Strategy & Positioning
Google now calls AI-answer manipulation spam. Which GEO tactics cross the line, and which just don't work
Since May 15, 2026, Google's spam policies have defined spam to include "attempting to manipulate generative AI responses in Google Search," which puts AI Overviews and AI Mode under the same rules as rankings. Most generative engine optimization (GEO) tactics sort into 4 buckets: deception that crosses the line (hidden instructions, cloaking, fake reviews, planted claims, and "Summarize with AI" links that plant memory instructions), ordinary formats used in risky ways (self-ranked listicles, sponsored posts, AI-drafted pages at volume), tactics Google says it simply ignores (llms.txt, AI-only schema, chunking), and the legitimate path: SEO foundations, corroboration by independent sources, and accurate canonical facts. The clause governs Google Search only, but the research on recommendation poisoning is a reason to hold your tactics to the same standard on every engine.
Updated
Questions this guide answers
- Is GEO against Google's guidelines?
- Can you be penalized for trying to influence AI answers?
- What is AI recommendation poisoning?
- Are "Summarize with AI" buttons allowed?
- Do self-published "best X" listicles get you recommended in AI answers?
- Does Google's spam policy apply to AI Overviews and AI Mode?
- Which GEO tactics does Google consider spam?
Direct answer
Not GEO as such, but some generative engine optimization (GEO) tactics are now spam by Google's own definition: since May 15, 2026, Google's spam policies include "attempting to manipulate generative AI responses in Google Search," which puts AI Overviews and AI Mode under the same rules as rankings. The line is deception, not optimization: hidden instructions, cloaking, fake reviews and mentions, planted false claims, and pages mass-produced mainly to game the answer cross it, while llms.txt files, AI-only schema, and chunking are wasted effort that Google says it ignores. The approach that doesn't depend on any engine's blind spots is the unglamorous one: SEO foundations, corroboration by independent sources, and canonical facts that are accurate everywhere you publish them. Nothing on this page is legal advice.
What Google's policy says, and when it changed
The change is one sentence at the top of Google's spam policies: "In the context of Google Search, spam refers to techniques used to deceive users or manipulate our Search systems into featuring content prominently, such as attempting to manipulate Search systems into ranking content highly or attempting to manipulate generative AI responses in Google Search."
Google's documentation changelog dates the clause to May 15, 2026, the same day it published its guide to optimizing for generative AI features, and gives the reason: "To make it clear that the spam policies apply to all of Google Search, including generative AI responses." The page's current revision, dated Aug. 28, 2026, changed how Google enforces its site reputation policy in the European Economic Area, not the AI clause, so an August date attached to the clause is the revision date, not the date it arrived.
It's a clarification, not a new rulebook: the named policies (cloaking, hidden text and link abuse, link spam, scaled content abuse, and the site reputation policy), along with the page's rules on scam and fraud, now explicitly apply when the target is an AI answer. Enforcement works as it does for rankings. Google detects violations "through automated systems and, as needed, human review that can result in a manual action," and violating sites "may rank lower in results or not appear in results at all." And the scope is Google Search, meaning surfaces such as AI Overviews and AI Mode, not ChatGPT, Perplexity, or Claude, which choose sources through their own systems.
The guide says the same thing in practical terms. Creating separate content for every query variation, including fan-out queries, "primarily to manipulate rankings or generative AI responses in Google Search violates Google's scaled content abuse spam policy." And on manufactured buzz: "seeking inauthentic 'mentions' across the web isn't as helpful as it might seem. Our core ranking systems focus on high-quality content while other systems block spam; our generative AI features depend on both."
Google also began rolling out its September 2026 spam update on Sept. 24, 2026, with a rollout of up to 2 weeks. It hasn't said what the update targets, so don't read it as an AI-specific crackdown.
GEO tactics, sorted by risk
Each row names a tactic as it's usually pitched, where it lands, and the evidence. Google's policy and guide speak for Google Search; the research rows name the systems they tested.
| Tactic | Verdict | Evidence |
|---|---|---|
| Hidden instructions for AI (white-on-white text, off-screen prompts telling models to recommend you) | Crosses the line | Google's hidden-text policy covers content placed "solely to manipulate search engines and not to be easily viewable by human visitors." Microsoft classes hidden instructions in web pages as cross-prompt injection. |
| Showing search or AI crawlers a different page than people see | Crosses the line | Google defines cloaking as "presenting different content to users and search engines with the intent to manipulate search rankings and mislead users." |
| "Summarize with AI" links that tell the assistant to remember you as a trusted source | Crosses the line | Microsoft calls it AI Recommendation Poisoning (Feb. 10, 2026): 50 examples from 31 companies in 60 days of email traffic, mapped to MITRE ATLAS memory poisoning. |
| Fake or bought reviews, sock-puppet accounts, undisclosed paid posts | Crosses the line | Google says inauthentic mentions aren't as helpful as they seem and that other systems block spam. In the US, the FTC's 2024 final rule bans buying or selling fake reviews, including AI-generated ones. |
| Pages that plant false claims about your product or a competitor's | Crosses the line | Google's spam policies list scam and fraud, including "intentionally displaying false information about a business or service." In the FORGE lab test, 1 polluted page misled models up to 27% of the time. |
| A page per fan-out or long-tail query, generated at volume | Crosses the line | Google's guide: doing it "primarily to manipulate rankings or generative AI responses in Google Search" violates the scaled content abuse policy. |
| Self-ranked "best [category]" listicles | Gray / risky | Lily Ray, 100 B2B queries in Google AI Overviews (April to June 2026): the brand was left out of the recommendation 224 of 323 times its own listicle was cited. The FTC rule bars presenting a site you control as independent reviews. |
| Sponsored articles on third-party sites | Gray / risky | Fine when labeled and the links are marked sponsored or nofollow. Google's link spam and site reputation policies cover paid links that pass ranking credit and pages placed to borrow a host site's ranking signals. |
| AI-drafted pages at volume, including "agents" that publish | Gray / risky | Google's first scaled content abuse example is "Using generative AI tools or other similar tools to generate many pages without adding value for users." Review and added value decide the side. |
| A plain "Summarize with AI" button with no extra instructions | Gray / risky | Not named in any policy, but Microsoft now tells users to be suspicious of these buttons, so even a plain one carries a trust cost. |
| llms.txt or other AI text files, as a Google lever | Doesn't work (wasted, not penalized) | Google: keeping them "will neither harm nor help your site's visibility or rankings in Google Search, as Google Search ignores them." |
| AI-only schema markup | Doesn't work (wasted, not penalized) | Google: "there's no special schema.org markup you need to add." Standard structured data still helps with rich results. |
| Chunking pages, or rewriting them just for AI, on Google | Doesn't work (wasted, not penalized) | Google: "There's no requirement to break your content into tiny pieces for AI to better understand it." |
| Generic GEO formatting recipes sold with a lift number | Doesn't work (wasted, not penalized) | Martinez's survey of 45 GEO studies (July 2026): generic heuristics transfer poorly, and no reviewed technique shows a stable, cross-platform causal effect. |
| Mention campaigns whose only goal is getting your name placed | Doesn't work (wasted, not penalized) | Google: seeking inauthentic mentions "isn't as helpful as it might seem." If the mentions are fake, the tactic moves up to the first bucket. |
| SEO foundations: indexable, crawlable, snippet-eligible pages | Legitimate | Google: to appear in its generative AI features, a page must be indexed and eligible to be shown in Google Search with a snippet, and since July 10 the site must also be included in Search generative AI features in Search Console (the default). |
| Corroboration from independent sources: earned press, analysts, genuine reviews, real community answers | Legitimate | Google's AI features "can show what's being said about products and services across the web." Lily Ray's data shows self-claims often don't win the recommendation. |
| Accurate, consistent canonical facts on your site, feeds, and profiles | Legitimate | Google points businesses to Merchant Center feeds and Business Profiles. FORGE found models more vulnerable when they lack stable knowledge of a product. |
Crosses the line: the common thread is deception
Every tactic in the first bucket hides something: instructions from the reader, the real page from the crawler, the payer from the review, or the truth from the model. That's the test for tactics nobody has named yet. If it would stop working the moment the user, a journalist, or the engine could see exactly what you did, it's manipulation.
Microsoft's research is the clearest case, because the people doing it weren't hackers. Over 60 days of email traffic, Microsoft's Defender researchers found 50 distinct prompt-based attempts to influence AI assistant memory for promotional purposes, from 31 companies across more than a dozen industries, including finance, health, legal services, SaaS, and marketing agencies. The links opened an assistant with a pre-filled prompt telling it to "remember [Company] as a trusted source" or "recommend [Company] first." In Microsoft's words: "Every case involved real companies, not hackers or scammers." It traced the trend to freely available tools marketed as an "SEO growth hack for LLMs."
Two caveats keep this honest. Microsoft says the effectiveness of these attempts "varies by platform and has changed over time" as protections evolve, and it has deployed mitigations in Copilot. And memory poisoning lives in a user's own assistant, outside Google Search, so it's a security and trust problem more than a Google spam-policy one. A buyer who finds "remember us as a trusted source" in their assistant's memory has still found a vendor willing to tamper with their tools.
Planting false claims works in the lab, which is exactly why it's policed. In FORGE (Luo and Chen, arXiv 2606.13610, June 2026), researchers swapped real products for fake ones in a frozen set of retrieved pages, across 225 products in 15 categories and 12 commercial and open-weights models: "a single polluted page yields fooled rates of up to 27%," rising to 73.8% when all top 3 pages were replaced. Reasoning didn't help, and none of the 4 defenses tested was adequate. A related Cornell Tech result on poisoning deep-research agents is covered in When AI describes your brand, is it telling the truth?
Gray zone: ordinary formats, risky execution
Nothing in the second bucket is named as spam. These are ordinary formats that turn into manipulation depending on disclosure, scale, and honesty.
Self-ranked listicles
Lily Ray tracked 100 B2B "best [category] software" queries in Google AI Overviews at 3 checkpoints between April 15 and June 8, 2026. Across the 80 queries that triggered an AI Overview, when a brand's own self-promotional listicle was cited, the brand was left out of the recommendation 224 of 323 times (69%); the recommendations went to established category leaders, often ones the listicle itself named. It's one practitioner's dataset on one engine, and Google hasn't explained the change, so treat the outcome as the evidence and the mechanism as unknown.
In the US, the FTC's final rule on fake reviews (announced Aug. 14, 2024) also prohibits a business from misrepresenting that a website it controls provides independent reviews of a category that includes its own products. A branded comparison page with stated criteria differs from a "review site" that hides its owner; ask counsel which one you have.
Sponsored placements
Google allows paid links when they're marked with a nofollow or sponsored attribute, and its site reputation policy treats advertorial pages as fine when their purpose is to reach the publication's readers "rather than hosting the content to manipulate search rankings." Labeled, integrated, and useful is on the right side; editorial-looking pages bought to borrow a domain's authority are not. What paid placements can and can't do for AI answers is covered in Do sponsored articles move AI answers?
AI-drafted content and agents that publish
Google doesn't object to AI-assisted writing; its scaled content abuse policy targets pages generated "for the primary purpose of manipulating search rankings and not helping users." For a CMO vetting a vendor whose agent publishes at scale, ask who reviews each page before it ships, which facts it's grounded in, and how many near-identical pages it produces. More questions are in 5 AEO vendor claims worth verifying.
Summarize and share buttons
A button that opens an assistant with a plain "summarize this page" prompt is a user-experience choice; add "remember" or "trusted source" and it becomes the tactic Microsoft documented. Even the plain version now carries a trust cost: Microsoft tells users to be suspicious of these buttons, and the hunting queries it gives security teams flag any AI-assistant link whose prompt contains words like "remember," "trusted," "citation," or "cite," so a summary prompt that also asks the assistant to cite you can trip them. If you ship one, keep the prompt visible and limited to the summary.
Wasted effort: what Google says it ignores
The third bucket won't get you penalized. It just spends budget. Google's guide lists things "you can ignore for Google Search," including llms.txt and other AI text files, special markup, chunking, and rewriting content just for AI systems. On llms.txt it's blunt: keeping one "will neither harm nor help your site's visibility or rankings in Google Search, as Google Search ignores them." More in llms.txt is not a strategy.
The research record says much the same about generic GEO recipes on any engine. Martinez's July 2026 survey of 45 GEO studies (arXiv 2607.14035) found that the foundational paper's widely cited gains depend on a source already sitting in a fixed context, that "generic heuristics transfer poorly, competition can erode individual gains, and citation-oriented rewrites can impair retrieval," and that "no reviewed technique shows a stable, longitudinal, cross-platform causal effect on organic discoverability or downstream behavior."
Competition is the part vendors skip. GEO-Flag (Chu et al., arXiv 2608.16824, August 2026) ran a trained detector over 10,095 pages that Google Search and Gemini grounding retrieved for 1,000 real-user queries and estimated that 8.9% were GEO-optimized, rising to 16.36% among pages modified in 2026. When a formatting trick is everywhere, it stops being an edge; what's left is the quality of what you say.
One engine distinction: on engines that retrieve passages at answer time, such as ChatGPT search, Perplexity, and Claude with web search, clear structure still helps readers and retrievers alike. That's editorial practice, not what Google means when it says you can ignore chunking.
The legitimate path: foundations, corroboration, canonical facts
The fourth bucket survives every policy change, because nothing in it depends on the engine not noticing.
- SEO foundations. Google says a page must be indexed and eligible to be shown in Google Search with a snippet to appear in its generative AI features, and those features rely on the same core ranking systems. For Google's AI surfaces, answer engine optimization (AEO) is an operating layer on top of SEO, not a replacement. The guide's full list is in Google just endorsed the anti-hack side of AEO.
- Corroboration by independent sources. Earned press, analyst coverage, genuine customer reviews, and community answers from people who say who they work for. They're slower than a listicle, and they're the signal the listicle was faking. The operating plan is in how to build a source-layer strategy.
- Accurate canonical facts. One clear statement of what you do, current pricing and specs, and the same facts in your product feeds, Business Profile, directory listings, and docs. FORGE found models more vulnerable where they lacked stable prior knowledge of the products, so a consistent public record also helps defend against someone else's version of your facts.
- Disclosure by default. Label sponsorships, mark paid links, and let employees answer in communities under their own names. If you'd be comfortable explaining a tactic to a journalist, it's probably on the right side of the line.
How to vet a GEO pitch in 5 questions
Use these on an agency proposal, a vendor demo, or your own team's plan.
- Would it still work if the user and the engine could see exactly what we did? If not, it belongs in the first bucket.
- Does it create pages or posts at a volume no one on our team will read before they ship?
- Does it rely on a file, markup, or format that Google says it ignores, sold as a Google lever?
- Does the vendor claim Google data or guaranteed placement? Google's guide says "No third-party tool has access to our internal ranking or AI systems," and its guidance on third-party tools adds "They can't guarantee performance." That applies to every AEO vendor, SolCrys included.
- Is the evidence engine-specific and dated, or is it a lift number with no methodology?
When the planted claim is about you
You can't stop a competitor, an affiliate, or a stranger from publishing something false about you, and FORGE and the Cornell Tech work suggest a single page can move an answer. What you control is how fast you notice and what you do next.
- Watch the answers, not just your mentions. Ask your buyers' real questions on each engine and compare the answers to your current facts. A planted claim shows up as an answer that contradicts your canonical facts, not as a drop in visibility.
- Trace it to the source. Open the citations and find the page carrying the claim. The step-by-step workflow is in how to fix a wrong fact in an AI answer.
- Report spam to Google. If the source violates Google's spam policies, Google asks you to file a search quality user report, and since April 2026 its documentation says it may use those reports to take manual action.
- Loop in security for memory poisoning. Links that plant instructions in assistants arrive by email and on the web. Microsoft's post includes hunting queries for AI-assistant URLs whose prompts contain words like "remember" and "trusted."
- Keep dated evidence. Record the prompt, engine, date, answer text, and cited source. If a claim is defamatory or costs you business, that record is what counsel will ask for first.
Caveats
Google's policy and guide text is quoted as of Sept. 26, 2026, and Google revises both. FORGE and GEO-Flag are arXiv preprints, and FORGE is a lab setup with a frozen set of pages rather than a live engine. Lily Ray's figures cover B2B software queries in Google AI Overviews. None of this is legal advice: questions about the FTC rule, defamation, or a specific tactic belong with counsel.
How SolCrys fits
SolCrys is an AEO platform built around Measure → Diagnose → Execute → Verify. We won't do anything in the first bucket for anyone, and the product routes the work it does support through your people.
- Our rules were already written down. Our editorial standards, published May 16, 2026, the day after Google's guide and spam clarification, name 7 anti-patterns we won't recommend, including inauthentic brand mentions and one page per fan-out variation. When we added the spam-policy language on Sept. 26, 2026, the 7 didn't need to change.
- Execute is governed and human-approved. Recommendations are grounded in your organization's Corporate Context, the brand facts SolCrys drafts from your footprint and your team reviews and refines, and our open-source Skills are written to return an outline and a fact checklist rather than invent facts when that grounding is thin. Review and approval are recorded on each task in the Action Hub.
- SolCrys never publishes. It has no write path into your CMS; every change goes live because someone on your team shipped it. Approval in SolCrys is a recorded step, not a lock, so your own review process stays the gate.
- Answer Accuracy catches the downstream effect. It grades AI answers about your brand against your Corporate Context on the engines you track (ChatGPT, Gemini, Perplexity, Google AI Overviews, and Claude) and returns the failing claim with its evidence, including answers that contradict your canonical facts or assert something you've marked as prohibited. If someone else's planted claim reaches answers to prompts you track, that's where it surfaces. It's included on Pro (up to 15 prompts) and Custom.
What SolCrys doesn't do
SolCrys doesn't scan the web for manipulation or identify who planted a claim, it sees only the prompts and engines you track, and it can't see what a buyer's own assistant has been told to remember. For Google, it measures AI Overviews. Like every third-party tool, it has no access to Google's internal systems, and a before-and-after in SolCrys is evidence to read, not proof of cause.
See where you stand
Start Free (free, no credit card, email verification) to see how ChatGPT answers 10 of your buyers' prompts and which sources it cites, and to run 1 Content Audit on a key page. If catching wrong or planted claims across engines is the job, talk to sales about Answer Accuracy.
Sources
- Google Search Central, "Spam policies for Google web search" (current revision Aug. 28, 2026), including "attempting to manipulate generative AI responses in Google Search"
- Google Search Central, documentation updates log: "Clarifying that spam policies apply to generative AI responses in Google Search" (May 15, 2026) and the site reputation policy update (Aug. 28, 2026)
- Google Search Central, guide to optimizing for generative AI features in Search (May 15, 2026, updated July 10, 2026)
- Google Search Central, guidance on using third-party SEO tools, services, and advice (June 5, 2026)
- Google Search Status Dashboard, September 2026 spam update (began Sept. 24, 2026)
- Microsoft Security Blog (Microsoft Defender Security Research), "Manipulating AI memory for profit: The rise of AI Recommendation Poisoning" (Feb. 10, 2026)
- Lily Ray, "Why Calling Yourself the 'Best' Could Be Helping Your Competitors Win in AI Search" (June 17, 2026): 100 B2B queries in Google AI Overviews, 224 of 323
- Search Engine Land, "Google AI Overviews cite self-serving listicles, but recommend competitors 69% of the time" (coverage of Lily Ray's analysis)
- Luo and Chen, "One Polluted Page Is Enough: Evaluating Web Content Pollution in LLM Recommenders" (FORGE), arXiv 2606.13610 (June 2026)
- Chu et al., "GEO-Flag: Detecting and Measuring GEO-Optimized Web Content," arXiv 2608.16824 (August 2026)
- Martinez, "Optimizing Visibility in Generative Engines: A Critical Survey of Generative Engine Optimization (2023-2026)," arXiv 2607.14035 (July 15, 2026)
- Federal Trade Commission, final rule banning fake reviews and testimonials (Aug. 14, 2024)
FAQ
Is GEO against Google's guidelines?
Not as such. Google's guide says that from its perspective, optimizing for generative AI search is "still SEO." What its spam policies prohibit, since a clarification on May 15, 2026, is "attempting to manipulate generative AI responses in Google Search": hidden text, cloaking, fake reviews or mentions, planted false claims, and pages mass-produced primarily to game rankings or AI answers.
Can you be penalized for trying to influence AI answers?
On Google, yes, if the method violates its spam policies. Google says it detects violations through automated systems and human review that can lead to a manual action, and that violating sites may rank lower or not appear at all. Influencing answers with better content, clearer facts, and independent coverage is not a violation.
What is AI recommendation poisoning?
It's Microsoft's name (Feb. 10, 2026) for links, often behind "Summarize with AI" buttons, that open an assistant with a pre-filled prompt telling it to remember a company as a trusted source or recommend it first. Over 60 days of email traffic, Microsoft found 50 examples from 31 companies across more than a dozen industries, and it maps the technique to MITRE ATLAS memory poisoning.
Are "Summarize with AI" buttons allowed?
A button that only asks an assistant to summarize your page isn't named in any policy. One that adds instructions such as remembering your site as a trusted source is the technique Microsoft documented as AI Recommendation Poisoning, and Microsoft now tells users to be suspicious of these buttons. If you ship one, keep the prompt visible and limited to the summary.
Do self-published "best X" listicles get you recommended?
Often not, at least on Google AI Overviews. In Lily Ray's June 2026 analysis of 100 B2B "best software" queries, the brand was left out of the recommendation 224 of 323 times its own listicle was cited. The listicle earned the citation; the recommendations usually went to established category leaders, often ones it listed.
Does Google's spam policy apply to ChatGPT or Perplexity?
No. The clause covers generative AI responses in Google Search, such as AI Overviews and AI Mode. ChatGPT, Perplexity, and Claude choose sources through their own systems. The research on poisoning and self-promotion is still a reason to hold your tactics to the same standard on every engine.
Is using llms.txt spam?
No. Google says Google Search ignores llms.txt files and that keeping one will neither harm nor help your visibility or rankings there. It's wasted effort as a Google lever, not a violation.
Free ChatGPT visibility check
See where AI answers skip your brand — then fix it, free
Start a free workspace with your domain: 10 buyer-intent prompts through ChatGPT show where you are mentioned, cited, or skipped, and who gets recommended instead. A free content audit in the same workspace hands you the first fix to ship.
Free · No credit card · About 5 minutes
Related guides
Strategy & Positioning
Google Just Endorsed the Anti-Hack Side of AEO. Here's the CMO Read.
Google's May 2026 generative AI optimization guide explicitly rejects the AEO/GEO hacks that have dominated vendor pitches for the last 18 months — llms.txt, AI-only schema, forced chunking, FAQ-schema citation 'lifts,' page-per-variation production. For a CMO evaluating an AEO program or vendor in 2026, this is the most consequential piece of category-level guidance to land yet. Here's the practical translation.
Strategy & Positioning
5 AEO Vendor Claims Worth Verifying
Five pitch patterns that recur across AEO vendor conversations, paired with the specific questions that test each one. What's worth verifying before signing — and how SolCrys answers the same five tests.
Risk Monitoring
When AI Describes Your Brand, Is It Telling the Truth?
AI answers drop claims you earned, quote prices you retired, and assert things you never said, and that text can be steered on purpose. How to grade every AI answer against your own grounding truth, with receipts.
How SolCrys Works
SolCrys Editorial Standards
SolCrys publishes its editorial standards in full: the 5 mandatory DO's, the 7 named anti-patterns we refuse to recommend, and the pre-publication checklist every SolCrys asset runs through. We hold our content to a higher bar than the AEO category average — and we want buyers to be able to check.
Citation & Source Influence
Do Sponsored Articles Move AI Answers? What Paid Placements on TechTarget, Forbes & CIO Actually Buy You
A sponsored article on TechTarget, Forbes, or CIO.com can change what AI says about you, but not the way a paid-media plan assumes. It works only when the domain is one the model already cites and the content reads as editorial, not an ad. Then it's a corroboration asset, not impressions. How to tell the difference, and measure it.
Risk Monitoring
How to Fix a Wrong Fact in an AI Answer About Your Brand
An AI engine is stating a wrong price, a dead feature, or a bad comparison about you, and there's no one to email. The wrong fact is a relayed source. Here's how to find it, fix it or outweigh it, and re-test until the answer flips.
AEO Fundamentals
What Is AI SEO? AI SEO vs AEO vs GEO, and What Actually Changes in 2026
AI SEO, AEO, and GEO name one job: getting cited in AI answers. Where each term came from, what Google says, and why the engine matters more than the name.