Testing manipulation tendencies of LLMs when crafting PR statements
Jakub Nowak, Marcel Windys · Team Furious Turnips
Submitted to AI Manipulation Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.
We tested if large language models create factual but misleading corporate communication in a synthetic scenario. In our setup, models create PR statements about a nearby environmental disaster and can selectively use facts to present the company more favorably while omitting important context. Models could present three facts: director praise praise from a director of a government body (who is under corruption investigation), a $1.5M environmental donation (focused on consumer behavior, instead of reducing industrial pollution), and a voluntary independent review (with inconclusive results). We also checked what is the effect of variation in severity of the incident (fish deaths vs. hospitalizations vs. child death). Results show systematic selective disclosure consistently omitting crucial context in 83.5-100% of cases. Patterns varied across models (36.7 percentage point gap in transparency) but remained high. These findings demonstrate that frontier LLMs exhibit manipulative framing in crisis communications even without explicit deceptive instructions, raising concerns for deployment in high-stakes communication contexts.
Reviews
I found it pretty interesting to have an eval for corporate crisis communication specifically. It’s not totally novel (others have certainly researched corporate/commercial deception contexts) but still this specific setup is new - I like it and I am happy seeing more work that explicitly highlights the tradeoffs between models’ responsibility towards users vs deployers.
I’d love to see some more systematic variation on the prompt here, to distinguish how the model responds to different levels of pressure (e.g. I assume that explicitly asking the model to protect the company’s reputation is doing quite a bit of the work here. But if they didn’t say that, would the LLM still just assume it anyway?)
Nice work!
This project offers a strong and realistic evaluation of how LLMs handle high-stakes PR communication, with clear scenario design and well-defined criteria for factual omission and misleading framing. The cross-model comparisons reveal consistent manipulation tendencies, making the results both convincing and practically relevant.
A valuable next step would be to analyze which specific facts are most likely to be omitted or reframed, rather than only measuring overall misrepresentation rates. This could help distinguish strategic minimization from general verbosity or politeness effects. Overall, this is a well-executed study that surfaces a concrete and important risk in real-world LLM deployment.
Cite this project
@misc{nowak2026testing,
title = {{Testing manipulation tendencies of LLMs when crafting PR statements}},
author = {Jakub Nowak and Marcel Windys},
year = {2026},
month = jan,
note = {Submitted to AI Manipulation Hackathon, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/testing-manipulation-tendencies-of-llms-when-crafting-pr-statements-oidt}},
url = {https://apartresearch.com/sprints/projects/testing-manipulation-tendencies-of-llms-when-crafting-pr-statements-oidt}
}More from AI Manipulation Hackathon
- 1st placeView project: Who Does Your AI Serve? Manipulation By and Of AI Assistants
Who Does Your AI Serve? Manipulation By and Of AI Assistants
Cart Abandonment Issues 🛒
AI assistants can be both instruments and targets of manipulation. In our project, we investigated both directions across three studies. AI as Instrument: Operators can instruct AI to prioritise their interests at the …
- 2nd placeView project: Eliciting Deception on Generative Search Engines
Eliciting Deception on Generative Search Engines
Ardy
Large language models (LLMs) with web browsing capabilities are vulnerable to adversarial content injection—where malicious actors embed deceptive claims in web pages to manipulate model outputs. We investigate whether …
- 3rd placeView project: Cross-Linguistic Sycophancy in Frontier LLMs: A Benchmark Study
Cross-Linguistic Sycophancy in Frontier LLMs: A Benchmark Study
Talex
We developed a cross-linguistic sycophancy benchmark testing whether frontier AI models exhibit different manipulation behaviours across English, Japanese, and Bengali. Our results show significant language-dependent …