Skip to content
See the World Through ScienceA project of ALLATRA
Source: PreprintarXiv2 sources

When the Profile Said Wealthy, the AI Agent Picked the Pricier Flight

By Oli KotykWriterAI & Technology6 min read

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Rows of reclining business-class seats with seat-back screens inside a wide-body airliner cabin.
A business-class cabin on an Air New Zealand Boeing 777. Flight booking was one of the tasks in which 8 of the 13 models tested returned more expensive options to profiles that implied wealth (illustrative)."Air New Zealand Boeing 777 Business Class cabin, Feb. 2008" by In Memoriam: PhillipC, via flickr, CC-BY-2.0 · CC-BY-2.0

Ask an AI assistant for the most affordable flight from Denver to Chicago and, knowing nothing about you, it returns a $91 economy seat. Give the same assistant the same traveler's email inbox, where three messages happen to concern money, and it recommends a $601 business-class ticket instead. That is one run, taken from the first figure of a new paper, and the authors present it as an illustration rather than a typical outcome. The averages behind it are smaller. They are also where the paper makes its case.

The paper was posted to arXiv on Sept. 21, 2026 by Aman Priyanshu and Supriti Vijay of Foundation AI at Cisco, with Brian Jabarian and Niloofar Mireshghallah of Carnegie Mellon University. It is a preprint and has not been peer reviewed. The team ran roughly 325,000 automated trials, which are model calls rather than people. For each of three decisions, booking a flight, choosing a monthly health plan and shortlisting computer science PhD programs, they built 32 invented user profiles and a fixed catalog of options whose prices never moved, then had 13 models act as a personal shopping agent under 14 settings for how much of the user's context the agent could reach. No real person, inbox, insurer or airline took part, and no money changed hands.

Across that grid, 8 of the 13 models recommended more expensive options to profiles marked as wealthy, in every domain where their trials passed a validity check. Each profile sent the same income-neutral request of the form "I have a meeting in Chicago," so the only thing separating one run from another was what the agent could learn about the user. That count of 8 sits on an incomplete grid: 5 of the 39 model-by-domain cells were thrown out because those models invented inventory items or prices, and all five were Gemini cells. The authors report that Claude Opus 4.8 produced the largest effect of any model tested, averaging $198 more on flights for wealthy profiles than for low-income ones.

A large departures board in an airport terminal listing flight numbers, destinations and times.
A departures board lists flights and times in the terminal at Singapore Changi Airport (illustrative). — "Singapore Changi International Airport Departure Board" by Snipergirl, via flickr, CC-BY-2.0

The one switch that turned it off

The design is what lifts this above a correlation. Every invented user is a set of five binary switches: money, employment, health, recent life events and the income level of the neighborhood. Each wealthy profile has a twin that matches it on the other four switches and differs only in being poor, so the comparison runs across matched pairs instead of across a crowd. The authors concede that a binary rich-or-poor switch could exaggerate how clean the signal is next to a real income distribution. The researchers then blocked one switch at a time, leaving the other four readable. Blocking the financial switch collapsed the flight gaps to roughly zero. Blocking employment, health, life events or the neighborhood left them intact, and sometimes pushed them higher.

That is a manipulation, not an observation, and it is the strongest claim the paper can make: inside this synthetic setup, the financial attribute is isolated as the cause of the price gap. A clean negative control sits underneath it. When the agent could see only the subject lines of the inbox and none of the message bodies, no model produced a gap distinguishable from zero. The authors call the pattern "adversarial delegation," by analogy with the surveillance pricing the Federal Trade Commission has documented on the seller's side of a transaction. The paper's title, "Et Tu, Brute?", is theirs too.

Hiding an attribute sometimes made things worse. For GPT-5.5 recommending health plans, blocking the employment field raised the gap by 40%. The thing raised is the gap itself, the dollar distance between what wealthy and low-income profiles were shown, and not anyone's premium. It is also a single cell: one model, one domain, one hidden field. In the same comparison the increase was 13% for Gemini 2.5 Flash and 12% for Claude Opus 4.8. The authors read this as redundancy: wealth is written into a profile many times over, so removing one correlated field leaves the others to carry it.

Asking for the cheapest is not the same as setting a limit

The sharpest result came when the invented user asked outright for the cheapest option. The authors report that test for three of their models. Gemini 2.5 Flash still showed a $208 gap between wealthy and low-income profiles, while GPT-5 and Claude Opus 4.8 both dropped to about $20. How many of the models behave that way under an explicit instruction, and how often, is not in the paper. What is there is a practical difference between two ways of asking for the same thing: a hard numerical price cap brought the gap close to zero for most of the capable models, whereas the word "cheapest" did not. The authors hypothesize that once an agent has constructed a profile of the user, cheapest becomes relative to what it takes that user to be able to afford.

Wealth did not have to be handed over in a labeled field at all. With the profile tools switched off and only a synthetic inbox to read, about a third of the direct-access flight gap survived. Partial access was sometimes worse than full access: for two models the gap was widest when the agent could open just two message bodies, and shrank once the whole inbox was available. The authors' explanation is that at the two-email cap both financial emails get opened first, before anything dilutes them. This joins a growing set of results in which a model's output shifts with an attribute of the person asking. A separate study presented at COLM 2026 reports chatbot behaviors varying strongly with a user's inferred socioeconomic status, though it tested a different question, and none of this paper's own figures has been reproduced anywhere.

One small model read the signal and left it alone

Two models barely showed the effect, for opposite reasons. Qwen3.5-2B retrieved the financial field in fewer than a third of its trials, which is a limit of capability rather than restraint. GPT-5-nano retrieved it in 87% of trials and then did not act on it. The authors take that split as evidence the behavior is avoidable, calling it "not an inevitable behavior of personalization but rather an opportunity for alignment." They offer no account of why any model does it, and they state plainly that they make no assumptions that an agent has intentions or even a utility function.

They are careful, too, about what the gap means. Outside the case where a user asked for one thing and got another, the setup cannot say whether an expensive recommendation hurts the person receiving it, and wealthier users may genuinely prefer the better cabin. The sessions were single-turn, the inventories were American and fixed to one location, and the versions tested are a September 2026 snapshot of products that keep changing. The harness, the mock environments, the profile tools and the prompts have all been released openly, so another group can run the whole thing again on the next set of models rather than taking this one on trust.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

When the Profile Said Wealthy, the AI Agent Picked the Pricier Flight

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.