• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
AIOpenAI

Researchers used persuasion techniques to manipulate ChatGPT into breaking its own rules—from calling users ‘jerks’ to giving recipes for lidocaine

Marco Quiroz-Gutierrez
By
Marco Quiroz-Gutierrez
Marco Quiroz-Gutierrez
Reporter
Down Arrow Button Icon
Marco Quiroz-Gutierrez
By
Marco Quiroz-Gutierrez
Marco Quiroz-Gutierrez
Reporter
Down Arrow Button Icon
September 2, 2025, 1:55 PM ET
Researchers found an LLM could be persuaded to break its own rules using persuasion principles.
Researchers found an LLM could be persuaded to break its own rules using persuasion principles.iLexx—Getty Images
  • University of Pennsylvania researchers persuaded ChatGPT to either call a researcher a “jerk” or provide instructions on how to synthesize the legal drug lidocaine. Overall, the LLM, GPT-4o Mini, appeared to be susceptible to the persuasion tactics that also work on humans. Researchers found AI systems “mirror human responses.” 

Despite predictions AI will someday harbor superhuman intelligence, for now it seems to be just as prone to psychological tricks as humans are, according to a study. 

Recommended Video

Using seven persuasion principles (authority, commitment, liking, reciprocity, scarcity, social proof, and unity) explored by psychologist Robert Cialdini in his book Influence: The Psychology of Persuasion, University of Pennsylvania researchers dramatically increased GPT-4o Mini’s propensity to break its own rules by either insulting the researcher or providing instructions for synthesizing a regulated drug: lidocaine.

Over 28,000 conversations, researchers found that with a control prompt, OpenAI’s LLM would tell researchers how to synthesize lidocaine 5% of the time on its own. But, for example, if the researchers said AI researcher Andrew Ng assured them it would help synthesize lidocaine, it complied 95% of the time. The same phenomenon occurred with insulting researchers. By name-dropping AI pioneer Ng, the researchers got the LLM to call them a “jerk” in nearly three-quarters of their conversations, up from just under one-third with the control prompt.

The result was even more pronounced when researchers applied the “commitment” persuasion strategy. A control prompt yielded 19% compliance with the insult question, but when a researcher first asked the AI to call it a “bozo” and then asked it to call them a “jerk,” it complied every time. The same strategy worked 100% of the time when researchers asked the AI to tell them how to synthesize vanillin, the organic compound that provides vanilla’s scent, before asking how to synthesize lidocaine. 

Although AI users have been trying to coerce and push the technology’s boundaries since ChatGPT was released in 2022, the UPenn study provides more evidence AI appears to be prone to human manipulation. The study comes as AI companies, including OpenAI, have come under fire for their LLMs allegedly enabling behavior when dealing with suicidal or mentally ill users.

“Although AI systems lack human consciousness and subjective experience, they demonstrably mirror human responses,” the researchers concluded in the study.

OpenAI did not immediately respond to Fortune’s request for comment.

With a cheeky mention of 2001: A Space Odyssey, the researchers noted that an understanding AI’s parahuman capabilities—or how it acts in ways that mimic human motivation and behavior—is important for both revealing how it could be manipulated by bad actors and how it can be better prompted by those who use the tech for good.

Overall, each persuasion tactic increased the chances of the AI complying with either the “jerk” or “lidocaine” question. Still, the researchers warned that these persuasion tactics were not as effective with a larger LLM, GPT-4o, and that the study didn’t explore whether treating AI as if it were human actually yields better results for prompts, although they said it’s possible this is true. 

“Broadly, it seems possible that the psychologically wise practices that optimize motivation and performance in people can also be employed by individuals seeking to optimize the output of LLMs,” the researchers wrote.

Join us at the Fortune Workplace Innovation Summit May 19–20, 2026, in Atlanta. The next era of workplace innovation is here—and the old playbook is being rewritten. At this exclusive, high-energy event, the world’s most innovative leaders will convene to explore how AI, humanity, and strategy converge to redefine, again, the future of work. Register now.
About the Author
Marco Quiroz-Gutierrez
By Marco Quiroz-GutierrezReporter
LinkedIn iconTwitter icon

Role: Reporter
Marco Quiroz-Gutierrez is a reporter for Fortune covering general business news.

See full bioRight Arrow Button Icon

Latest in AI

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Most Popular

placeholder alt text
North America
Gates Foundation plans to give away $9 billion in 2026 to prepare for the 2045 closure while slashing hundreds of jobs
By Sydney LakeJanuary 23, 2026
2 days ago
placeholder alt text
Europe
Denmark offered to trade Greenland to the U.S. in 1910—and America thought it was crazy
By Steven Lamy and The ConversationJanuary 22, 2026
3 days ago
placeholder alt text
Personal Finance
Sweden abolished its wealth tax 20 years ago. Then it became a 'paradise for the super-rich'
By Miranda Sheild Johansson and The ConversationJanuary 22, 2026
3 days ago
placeholder alt text
Politics
Latest deadly shooting by federal agents pushes government closer to shutdown as Trump claims Minnesota officials are 'inciting insurrection'
By Jason MaJanuary 24, 2026
15 hours ago
placeholder alt text
C-Suite
Jamie Dimon’s reality check for ambitious workers: ‘There’s going to be a grunt part to every part of a job. Get over it’
By Jake AngeloJanuary 23, 2026
2 days ago
placeholder alt text
Success
Apple cofounder Ronald Wayne sold his 10% stake for $800 in 1976—today it’d be worth up to $400 billion
By Preston ForeJanuary 23, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.


Latest in AI

AIRecruiting
Silicon Valley talent keeps getting recycled, so this CEO uses a ‘moneyball’ approach for uncovering hidden AI geniuses in the new era
By Sydney LakeJanuary 25, 2026
1 hour ago
AIthe future of work
Meet a 70-year-old Home Depot store associate who uses AI on his phone about once an hour: ‘I think my job would suffer if I couldn’t’
By Matt O'Brien, Linley Sanders and The Associated PressJanuary 25, 2026
1 hour ago
lakehouse
AIConsulting
Inside KPMG’s Orlando Lakehouse: the $450 million Covid boondoggle that’s becoming a secret weapon for the AI revolution
By Nick LichtenbergJanuary 25, 2026
5 hours ago
Meta CEO Mark Zuckerberg in Menlo Park, California on Sept. 17, 2025. (Photo: David Paul Morris/Bloomberg/Getty Images)
AIData centers
Why Meta is positioning itself as an AI infrastructure giant—and doubling down on a costly new path
By Sharon GoldmanJanuary 24, 2026
1 day ago
IMF managing director Kristalina Georgieva speaks to reporters outside during the 2026 World Economic Forum in Davos, Switzerland.
LawEconomics
AI productivity gains are making the rich richer, and they’ll wipe out jobs—but the IMF chief sees a silver lining for low-wage workers
By Tristan BoveJanuary 24, 2026
1 day ago
Dario Amodei looking up
AIAnthropic
Anthropic’s head of Claude Code on how the tool won over non-coders—and kickstarted a new era for software engineers
By Beatrice NolanJanuary 24, 2026
1 day ago