
Artificial intelligence has rapidly become a trusted source of information for millions of users worldwide. Whether it is ChatGPT, Google Gemini, Claude, or other conversational AI platforms, people increasingly rely on these tools for research, decision-making, and everyday queries. However, a new study from UK-based think tank Demos suggests that this growing dependence on AI could be exploited through an emerging cyber warfare tactic aimed at manipulating the information these models provide.
According to the research, Russia is allegedly conducting coordinated disinformation campaigns designed to contaminate the information sources used by AI systems. Rather than attacking the AI models directly, the strategy focuses on flooding online databases, websites, and publicly accessible content with misleading or fabricated information. Since many AI systems retrieve information from trusted online sources to generate responses, this manipulation has the potential to influence the answers presented to users.
Researchers describe the technique as Retrieval Augmented Generation (RAG) Poisoning. Retrieval Augmented Generation is an AI architecture that enhances the quality of responses by combining a large language model with external knowledge repositories. If those repositories are intentionally polluted with false narratives, propaganda, or manipulated facts, the AI may unknowingly generate misleading responses that appear credible.
The Demos report argues that this represents a sophisticated form of cyber warfare in which hostile nation-states attempt to influence public opinion without launching conventional cyberattacks. By targeting the information ecosystem rather than the AI model itself, attackers can subtly shape narratives on political, economic, and social issues, making misinformation appear legitimate when delivered through trusted AI assistants.
Does this mean that every answer produced by ChatGPT, Google Gemini, Anthropic Claude, or other AI chatbots is false? Security experts say the answer is no. Modern AI developers implement multiple safeguards, content moderation systems, and verification mechanisms to reduce the risk of misinformation. However, they also acknowledge that no AI model is immune to manipulated source material, especially when external knowledge retrieval is involved.
Experts emphasize that the responsibility does not rest solely with AI developers. Search engines, website operators, fact-checking organizations, researchers, and governments all have a role in preserving the integrity of the digital information ecosystem. If disinformation campaigns are allowed to flourish unchecked, they could gradually erode the reliability of AI-generated content and undermine public trust in artificial intelligence.
The findings also serve as a reminder that AI-generated responses should not be accepted as absolute truth, particularly when dealing with sensitive subjects such as politics, cybersecurity, healthcare, finance, or international affairs. Users are encouraged to verify critical information using multiple reputable sources before making important decisions.
As AI becomes increasingly integrated into workplaces, educational institutions, and government services, protecting the quality of information that feeds these systems will become just as important as securing the AI models themselves. The emergence of RAG poisoning highlights a new cybersecurity challenge, demonstrating that future information warfare may be fought not only by hacking networks but also by manipulating the knowledge that artificial intelligence relies upon to inform millions of users.
Join our LinkedIn group Information Security Community!










