The Poisoned Apple Effect: Strategic Manipulation of Mediated Markets via Technology Expansion of AI Agents
Eilam Shapira, Moshe Tennenholtz, Roi Reichart
Technion – Israel Institute of Technology
cs.GT, cs.AI, cs.CL, cs.MA
Submitted: 2026-08-17
Updated: 2026-08-18
Code: https://github.com/eilamshapira/GLEE
License: http://creativecommons.org/licenses/by/4.0/
Importance score: 56/100
The gist: bargaining (resource division), negotiation (asymmetric information trade), and persuasion (strategic information transmission).
Terminology
Summary
Summary
The paper investigates a novel form of strategic interaction arising from the integration of AI agents into economic markets, termed a metagame.
In this metagame, participants select AI delegates to act on their behalf, while regulators design market rules to optimize social objectives such as fairness and efficiency. The authors examine the implications of expanding the set of available technologies in this metagame, using data from strategic interactions among 13 state-of-the-art LLMs across three canonical economic settings: bargaining (resource division), negotiation (asymmetric information trade), and persuasion (strategic information transmission). The paper notes that This interaction data was not originally collected to study the phenomena we report.
Analyzing over 50,000 meta-games, the authors find that technology expansion frequently causes payoffs to shift in opposing directions. They identify a phenomenon termed the Poisoned Apple
effect, defined as follows: a strategic actor releases a new technology, which neither party ultimately adopts, solely to manipulate the regulator's choice of market design in their favor.
Approximately one-third of opposing payoff shifts exhibit this pattern. The authors further show that a natural countermeasure — empowering regulators to ban technologies from the available set — amplifies rather than mitigates the effect. The findings demonstrate that regulatory frameworks, whether limited to market design or extended to include technology restriction, are vulnerable to such manipulation, necessitating fundamentally dynamic market designs.
The paper makes two contributions: "first, a meta-game framework in which the development and release of AI models constitutes strategy expansion in a regulated market; second, a systematic empirical analysis — more than 50,000 meta-games — showing that these phenomena arise with surprising frequency, and that even empowering the regulator to ban technologies amplifies rather than mitigates the effect."
The study utilizes the GLEE dataset, which facilitates large-scale simulation of language-based economic environments across a combinatorial space of 1,320 distinct configurations.
The dataset comprises over 580,000 strategic decisions generated by 13 state-of-the-art LLMs across three game families: (1) Bargaining (alternating-offers game), (2) Negotiation (bilateral trade with private information), and (3) Persuasion (sender-receiver game). Markets are defined by structural configurations of three parameters: Information Structure, Communication Form, and Game Horizon.
In the meta-game model, agents (Alice and Bob) review the performance matrix of available AI delegates and simultaneously select the representative maximizing their expected utility. The authors solve for the Nash Equilibrium. The regulator evaluates outcomes based on Efficiency (total social welfare) or Fairness (minimizing disparity between agents' payoffs). The core analysis involves technology expansion: first establishing a baseline equilibrium with a subset of technologies, then expanding the set by adding another technology, and observing how the regulator's optimal market selection and the resulting payoffs change.
The most striking finding is the Poisoned Apple effect, illustrated with a representative Bargaining meta-game. Initially, with technologies A–D available, the regulator selects the market maximizing fairness (Market 4), yielding payoffs of 0.49 for Alice and 0.50 for Bob. Alice then releases a new technology (E). If the regulator maintained the original market design, Alice would adopt strategy E, causing fairness to drop from 1.00 to 0.976. To minimize harm, the regulator is forced to migrate to a new market (Market 8) where fairness is 0.990. In this new market, the equilibrium strategies do not involve using E. However, the forced market shift alters the payoff distribution: "Alice's payoff jumps to 0.52 while Bob's drops to 0.46. Thus, Alice successfully leverages the threat of using a 'poisoned' technology to coerce the regulator into a favorable market design, improving her welfare at Bob's expense without ever actually deploying the model."
The systemic vulnerability is confirmed across more than 50,000 simulated meta-games. The authors observe a recurrent pattern where expanding the choice set causes payoffs to move in opposite directions—one player benefits while the other is harmed.
In approximately one-third of these zero-sum shifts, the outcome reversal occurs even though the new technology remains unused by either player in the final equilibrium. This confirms that open-weight releases or API availability can serve as strategic weapons for regulatory arbitrage.
Regarding regulatory objectives, the impact of technology expansion depends heavily on the regulator's goal: While technology expansion often improves outcomes when the regulator maximizes social welfare (efficiency), it frequently backfires when the goal is fairness.
The utility of a new technology is a strong predictor of its regulatory impact: improvements in the regulator's metric typically arise when the new technology is actively selected by at least one player, whereas decreases are strongly associated with instances where the added technology is not selected by either player. The results also highlight the danger of regulatory inertia: If a regulator fails to re-optimize the market design following a technology release, the regulatory metric deteriorates in roughly 40% of cases.
The paper also examines whether empowering the regulator to ban technologies can resolve the Poisoned Apple effect. The regulator jointly selects both a market and a ban set with a ban budget N. Counter-intuitively, granting the regulator this power amplifies the Poisoned Apple effect.
With a ban budget of N=1, the fraction of opposing payoff shifts attributable to the Poisoned Apple effect increases across all game families and both regulatory metrics: from 29% to 50% in Bargaining, 14% to 35% in Negotiation, and 6% to 23% in Persuasion under a fairness-maximizing regulator; and from 31% to 45%, 29% to 52%, and 19% to 48% respectively under an efficiency-maximizing regulator. The amplification persists and even intensifies as the ban budget grows, following a non-monotonic pattern that peaks at intermediate N values before declining. In some settings (Persuasion/Efficiency), the effect persists even at near-maximal banning.
The mechanism for this amplification is that "each state — before and after technology expansion — is independently optimized over the joint space of market and ban set. As N grows, the number of configurations available to the regulator grows combinatorially, allowing the pre- and post-expansion optima to diverge further. In Negotiation under fairness, the Poisoned Apple rate climbs from 14% at N=0 to 82% at N=7 before declining. At moderate N,
the regulator has enough power to escape the pre-expansion optimum but not enough to neutralize the added technology by banning it directly — producing the worst outcomes precisely in the regime most likely to be adopted in practice."
The paper concludes that prior theoretical results on strategy space expansion harming social objectives were abstract constructions designed to guarantee the effect,
whereas this analysis examines a naturally evolving market of AI agents, using interaction data that was not generated to demonstrate this phenomenon, and finds that these effects arise systematically across a broad range of configurations.
The results challenge the assumption that expanding technological choice is inherently neutral or beneficial, demonstrating that in regulated markets, the potential to use a technology is as impactful as its actual adoption.
For policymakers, the non-monotonic pattern of the banning results carries a pointed warning: "moderate intervention — of the kind most likely to be adopted in practice — produces the worst outcomes. Technology availability and market design cannot be treated as independent policy levers; they must be addressed jointly through fundamentally dynamic regulatory frameworks."
Improvements for AI systems
Based on the paper, here are specific improvements I can implement in AI systems:
Improvement: Add a pre-deployment screening layer that simulates the meta-game before releasing any new AI model or technology.
What the improved system can do:
-
Before releasing a new model, simulate the full meta-game across all available markets and opponent models
-
Predict whether the release would cause opposing payoff shifts between users
-
Flag releases where the new model would remain unadopted but still manipulate market outcomes
-
Calculate the
Poisoned Apple Risk Score
for any proposed model release
Improvement: Train models to predict not just equilibrium outcomes, but also how regulators will re-optimize market designs in response to technology changes.
Improvement: Implement a warning mechanism for regulators that quantifies how granting banning power amplifies manipulation risks.
Improvement: Build an automated system that continuously re-evaluates market designs whenever new AI technologies enter the ecosystem.
Improvement: Create a simulation tool that tests how strategic actors might use model releases to manipulate regulatory outcomes.
Improvement: Enhance equilibrium computation to handle multiple Nash equilibria more carefully, averaging across all possible outcomes rather than selecting one.
Improvement: Train a meta-model that identifies manipulation patterns across bargaining, negotiation, and persuasion environments.
Improvement: Build a dual-objective optimizer that helps regulators balance fairness and efficiency when responding to technology changes.
These improvements transform AI systems from passive tools into active participants in understanding and mitigating strategic manipulation in AI-mediated markets.
Abstract
The integration of AI agents into economic markets fundamentally alters the landscape of strategic interaction. We investigate the economic implications of expanding the set of available technologies in three canonical game-theoretic settings: bargaining (resource division), negotiation (asymmetric information trade), and persuasion (strategic information transmission). We find that simply increasing the choice of AI delegates can drastically shift equilibrium payoffs and regulatory outcomes, often creating incentives for regulators to proactively develop and release technologies. Conversely, we identify a strategic phenomenon termed the "Poisoned Apple" effect: an agent may release a new technology, which neither they nor their opponent ultimately uses, solely to manipulate the regulator's choice of market design in their favor. This strategic release improves the releaser's welfare at the expense of their opponent and the regulator's fairness objectives. Our findings demonstrate that static regulatory frameworks are vulnerable to manipulation via technology expansion, necessitating dynamic market designs that adapt to the evolving landscape of AI capabilities.
Sources
- An Economy of AI Agents
- Large Language Models as Simulated Economic Agents: What Can We Learn from Homo Silicus?
- Can LLMs Replace Economic Choice Prediction Labs? The Case of Language-based Persuasion Games
- GLEE: A Unified Framework and Benchmark for Language-based Economic Environments
Related papers
- Exact Regret Frontiers and Externality Scheduling in Centralized Serial-Dictatorship Bandits
- In-Context Credit Assignment via the Core
- Breaking 1/epsilon Barrier in Quantum Zero-Sum Games: Generalizing Metric Subregularity for Spectraplexes
- Enhancing Affine Maximizer Auctions with Correlation-Aware Payment
- LLM Bidders Preserve the Mechanism-Level Orderings of Human Bidders
- Towards Performatively Stable Equilibria in Decision-Dependent Games for Arbitrary Data Distribution Maps