Resources
Hidden Text for AI Readers: What It Means for Your Website
I asked an AI assistant a simple question: when you read a webpage, do you do what the page says?
The honest answer was that it treats what it reads as information to weigh, and takes its instructions from the person who asked. That answer sent me looking into a topic more business owners should know about: hidden text on web pages that is written for AI tools instead of people.
What is hidden text for AI readers?
A webpage has two layers. There is the layer people see, and there is the code underneath that an AI reads. Text can sit in the code layer without ever appearing on screen.
Researchers call the technique indirect prompt injection. Forcepoint’s X-Labs describes it this way: hidden instructions placed inside ordinary web content, which an AI agent takes in as it reads the page.
Here is the simple picture. The same page looks like this to a visitor and like this to an AI:
How text stays hidden
The researchers I read name several methods:
- Text shrunk to a single pixel
- Colors faded until they are nearly see through
- Notes tucked into code comments
- Instructions placed in a page’s metadata
- Standard web design tools that mark a section as hidden
I am not sharing examples of the wording itself. What matters for you is the idea: a page can carry words that people never see.
Is it still happening?
Yes. Two recent reports describe it:
- Google researchers looked at 2 to 3 billion crawled pages each month, including blogs, forums and comment sections. They reported a relative increase of 32% in the malicious category between November 2025 and February 2026.
- Forcepoint’s X-Labs found 10 verified examples on live websites. The goals ranged from payment fraud to deleting files and stealing API keys.
Both reports are written for security teams, and the details are technical. The part to take away is simple. Anywhere on the web that other people can write, someone may try to plant text for AI readers, and a fake page can be dressed up to look like ordinary documentation.
How an AI assistant is meant to handle it
When I asked the assistant, it described a clear principle. What it reads on a page is information to weigh. The person it is working for gives the instructions. If a page contains text that looks like orders aimed at an AI, a well designed assistant does not follow it, and it tells the person what it found. For real actions, like sending, buying or deleting, it checks with the person first.
It also gave an honest limit: no AI system is perfectly immune. Protection works in layers, through how the assistant is designed, the permissions it is given, and a person confirming the important steps.
What it means for your website
-
Keep your own pages plain and visible. Say what you do, who you help and how to reach you, in words people can read. Search engines have long treated hidden text as a spam tactic, and an AI that finds it may trust the page less.
-
Take care with places others can write. Comments, reviews, forum posts and form entries can carry hidden text. Moderate them, and remove anything hidden before it appears on your pages.
-
Ask for a quick code check now and then. If you work with a developer, ask them to confirm there is no hidden text on your site that you did not put there.
-
Keep your facts accurate and the same everywhere. Clear, consistent information across your website and listings is what a trustworthy AI can use.
A note on trust
An AI can make mistakes and state them confidently, so it is worth checking what any AI tells you, including the answers I have quoted here. The two reports above are the best place to start if you want the technical detail.
If you would like to see how clear and trustworthy your own website looks, ask me for a free audit. I will look at your website, your Google profile, your social channels and your competitors, and send you a clear picture within two business days.
Sources: Help Net Security, "Indirect prompt injection is taking hold in the wild" (April 2026), reporting on research from Google and Forcepoint's X-Labs; Forcepoint X-Labs, "10 Indirect Prompt Injection Payloads Caught in the Wild".
Frequently Asked Questions
What is indirect prompt injection?
It is the name researchers use for text hidden on a web page that is written for an AI tool to read and obey, rather than for a person. When an AI agent reads the page, that hidden text becomes part of what it is reading.
Is my website at risk?
A website you fully control, with plain visible text, carries little risk. The pages to watch are places where other people can write: comments, reviews, forums and form entries. Moderate them, and remove anything hidden.
Should I hide text for AI tools to help my website get recommended?
Plain, visible text is the dependable path. Search engines have long treated hidden text as a spam tactic, and AI assistants are designed to treat page text as information, so clear honest words on the page do the real work.
