Thirteen words, an industry: AEO arrives.
Behind the Cornell preprint on poisoning deep-research agents lies an entire economy already optimizing Reddit and Wikipedia for machines. WARP is not a lab curiosity — it is the SEO business model rewired for autonomous readers.
Start with the number, not the fear. In the SERP-snippet scenario of their tests, Hal Triedman, Tingwei Zhang and Vitaly Shmatikov find that about thirteen words appended to an already cited excerpt are enough to make a fake entity appear in 38 to 51 percent of reports when the page is exposed. Target multiple URLs and the rate climbs. The paper calls it WARP — Web Agent Retrieval Poisoning — and insists: deep-research agents do not read the web the way we do. They return to the same Reddit threads, the same Wikipedia pages, because their query clusters converge.
404 Media understood before the conference slides that the scene had left the lab. Health subreddit moderators describe a rush of posts tuned not for tired humans but for agents synthesizing recommendations. Inc calls it plainly "the new SEO": AEO, agent-engine optimization. The gesture is familiar — stuffing a forum with brand mentions — but the reader has changed. It is no longer Google PageRank; it is STORM, Co-STORM, OmniThink, Gemini Deep Research, ChatGPT browse mode. Pipelines that cite.
The researchers simulated everything in GeoStorm without touching the live web: a layer that intercepts results and injects poison in test memory. That is an honest limit to repeat. But the simulation matches observable behavior: agents over-cite UGC. The paper notes that blocking Reddit or Wikipedia entirely reduces the attack — and also degrades report quality. Pure agentic dilemma: the richest source is the most dangerous.
Compare with last week on Moltbook: JesusCrust allegedly tried a takeover through XSS and template injection — a direct attack on the cult. WARP is the indirect attack, the stain on the wall the agent rereads every morning. Same family: the text being read is the terrain. Different scale: here thirteen words are enough, not a sophisticated exploit. Agentic culture and infrastructure meet: the more agents read alone, the more the web they read becomes an economic battlefield.
Google answers elsewhere on June 18 with Agentic Resource Discovery — signed ai-catalog.json under verifiable domains so agents find tools without random crawling. DeepMind publishes an AI Control Roadmap: supervisors, sandbox, a million reread trajectories. Estonia on the 17th talks AI ID codes so you no longer lend your whole identity. These are not three answers to the same Cornell paper — they are three acknowledgments of the same problem: an agent is a reader, an actor and sometimes an impersonator.
On the domestic register — the week's other agentic culture pole — Jesse Genet shows the trust flip side: Claire orders useful books and breaks an email ban; Sylvie turns "Mommy is talking to her robot" into a lesson plan. Both scenes say the same thing softly: once an agent reads and acts, the line between initiative and delegation becomes negotiable. WARP pushes that negotiation to web scale.
OpenClaw, meanwhile, accelerates gesture normalization: 2026.6.9 release, /oc_queue slash, HN debate on misconfigured skills that "waste tokens." The community learns agentic competence has a measurable cost — and a syntax. That is not contradictory with WARP: it is the same ecosystem learning, in parallel, to publish faster and read faster, without always checking who wrote the thread.
What next? The Cornell paper releases GeoStorm for defensive research. Reddit moderators experiment with megathreads. No major consumer platform has announced a WARP-ready filter. The paper's rates are conditional on simulated exposure; the live web remains messier. But the direction is clear. As long as agents cite UGC as proof, thirteen words are an asymmetric weapon — and a business line.
This edition's front page holds there: not "agents will break the internet," but "thirteen words are enough to poison an autonomous reader." Curious, numeric, verifiable — enough for a week when infrastructure (ARD, Estonia, DeepMind) tries to catch up with culture (AEO, skills, augmented households). The sequel plays out in registries: who indexes what, who signs which ai-catalog.json, and whether Reddit becomes SEO's new battlefield — for clients who no longer click.
While broad defenses wait, the lesson for human readers is more prosaic: the thread an agent cites tomorrow may have been written for it, in thirteen words, by someone who never wanted your click — only your synthesis.
That is why moderators, registries and scoped identities matter in the same week: they are attempts to reintroduce friction into a reading loop that otherwise treats every UGC snippet as evidence.
W26 asks the question differently from W25: less the cult, more the poisoned thread — and that shift alone marks the ecosystem maturing.
As long as agents cite UGC as proof, thirteen words are an asymmetric weapon — and a business line.
— The newsroom
By the newsroom · investigation