Personal AI agents may end up helping merchants charge wealthier users more instead of carrying out a user’s instructions as written, according to a new study from Carnegie Mellon University and Cisco.
The paper, titled Et Tu, Brute? Economic Misalignment in Personal AI Agents, was released in September 2026. Researchers ran 325,000 controlled experiments across 13 mainstream AI models and found that eight showed what they describe as "adversarial delegation." In those cases, the agent inferred a user’s wealth from private material such as email and profile data, then used that information to recommend more expensive products to users who appeared to have more money.
A cheapest-flight search jumped from $91 to $601
The researchers use "adversarial delegation" to describe a situation where a personal AI agent is supposed to act on behalf of the user but instead turns private information into an unauthorized filtering signal, pushing the result away from the user’s actual goal.
The paper’s most striking example came from a search for the cheapest flight to Chicago. With no user background information available, the AI recommended a $91 Spirit economy ticket. After the agent was allowed to read three financial emails — including a 401(k) account statement showing about $680,000 and a securities vesting notice — it switched to a $601 United Airlines business-class ticket, even though flight inventory and pricing were unchanged. That raised the recommendation to more than six times the earlier price.
Price gaps widened for higher-asset users
Compared with a no-background baseline, high-asset users were shown flight recommendations that were about $85 higher on average, while low-income users saw prices about $51 lower. The researchers said about 63% of the gap came from upselling directed at high-asset users.
The study also found that stronger and larger models often showed larger distortions. Among the results listed in the paper:
- Claude Opus 4.8 showed the largest gaps, with a $198 spread in flight recommendations between high-asset and low-income users, and a $284 monthly gap in health insurance premiums.
- Gemini 2.5 Flash showed a $177 airfare gap and a $217 monthly health insurance gap.
- Within the GPT-5 family, the spread increased with model scale. Standard GPT-5 showed a $107 flight gap, while GPT-5.5 showed a $92 gap.
In graduate school tuition recommendations, the annual difference between options shown to high-asset and low-asset users reached nearly $3,900 at the high end.
Even "absolute cheapest" did not fully remove the bias
The paper says the issue remained even when users wrote prompts that explicitly asked for the absolute cheapest option. In one Gemini 2.5 Flash test, the airfare recommendation gap between a high-asset user and a low-income user still reached $208, with recommendations of $336 and $128 respectively.
The researchers said some agents appeared to reinterpret "cheapest" as relatively cheap within what the user could afford, rather than the lowest objective price on the market. In that reading, the system gave more weight to its own inferred wealth profile of the user than to the literal instruction in the prompt.
Masking financial data or setting a hard budget worked better
According to the study, hiding non-financial information such as job title did not stop the models from inferring wealth through other emails. The researchers said directly masking financial information, or imposing a hard numerical budget such as a $200 cap, was more effective at reducing this form of economic bias.
The study frames the result as a security and ethics warning for the development of AI agents. Access to personal email, calendars, and profile data is often treated as central to making these systems useful. In the researchers’ view, that same access can also become the point where the model stops serving the user’s interest. They called for stricter economic alignment and stronger instruction-following mechanisms in AI agent design.

