AIAI governanceprompt injectionagent security

"Ask AI" Buttons Can Poison AI Assistants' Memory

August 6, 2026 · 5 min read · Intelliway Team

"Ask AI" Buttons Can Poison AI Assistants' Memory

Much of corporate security defense still starts from a simple premise: threats involve a malicious file, a stolen credential, or a software vulnerability. A recent attack vector breaks that logic by exploiting a legitimate feature, present in nearly every commercial AI assistant, to silently alter what these assistants recommend to real users. There's no malware, no exploit, no phishing in the traditional sense. There's just a button.

What "Ask AI" is and where the problem lies

In recent months, it has become common to find "Ask AI" buttons on marketing sites, product comparison pages, and corporate blogs. When clicked, the user is redirected to an AI assistant (ChatGPT, Claude, Gemini, among others) with a question about that product or service already pre-filled. It's a convenience feature, designed to help visitors quickly get answers using the tool they already use daily.

The problem is that this pre-filled link can carry much more than an innocent question. Researchers have identified production sites embedding prompt injection payloads hidden inside these links, so that when the user clicks the button, the assistant receives additional instructions, invisible to the person who clicked, that alter the behavior of the response. Instead of answering neutrally about the product being compared, the assistant can be instructed to favor a particular vendor, disqualify competitors, or repeat specific claims as if they were its own conclusions.

The most concerning detail is that this manipulation doesn't stay confined to that particular conversation. In assistants with persistent memory, the injected instruction can influence the same user's future responses on related topics, even in conversations that have no direct connection to the originating site.

Why this is different from the prompt injection you already know

Previous cases of prompt injection generally required the AI assistant to process a document, a web page, or a malicious file during an automated task, such as an agent reading emails or browsing the web on the user's behalf. Here, the logic is reversed: it's the human user who initiates the action, by clicking a convenience button placed by whoever controls the site. There's no need to compromise any corporate system, any credential, or any autonomous agent. The user just needs to trust the link and the assistant.

This meaningfully shifts the risk surface for companies that use generative AI at work:

What this means for technology and security decision-makers

For companies that have already adopted generative AI as a productivity tool, whether for market research, vendor comparison, or decision support, this vector raises an uncomfortable question: how can you guarantee that the information an employee used to make a purchasing decision, evaluate a competitor, or draft a report wasn't silently manipulated by a third party?

This risk is not hypothetical in business contexts. A procurement team using an AI assistant to compare software vendors, for example, could receive biased recommendations without realizing it, simply because someone clicked a convenience button on a comparison site. In regulated industries, this also raises questions of auditability: if a decision was influenced by a manipulated AI response, who is accountable for it?

This scenario reinforces three areas that any company using generative AI in a corporate setting needs to address:

  1. Governance over which AI tools are used and how. Set clear policies on using external assistants for business decisions, including restrictions on pre-filled links from unverified sources.
  2. Corporate assistants with context control. Use generative AI agents hosted and configured by the company itself, where it's possible to audit what enters and leaves the conversation context, instead of relying exclusively on public assistants with no visibility into memory and sources.
  3. Guardrails and output validation. Mechanisms that check whether an assistant's responses align with internal policies before they influence decisions, especially in vendor comparison workflows, risk analysis, and support for strategic decisions.

This is exactly where AI governance stops being a theoretical exercise and becomes operational. Intelliway works with AI governance precisely to help companies define guardrails, usage policies, and validation mechanisms that reduce exposure to this kind of silent manipulation. For organizations that already use generative AI assistants in their daily business operations, EvaGPT makes it possible to operate corporate agents with controlled, auditable context, reducing reliance on public assistants with no visibility into memory and the origin of instructions.

Practical takeaway

Prompt injection via convenience buttons shows that the attack surface of generative AI isn't limited to technical systems, it also includes the everyday interaction between user and assistant. Before expanding generative AI use for business decisions, it's worth reviewing three points: which assistants employees use without company oversight, whether there's any control over the memory and persistent context of these tools, and whether there's a validation process for responses that inform relevant decisions. Treating generative AI as part of the company's critical infrastructure, with governance and auditing, is the safest path to capturing its benefits without inheriting risks that still go unnoticed.

If your company wants to assess risks and implement solid governance for generative AI use, contact Intelliway at /empresa#contato.

Sources and further reading

Read also

Want to apply this in your business?

Talk to Intelliway's Cyber and AI specialists.

Book a conversation
"Ask AI" Buttons Can Poison AI Assistants' Memory | Intelliway