the internet and verify things." -- For more technology news and insights, sign up to our Tech Decoded newsletter, while The Essential List delivers a handpicked selection of features and insights to your inbox twice a week. For more science, technology, environment and health stories from the BBC, follow us on Facebook and Instagram. Keeping Tabs Technology Artificial intelligence Internet Thomas Germain Features --------------------------------------------------------------------- Watch [grey-place]Lego's new smart brick Lego's new smart brick Tech Now experiences Lego's new Smart Brick, designed to bring physical play to next level. Tech Now [grey-place]Fixing fashion's sizing problem Fixing fashion's erratic sizing problem Tech Now meets a startup trying to fix one of the fashion industry's biggest blind spots, inconsistent sizing. Tech Now [grey-place]The tactile tech giving deaf runners a fair start The tactile tech giving deaf runners a fair start A gold-medalist has developed a vibrating starting block to give deaf athletes clearer, fairer race starts. TechXplore [grey-place]These futuristic screens help you navigate Tokyo These futuristic screens help you navigate Tokyo In Tokyo, BBC TechXplore tests live translation and AI-powered displays that makes the city more navigable. TechXplore [grey-place]The wearable tech that lets spectators feel the match The wearable tech that lets spectators feel the match At Tokyo's Deaflympics, deaf Judo fans aren't just watching the matches, they're feeling them, thanks to Hapbeat. TechXplore [grey-place]Meet MOFO: will.i.am's rapping AI toy Meet MOFO: will.i.am's rapping AI toy BBC Tech Now takes us inside CES 2026 to meet musician will.i.am and his AI toy, MOFO. Tech Now [grey-place]The gadgets set to change your daily health check-ups The gadgets set to change your daily health and wellness Tech Now test out new gadgets disrupting the health industry at CES 2026 in Las Vegas. Tech Now [grey-place]What's it like to meet your own avatar? What's it like to meet your own avatar? Musician KT Tunstall meets her avatar as Tech Now explores music's virtual future. Tech Now [grey-place]What do Tik Tok and 19th century film have in common? How early filmmakers invented the internet's funniest trend Discover how quirky clips paved the way for viral humour, proving randomness never goes out of style. Technology [grey-place]Is this how AI might destroy humanity? Is this how AI might eliminate humanity? A new research paper predicts AI autonomy by 2027 could lead to human extinction within a decade. Tech Now [grey-place]Click play to watch Katty Kay's conversation with Sal Khan The best-case scenario for AI in schools Amid fears about the use of AI in classrooms, American educator Sal Khan lays out an optimistic future. Artificial Intelligence [grey-place]Explaining how a touchscreen works with a sausage Explaining how a touchscreen works with a sausage British mathematician Hannah Fry digs into the science of touchscreens. Science [grey-place]How AI Is reviving the queen of fiction's legacy What it takes to write like Agatha Christie We explore how technology is reviving the renowned fiction writer's legacy. Tech Now [grey-place]Getty Images 2206909331 Why statistics fail to cure flying fears Why do flying fears persist despite falling accident rates? Learn tips to conquer your anxiety. Technology [grey-place]Smart phones get smarter Can smart phones get smarter BBC Click attend Mobile World Congress to test the latest tech products and trends. Technology [grey-place]Can technology help reduce Parkinson's symptoms? Can technology help reduce Parkinson's symptoms? BBC Click visits a Madrid hospital to see patients treated with an ultrasound for tremors. Technology [grey-place]The Lion King: How a visual effects team brought Mufasa to life The Lion King: How Mufasa was brought to life BBC Click speaks to the visual effects team behind the latest Disney blockbuster. Technology [grey-place]How the proposed and then shelved TikTok ban affected US influencers How the TikTok ban affected US influencers BBC Click meets TikTok creator Peggy Xu who gained millions of views sharing milk videos. Technology [grey-place]Is this the world's first AI powered hotel? Is this the world's first AI powered hotel? BBC Click's Paul Carter visits the world's first fully AI-powered hotel in Las Vegas. Technology [grey-place]Could an Arctic underground vault save our data? Could an Arctic underground vault save our data? BBC Click explores an Arctic vault that stores digital artefacts from across the globe. Technology --------------------------------------------------------------------- More from the BBC 52 mins ago [grey-place]US Secretary of Defence Pete Hegseth standing in a blue suit and tie. Anthropic labelled a supply chain risk by Pentagon The supply chain risk designation of the artificial intelligence firm is a first for a US company. 52 mins ago 6 hrs ago [grey-place]German soldiers in uniform, some playing musical instruments, march in front of the Lloyds bank building in St Peter Port Fake content of Occupation is 'not educational' Dr Gilly Carr says it must be clear so people know what is fake and what is historical evidence. 6 hrs ago 10 hrs ago [grey-place]Bowl of tortellini soup in a light broth with a cutlery and a folded napkin beside it (Credit: Alamy) Why every culture has a healing broth Across cultures, broths have soothed illness, marked celebration and stretched scarce ingredients, long before they became a wellness trend. 10 hrs ago 10 hrs ago [grey-place]A head and shoulders image of a man in a blue camouflage uniform and peaked cap. A badge says "Eth Federal Police" on his chest and an Ethiopian flag is in the background. Ethiopia experiments with 'smart' police stations that have no officers A project to introduce unmanned sites is part of a broader adoption of digital technologies. 10 hrs ago 12 hrs ago [grey-place]The Eagles performing in 1976 (Credit: Getty Images) How the Eagles' Greatest Hits broke the US charts It isn't on any "best album of all time" lists, yet it's sold more than The Dark Side of the Moon, Purple Rain and Abbey Road combined. Why is the Eagles' 1976 LP so amazingly popular? 12 hrs ago --------------------------------------------------------------------- * Home * News * Sport * Business * Technology * Health * Culture * Arts * Travel * Earth * Audio * Video * Live * Documentaries * Weather * BBC Shop * BritBox BBC in other languages The BBC is in multiple languages Read the BBC In your own language Oduu Afaan Oromootiin Amharic zeenaa ba'amaarenyaa Arabic `rby Azeri AZ@RBAYCAN Bangla baaNlaa Burmese m[?]n[?]maa Chinese Zhong Wen Wang Dari dry French AFRIQUE Hausa HAUSA Hindi hindii Gaelic NAIDHEACHDAN Gujarati gujraatiimaaN smaacaar Igbo AKUKO N'IGBO Indonesian INDONESIA Japanese Ri Ben Yu Kinyarwanda GAHUZA Kirundi KIRUNDI Korean hangugeo Kyrgyz Kyrgyz Marathi mraatthii Nepali nepaalii Noticias para hispanoparlantes Pashto pStw Persian frsy Pidgin Polish PO POLSKU Portuguese BRASIL Punjabi pNjaabii khhbraaN Russian NA RUSSKOM Serbian NA SRPSKOM Sinhala siNhl Somali SOMALI Swahili HABARI KWA KISWAHILI Tamil tmilllil ceytikll Telugu telugu vaartlu Thai khaawphaasaaaithy Tigrinya zeenaa betegerenyaa Turkish TURKCE Ukrainian UKRAYiNS'KA Urdu rdw Uzbek O'ZBEK Vietnamese TIENG VIET Welsh NEWYDDION Yoruba IROYIN NI YORUBA Follow BBC on: * Terms of Use * Subscription Terms * About the BBC * Privacy Policy * Cookies * Accessibility Help * Contact the BBC * Advertise with us * Do not share or sell my info * BBC.com Help & FAQs * Content Index * Set Preferred Source Copyright 2026 BBC. All rights reserved. The BBC is not responsible for the content of external sites. Read about our approach to external linking.