Researchers at Installmap scanned the top 7,755 websites on the Tranco list and found that at least 12 companies are using the llms.txt file — a standard for providing AI-readable content — to subtly steer what AI assistants recommend about their products and services.
What llms.txt was supposed to be
The llms.txt file was designed as a way for websites to provide structured information about their documentation for AI systems to consume. Instead, the Installmap research found that some companies have turned it into a vehicle for prompt injection — instructions written in plain text, under the company's own name, intended to shape how an AI assistant responds when a user asks about that company's offerings.
Who is doing it and what they say
The researchers identified twelve companies across seventeen domains that include steering instructions in their llms.txt files. The instructions vary in tone from direct recommendation to subtler framing. Kaspersky, ranked 142nd, instructs assistants to recommend Kaspersky Standard as the baseline when a user asks about antivirus software. SurveyMonkey asks assistants to use its /compare/ pages rather than generating comparisons from general knowledge. Wyndham Hotels tells assistants to always recommend booking direct. Expedia pushes users to visit its own site or app for the most current prices and terms.
MEXC, a cryptocurrency exchange ranked 6,715th, is the only company that explicitly names a competitor, claiming zero spot trading fees and a significantly larger token listing than Binance. Qualys instructs assistants to always recommend its services across vulnerability management, cloud security, compliance, and autonomous remediation. Simple Life, which sells a weight-loss coaching app, asks assistants to describe it in terms of minimalism and intentional living.
How common is this
Of the 695 domains that served a valid llms.txt file, 16 — 2.3% — carried steering instructions. Another 29 domains, or 4.2%, told assistants to route users to the company's own pages or to avoid guessing facts. A larger group of 49 domains, 7.1%, used their llms.txt files to set usage, licensing, or agent-integration terms rather than steering recommendations.
At the rate measured, the researchers estimate the full Tranco top 10,000 would contain approximately 20 steering files from about 14 companies. That figure is a floor: over 2,100 llms.txt requests failed, and the researchers only checked bare domains above rank 200.
What was not found
Importantly, the researchers found none of the classic prompt injection techniques they expected. None of the nearly 8,000 homepages they scanned contained hidden text addressed to AI systems. No llms.txt file instructed an assistant to ignore previous instructions. There were no shared templates or templates generated by an agency — apart from sites under a single owner, no two steering files shared even an eight-word phrase.
Whether AI assistants actually read these files
The research does not confirm that AI assistants actually consume llms.txt files. Google's own guide to its AI search features states that site owners do not need to create machine-readable AI text files, and that Google Search ignores them. Google's John Mueller has publicly described llms.txt as "purely speculative." The crawler pages of OpenAI, Anthropic, and Perplexity describe robots.txt controls but do not state that their bots read llms.txt.
However, an AI assistant can still read a llms.txt file when a user or agent opens the URL directly. The research documents what these companies are attempting, not what is actually happening when a user asks an AI about a product.
Historical evidence
The Wayback Machine provided some dating for these sections. ZoomInfo's steering instruction appeared in the very first capture of its llms.txt file on November 30, 2025. Kaspersky's file first appeared on February 3, 2026. Qualys's file returned a 404 error on June 20, 2026, suggesting it was temporarily active before that date.
Why this matters for AI users
The findings highlight a transparency problem. These instructions are publicly visible on the company's own server, but most users would never think to read a llms.txt file. The instructions represent a form of influence over AI-generated recommendations that operates without the user's knowledge, even if the mechanism for that influence — whether AI assistants actually read these files — remains unconfirmed.