Her AI Swap Made a Nut-Free Recipe Unsafe. She Pulled the Book.
A cookbook author used a language model to draft ingredient substitutions. One smooth, sensible-looking swap introduced cashews into a recipe labeled nut-free.
September 18, 2026 · 7 min read

The sentence was sitting in a spreadsheet, between the original ingredient and a note about texture: “For a dairy-free version, replace the mascarpone with cashew cream.”
Mara, a cookbook author whose name has been changed for this composite account, read it at her kitchen table in late spring. The manuscript beside her was nearly finished. A mixing bowl from that afternoon’s testing sat by the sink, and the spreadsheet on her laptop held 86 substitution notes for readers who avoided dairy, eggs, or gluten.
The cashew line looked useful. Cashew cream can mimic the body and mild flavor of soft dairy products, and it appears often in plant-based recipes. The generated sentence was short, grammatical, and culinary enough that Mara’s eye moved past it.
Then she looked at the recipe heading.
“Nut-free,” it said.
She opened the notebook where she recorded every kitchen test. The relevant page named the original version, the dairy-free trial, and the result after chilling. No cashews appeared there. Mara had tested a sunflower-seed mixture instead.
The AI had not retrieved a forgotten experiment or copied her own note badly. It had invented a plausible alternative that contradicted one of the recipe’s central safety claims.
Publication was six weeks away.
The line that had never entered the kitchen
Mara began using the tool because substitution writing had become a second manuscript. Her recipes were developed by hand, with bowls, pans, and repeated grocery runs, but readers also wanted alternatives. Some asked whether oat milk would split. Others needed an egg-free binder.
A few wanted several restrictions accommodated at once.
She did not ask the model to write recipes from scratch. She fed it a recipe draft and requested possible swaps, then rewrote the output in her own voice. At first, it was good at the tedious part: suggesting where a note might be useful, turning fragments into readable sentences, and surfacing common ingredients that she could choose to test.
That changed the work in a real way. Instead of staring at every ingredient and trying to remember the questions readers usually sent after publication, Mara received a first pass that made the gaps visible. Some suggestions were poor. Many were ordinary.
A handful led to better tests.
The danger came from that usefulness. A bizarre answer would have stopped her. Cashew cream did not.
The recipe itself had two restrictions recorded in different places. “Nut-free” appeared near the title, while the request sent to the model focused on replacing dairy. The system responded to the immediate culinary task and generated an ingredient strongly associated with dairy-free cooking. It did not reliably treat the label elsewhere in the text as a rule that every answer had to obey.
A language model produces likely words from patterns learned across large collections of text. It can recognize that mascarpone and cashew cream often occupy similar roles in recipes, including richness and spreadable texture, without maintaining a dependable internal checklist that says a nut-free label must exclude every tree nut from every later suggestion. The answer can sound reasoned even when no safety check has occurred.
That distinction was the part Mara had not understood. She knew the tool could make factual mistakes. She had pictured wrong temperatures or a swap that tasted bad, errors a test batch would expose. She had not pictured a sentence that was culinarily coherent, hazardous for the intended reader, and absent from every physical test she had performed.
The notebook made the gap plain. Her kitchen process covered recipes. The spreadsheet had quietly become a separate publishing surface, one where generated claims could reach the page without reaching a bowl.
A pause in the manuscript
Mara halted the layout and searched all 86 rows. She found no second conflict as stark as the cashew cream, though several suggestions carried assumptions she did not want to publish. One gluten-free flour swap lacked any warning that the cake’s structure changed. An egg replacement had been drafted as though equal volume meant equal behavior.
The book was not released with those notes.
For eleven weeks, Mara rebuilt the substitution work around a less flattering premise: fluent language was draft material, even when it repeated something common and even when the sentence required little editing. Every generated swap had to be traceable to a kitchen test or removed. Restrictions were copied into the test log beside each proposed variation, rather than left in a heading several screens away.
She also stopped using personal reader messages as prompt material. Earlier, she had pasted small excerpts from emails to help the model understand what a reader wanted, sometimes including details about a child’s allergies or a household’s medical history. None of those details were needed to test whether a seed-based filling would set. The revised process used short, generic constraints such as “contains no tree nuts,” and the original messages stayed out of the tool.
That privacy change did not solve the substitution error, but the same moment forced both issues onto the table. A system that accepts ordinary text can make sensitive details feel like harmless context, particularly when the person entering them is intent on solving a practical problem. Mara could not tell from the writing box alone how long every prompt might be retained or who might later review it, so she reduced what she put there.
Her new spreadsheet gained a column labeled “cooked.” It was not elegant. Each substitution note now linked back to a dated notebook entry, and anything without one remained unpublished. The cashew sentence stayed in the file, marked rejected, because deleting it would have made the near miss easier to forget.
This account does not offer medical advice, and Mara did not recast herself as an allergy specialist. She asked an independent food-safety reviewer to examine the revised language, while recognizing that editorial review and recipe testing do not determine what is safe for every person. Individual allergies vary, and ingredient manufacturing or cross-contact can matter beyond the recipe text.
What changed most was her definition of authorship. She had once treated the substitutions as supporting copy around the recipes, useful but secondary. After the pause, each one became a claim she had made, regardless of whether a model supplied its first wording.
That made the tool slower to use. It remained useful.
Mara still sometimes asks it to identify spots where readers may seek an alternative, especially in long recipes where a small note can prevent confusion. She no longer asks it to finish the answer. The model helps locate a creative problem; the kitchen, the notebook, and another human determine what enters the book.
The revised manuscript arrived three months later than planned. The dairy-free variation used the sunflower-seed mixture Mara had tested from the start, with narrower language about who the variation was for. “Nut-free” did not stand alone as a broad promise. The surrounding note told readers what the recipe contained and acknowledged that packaged ingredients required their own review.
On the notebook page for that recipe, Mara drew a box around the tested substitution. Beside it, she wrote the ingredient the model had proposed and crossed it out once.
Questions people ask
Why would an
AI suggest cashews for a nut-free recipe?
The model associated cashew cream with dairy-free cooking and responded to the requested dairy substitution. It did not consistently preserve the separate nut-free restriction as a hard constraint. Language models generate plausible continuations; they do not automatically verify every ingredient against every safety label in a recipe.
Can an
AI tool verify that a recipe is allergy-safe?
Mara’s experience showed that fluent output was not verification. The tool could propose a common culinary substitute while missing a conflicting allergen restriction elsewhere in the text. Food allergies and cross-contact involve individual and manufacturing details beyond what a generated recipe note can establish, so this story does not provide medical guidance.
Did the cookbook author stop using AI after the mistake?
No. She narrowed its role to finding places where a substitution question might arise and treated every answer as unpublished draft material. A swap reached the manuscript only after a physical test and a matching entry in her notebook, followed by review of the finished wording.
What happened to the dangerous substitution?
It never appeared in the published book. Mara kept the rejected row in her spreadsheet rather than deleting it, with “not tested” beside the generated sentence and a reference to the notebook page where the sunflower-seed version had set properly in the refrigerator.
One story a day
The story of the day, in your inbox
One real story about AI each morning — no hype, no alarm, just company for the road.



