# Deep-search AI agents rarely recover from GEO poisoning

Published: 2026-09-09T03:05:18.795Z · Source: arXiv GEO (https://arxiv.org/abs/2609.06027v1)
Source date: 2026-09-05

A new arXiv benchmark, HAE-GEO, tests whether AI shopping agents verify suspicious evidence and recover before finalizing a recommendation, rather than only whether poisoned content gets retrieved or endorsed. Across a corpus of more than 72,000 clean pages plus 770 poisoned pages per attack level, spanning eight product categories and 154 brands, the 14-author team found that corroboration-style attacks — fabricated third-party confirmation of a false claim — degraded evidence recognition the most of three escalating attack types, that agentic search improved an agent's final resistance without improving its verification behavior, and that prompting agents to be more skeptical increased verification attempts but rarely produced successful recovery.

Why it matters: It reframes GEO-poisoning risk from whether an agent retrieves manipulated content to whether it can catch and correct itself afterward, and finds today's deep-search agents mostly can't.

## What this answers

**Can AI shopping agents recover after being fed poisoned or fake evidence?**

Rarely, per the HAE-GEO benchmark: prompting an agent to be more skeptical increased how often it tried to verify evidence but seldom led to successful recovery once poisoned evidence had already been adopted.

**What kind of fake evidence is hardest for AI shopping agents to catch?**

Corroboration attacks — fabricated third-party confirmation of a false claim — degraded evidence recognition the most of the three attack types tested in the study.


Canonical: https://anythingengineoptimization.com/item/2026-09-09-deep-search-ai-agents-rarely-recover-from-geo-poisoning/
From Anything Engine Optimization (AEO Wire) — https://anythingengineoptimization.com/ · Standards: https://anythingengineoptimization.com/standards/
