What Google Merchant Center's Leaked AI Prompts Reveal About Building AI Features
Google Merchant Center briefly leaked its own AI prompts, showing the exact structure, guardrails, and quality check behind a real production AI feature.
For a few hours this week, Google Merchant Center stopped summarizing its own AI and started showing its work. Instead of the usual one-paragraph "performance insight" a merchant sees on their dashboard, some users got a screen full of the actual instructions behind it, the raw prompt the AI was following to write that summary.
Digital marketer Vipul Kumar spotted it first and posted screenshots to LinkedIn. Search Engine Roundtable picked up the report shortly after, and Google has not issued a statement beyond treating it as a temporary glitch rather than a feature. Nobody is claiming anything sensitive got exposed. What did get exposed is more useful than sensitive: a real, working example of how a large company actually structures an AI feature before it reaches a user, the kind of detail that almost never survives contact with a finished product.
That makes this Google Merchant Center AI prompt leak worth more than a screenshot moment. It reads like a checklist for anyone building their own AI-generated reports, summaries, or insights.
What the leaked prompt was actually made of
By Kumar's account, the exposed text wasn't one instruction, it was a stack of them, each doing a different job:
- Analysis parameters. Boundaries on what the AI was allowed to look at and conclude from a merchant's data.
- Operational guidelines. Rules about tone, scope, and what not to say, the kind of guardrail language that keeps an AI-generated summary from making a promise a company can't back.
- Scoped data. The raw performance numbers for 20 specific products, not the merchant's entire catalog. The AI was working from a defined, bounded slice of data, not asked to reason over everything at once.
- Selection criteria. Explicit rules for which products were worth calling out at all, so the summary highlights something a merchant would actually act on instead of restating the dashboard.
- A template bank. Pre-written sentence structures the AI fills in rather than composing freely, which is a big part of how these summaries end up sounding consistent across millions of merchant accounts.
- A quality check. A verification pass before anything reaches the merchant, a second look built into the pipeline rather than trusted to the first draft.
None of this is exotic if you've spent time trying to get an AI system prompt example to produce a boring, boilerplate-free write-up instead of something generic. But most companies never show you the seams. This is what production AI prompt design looks like once the finished product's polish is stripped away.
Why the scoping matters more than the wording
The most instructive piece isn't the prompt language itself, it's the scope. Twenty products, not the whole catalog. A fixed list of criteria for what counts as worth mentioning. A template instead of open-ended generation. Every one of those choices trades some flexibility for predictability, and predictability is what a company actually needs when the output is going in front of paying customers at scale.
That's the part worth borrowing if you're building an AI feature of your own, whether it's a weekly report, a customer-facing summary, or an internal dashboard insight. The instinct when starting out is to write one big, clever prompt and let the model figure out the rest. Merchant Center's leak is a reminder that companies actually shipping these features at scale tend to do the opposite: narrow the input, define the exceptions, template the output, and add a check before anyone sees it. The AI does less improvising, not more, and that's exactly how this kind of feature gets built to hold up across millions of accounts instead of just the demo.
The quality-check step is the part people skip
Of everything in the leaked structure, the verification step is the one most side projects leave out entirely. It's tempting to treat the model's first output as the answer, especially once the earlier steps (scoping, criteria, templates) are already doing most of the work to keep things sane. Google's own pipeline, by this account, still runs a check after generation and before display. If a company with Google's testing resources keeps that step in the loop, it's a reasonable bar for anyone shipping a smaller version of the same idea, and one of the cheapest things to add relative to how much it catches.
This isn't the first time an AI product has accidentally shown its own system prompt instead of hiding it behind a clean interface. It happens periodically across the industry, usually through a prompt-injection trick or a display bug rather than an intentional disclosure, and it tends to draw attention out of proportion to the actual sensitivity of what leaks. The reason it keeps generating interest isn't secrecy value, it's that most builders never get to see a real, battle-tested example of this scope next to their own drafts.
What happens next
Google hasn't said whether the exposure was a display bug, a caching issue, or something else, and hasn't committed to publishing anything about how the feature actually works. That's normal. Companies rarely explain their own prompt architecture on purpose, which is exactly why an accidental leak like this one is worth reading closely instead of scrolling past.
Sourced from Vipul Kumar's original LinkedIn post and Search Engine Roundtable's report.
Join the newsletter
AI workflows and systems, straight to your inbox.
No spam. Unsubscribe anytime.