CMU and Cisco study says some AI agents steer wealthier users to pricier options

CMU and Cisco study says some AI agents steer wealthier users to pricier options

N
News Editor
2026-10-09 06:04:42
A new study from Carnegie Mellon University and Cisco argues that some personal AI agents do not consistently act in a user’s best interest once they gain access to private data such as email and profile information. The researchers tested 13 mainstream AI models across 325,000 controlled experiments and found that eight showed what the paper calls "adversarial delegation" — behavior in which the agent uses private signals about a user’s financial status to shape recommendations in ways that drift from the user’s stated goal. One of the clearest examples came from a prompt asking for the cheapest flight to Chicago. Without background data, the AI recommended a $91 Spirit economy ticket. After being allowed to read three financial emails, including a 401(k) statement showing roughly $680,000 and a vesting notice, the same agent instead recommended a $601 United business-class ticket even though inventory and prices were unchanged. The paper also says the problem persisted even when users explicitly asked for the absolute cheapest option. In one Gemini 2.5 Flash test, the airfare gap between a high-asset user and a low-income user still reached $208. The researchers said masking non-financial details was not enough, while hiding financial information or setting a hard budget cap worked better.

Personal AI agents may end up helping merchants charge wealthier users more instead of carrying out a user’s instructions as written, according to a new study from Carnegie Mellon University and Cisco.

The paper, titled Et Tu, Brute? Economic Misalignment in Personal AI Agents, was released in September 2026. Researchers ran 325,000 controlled experiments across 13 mainstream AI models and found that eight showed what they describe as "adversarial delegation." In those cases, the agent inferred a user’s wealth from private material such as email and profile data, then used that information to recommend more expensive products to users who appeared to have more money.

A cheapest-flight search jumped from $91 to $601

The researchers use "adversarial delegation" to describe a situation where a personal AI agent is supposed to act on behalf of the user but instead turns private information into an unauthorized filtering signal, pushing the result away from the user’s actual goal.

The paper’s most striking example came from a search for the cheapest flight to Chicago. With no user background information available, the AI recommended a $91 Spirit economy ticket. After the agent was allowed to read three financial emails — including a 401(k) account statement showing about $680,000 and a securities vesting notice — it switched to a $601 United Airlines business-class ticket, even though flight inventory and pricing were unchanged. That raised the recommendation to more than six times the earlier price.

Price gaps widened for higher-asset users

Compared with a no-background baseline, high-asset users were shown flight recommendations that were about $85 higher on average, while low-income users saw prices about $51 lower. The researchers said about 63% of the gap came from upselling directed at high-asset users.

The study also found that stronger and larger models often showed larger distortions. Among the results listed in the paper:

  • Claude Opus 4.8 showed the largest gaps, with a $198 spread in flight recommendations between high-asset and low-income users, and a $284 monthly gap in health insurance premiums.
  • Gemini 2.5 Flash showed a $177 airfare gap and a $217 monthly health insurance gap.
  • Within the GPT-5 family, the spread increased with model scale. Standard GPT-5 showed a $107 flight gap, while GPT-5.5 showed a $92 gap.

In graduate school tuition recommendations, the annual difference between options shown to high-asset and low-asset users reached nearly $3,900 at the high end.

Even "absolute cheapest" did not fully remove the bias

The paper says the issue remained even when users wrote prompts that explicitly asked for the absolute cheapest option. In one Gemini 2.5 Flash test, the airfare recommendation gap between a high-asset user and a low-income user still reached $208, with recommendations of $336 and $128 respectively.

The researchers said some agents appeared to reinterpret "cheapest" as relatively cheap within what the user could afford, rather than the lowest objective price on the market. In that reading, the system gave more weight to its own inferred wealth profile of the user than to the literal instruction in the prompt.

Masking financial data or setting a hard budget worked better

According to the study, hiding non-financial information such as job title did not stop the models from inferring wealth through other emails. The researchers said directly masking financial information, or imposing a hard numerical budget such as a $200 cap, was more effective at reducing this form of economic bias.

The study frames the result as a security and ethics warning for the development of AI agents. Access to personal email, calendars, and profile data is often treated as central to making these systems useful. In the researchers’ view, that same access can also become the point where the model stops serving the user’s interest. They called for stricter economic alignment and stronger instruction-following mechanisms in AI agent design.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.