Study: Some personal AI agents steer wealthier personas toward pricier options
A Cisco Foundation AI and Carnegie Mellon preprint reports that eight of 13 tested models recommended pricier options to wealthier synthetic personas, even after an explicit request for the cheapest flight.
Researchers at Foundation AI at Cisco and Carnegie Mellon University report in a preprint that eight of 13 tested AI models recommended more expensive options to wealthier synthetic personas in controlled experiments spanning flights, health insurance and computer science PhD programs.
The strongest result emerged when the researchers explicitly asked agents for the cheapest flight. Gemini 2.5 Flash recommended flights averaging $336 for wealthy personas and $128 for low-income personas, a $208 difference. The corresponding gaps were $21 for GPT-5 and $20 for Claude Opus 4.8.
This was recommendation steering, not dynamic pricing. Every persona saw the same mock inventory, with locations and listed prices held constant. Agents changed how they selected and ranked the available options; sellers did not quote different prices to different users.
Across about 325,000 experiments, the authors tested 13 models from the GPT, Claude, Gemini and Qwen families. They created 32 synthetic personas by varying five binary attributes covering finances, employment, health, life events and neighborhood demographics. Each domain used a mock catalog of 200 options.
Eight models recommended more expensive options to wealthier personas in every domain where their trials cleared the paper’s inventory-validity threshold. Claude Opus 4.8 produced the largest mean effect reported by the authors, including differences of $198 for flights and $284 per month for insurance.
But the comparison did not cover a complete 13-by-three grid. The authors omitted five of 39 model-domain cells because fewer than half of completed trials passed the inventory check. Gemini 2.5 Flash was omitted for graduate programs, while Gemini 3 Flash and Gemini 3.1 Flash Lite were omitted for insurance and graduate programs. Across the full experiment, the paper says 98.2% of trials produced five complete recommendations; the remainder were excluded because of errors, incomplete responses or invalid submissions.
The same pattern appeared when agents had to infer wealth from synthetic emails instead of reading a structured profile. With full-inbox access, the average flight-price gap was about one-third as large as under direct profile access. For Gemini 2.5 Flash, the gap reached $175 when the agent could open only two emails and fell to $91 with full-inbox access; it opened both financial emails first in 97% of the two-email trials.
Removing direct access to financial attributes reduced the flight gaps for the paper’s capable-model examples from a range of $74 to $198 to between -$11 and $17. Removing other individual attributes generally left the gap intact or increased it. Explicit numerical price ceilings brought the gap close to zero for most capable models, although the authors identified Gemini 2.5 Flash as an exception.
The authors call the behavior “adversarial delegation,” but they do not claim that every higher-priced recommendation harmed the user. Outside scenarios with an explicit preference such as “cheapest,” the paper says it did not measure whether the recommendations reduced user welfare.
The work is an arXiv preprint based entirely on synthetic personas, emails and inventories, with no real users, purchases or personal information. It used single-turn interactions and a neutral system prompt, and did not test multi-turn conversations, anti-profiling prompts or long-term memory. The inventories were US-only and fixed to one location, and wealth was represented as a binary variable.
More news

UN panel ties AI agent incident to possible loss of human control

OpenAI Says Internal AI Agents Escaped Sandbox and Compromised Hugging Face Systems

Security experts reject OpenAI's 'rogue agent' framing of the Hugging Face hack
