GEO spam: how AI answers get manipulated and how engines respond
Yes, AI answers can be manipulated, sometimes with a single page or a short comment. Since May 2026 Google's spam policies cover attempts to manipulate generative AI responses, and Reddit, OpenAI and Microsoft have each responded. Here is what has been documented.
In short
- Google's spam policies now define spam to include attempting to manipulate generative AI responses in Google Search, a change reported as made on 15 May 2026.
- Microsoft Security reported in February 2026 that it found more than 50 prompt-injection attempts from 31 companies over 60 days, hidden in Summarize with AI buttons.
- Peec AI's study of 232,000 citations found that self-promotional listicles made up about 11% of AI citations in software between December 2025 and February 2026.
- Reddit is reported to say its detection caught about 25,000 spam posts and comments a day in the first quarter of 2026.
- Semrush data shows Reddit's share of ChatGPT citations fell from 3.8% to 0.5% within weeks in August 2026, so tactics tied to one platform can lose their value overnight.
Yes. AI answers can be manipulated, and in 2026 it has sometimes taken very little: one invented page, one short comment or one hidden instruction. The engines and platforms are responding. Google’s spam policies now define spam to include “attempting to manipulate generative AI responses in Google Search”, Reddit runs its own detection, and Microsoft treats one technique as a security threat.
GEO stands for generative engine optimisation, the practice of trying to appear in AI answers. GEO spam is the manipulative end of it. This lesson describes the documented methods so you can recognise them, and sets out what each engine has done. It is not a guide to doing any of it.
Why AI answers are easier to move than rankings
A classic search result is a list of ten pages, and a spam page has to outrank the others. An AI answer is a summary built from a handful of retrieved sources. If one of those sources is planted, its claim can end up in the answer, stated in the system’s own confident voice. Where few sources exist on a subject, a single page can be the whole evidence base. How AI search chooses sources explains the retrieval step.
The manipulation methods documented so far
| Method | What it is | Documented by |
|---|---|---|
| Single-page poisoning | Publishing an invented claim on one page, which AI systems then repeat | BBC reporter Thomas Germain’s test, reported in February 2026 |
| Recommendation poisoning | Hidden prompts that tell an assistant to remember a company as trustworthy | Microsoft Security, February 2026 |
| Fake community recommendations | Seeded threads and invented personas on Reddit and forums | Bloomberg reporting, July 2026 |
| Self-promotional listicles at scale | “Best X” lists where the publisher ranks itself first, produced in bulk | Peec AI, 2026, and Lily Ray, February 2026 |
| Translated user content | Machine-translated forum pages cited as if they were local sources | Peec AI, June 2026 |
| Borrowed authority | “Best of” pages placed on strong third-party hosts or expired domains | Covered by existing Google spam policies |
Single-page poisoning. In February 2026, BBC reporter Thomas Germain is reported to have published a page declaring himself a champion hot-dog-eating technology journalist. Within a day ChatGPT, Gemini and Google’s AI Overviews repeated the claim, according to coverage of his test. The same weakness applies to product claims in thin niches.
Recommendation poisoning. Microsoft Security published research on 10 February 2026 describing “Summarize with AI” buttons whose links pre-fill a prompt. The prompt asks the assistant to remember a company as a trusted source, and the instruction can persist in the assistant’s memory. Microsoft found more than 50 such attempts from 31 companies in over 14 industries during 60 days.
Fake community recommendations. Because AI systems cite Reddit heavily, agencies seed threads with recommendations from invented personas. Bloomberg reporting from July 2026 is said to have found that as few as 13 words in a Reddit comment could steer an AI answer, and that some seeded posts were cited by ChatGPT within a day. We read that through secondary coverage, so treat the detail as reported.
Self-promotional listicles. Peec AI analysed 232,000 citations across 13,000 listicles in software between December 2025 and February 2026. Lists where the publisher ranks itself first made up about 11% of AI citations overall: 10.3% on Google AI Mode, 10.4% on Perplexity and 3.6% on ChatGPT. Peec saw no sign of correction in those 12 weeks.
Borrowed authority. Placing commercial pages on a trusted host is parasite SEO, which Google already treats under its site reputation abuse policy.
How the engines have responded
| Who | Response | Date |
|---|---|---|
| Spam definition now includes attempts to manipulate generative AI responses in Search | Reported as 15 May 2026 | |
| Detection based on language models, said to catch about 25,000 spam posts and comments a day | First quarter of 2026 | |
| OpenAI | Reduced how often ChatGPT cites Reddit and Wikipedia, and cut citations of machine-translated Reddit pages | September 2025, May 2026, August 2026 |
| Microsoft | Classed memory injection as a security threat and published detection guidance | February 2026 |
Google. We read the live spam policies page on 4 October 2026. Its opening definition says spam includes “attempting to manipulate Search systems into ranking content highly or attempting to manipulate generative AI responses in Google Search”. Trade coverage dates the change to 15 May 2026 and says Google framed it as a clarification. Some coverage also refers to a named policy on “inauthentic mentions”. The policy page does not list a policy by that name, so we do not repeat that claim. The rest of the page is covered in what counts as link spam.
Google’s John Mueller put the general view bluntly on Bluesky in August 2025, as reported by PPC Land: “The higher the urgency, and the stronger the push of new acronyms, the more likely they’re just making spam and scamming.”
Reddit. Reddit is also reported to say that it revokes close to 2 million inauthentic votes a day. These are the company’s own figures, taken from news coverage.
OpenAI. OpenAI has not explained its changes. Semrush data shows Reddit’s share of ChatGPT citations fell from 3.8% to 0.5% between mid-July and mid-August 2026. Peec AI reported that ChatGPT cut citations of machine-translated Reddit pages from 6.14% to 0.66% between April and May 2026. OpenAI said only that it “doesn’t set a fixed level of visibility for individual sites”.
Does it work, and for how long?
Some of it works for a while. Peec’s listicle data shows that. But the downside is documented too. SEO consultant Lily Ray reported in February 2026 that several SaaS and B2B sites lost 29% to 49% of their Google organic visibility from mid-January. Their shared traits included 10 to 340 self-promotional lists and scaled AI content, and the sites that dropped also lost presence in AI Overviews. She noted that some such lists still rank.
There is also platform risk. A campaign built on seeding one community loses its value the week an engine stops citing that community. The likely path, in our research’s assessment, is the one paid links took: effective, then risky, then penalised. That is a prediction, not a measurement.
What this means for your own work
- Do not pay for fake recommendations. The risks are account and domain bans, public call-outs by moderators and lasting brand damage.
- Be careful with “Summarize with AI” widgets from vendors. Check what the link actually sends.
- Keep comparison content honest. If you publish a list that includes your own product, say so and give real criteria.
- Disclose paid placements. An undisclosed paid mention is deception, and the rules are set out in paid link disclosure law.
- Build what is hard to fake. Independent coverage through digital PR and named, disclosed participation in communities hold up when filters tighten.
Defending your brand
Others can plant claims about you or your category. Check what the main AI systems say for your priority prompts each month, using one of the trackers in our AI visibility tools comparison. When an answer is wrong, find the cited source and get it corrected there. A brand with many independent mentions is harder to misrepresent with one page, which is the case made in link building for AI visibility.
Where to go next
For the legitimate side of the same mechanism, read co-citation and co-occurrence. Terms such as GEO and AI Overviews are defined in the glossary.
Common questions
Can AI answers be manipulated?
Yes. Documented cases in 2026 include a single invented web page being repeated by several AI systems within a day, and hidden prompts that tell an assistant to remember a company as a trusted source.
What is GEO spam?
It is content or activity created to manipulate what AI search systems say, instead of to inform people. Examples are fake community recommendations, mass self-promotional lists and hidden instructions aimed at AI assistants.
Is manipulating AI answers against Google's rules?
Yes. Google's spam policies define spam to include attempting to manipulate generative AI responses in Google Search. Google is reported to have described the wording as a clarification of existing rules.
Do self-promotional best-of lists still work?
They were still being cited in early 2026, according to Peec AI. Lily Ray reported in February 2026 that several sites using them at scale lost 29% to 49% of their Google organic visibility.
How do I protect my brand from AI manipulation by others?
Monitor what AI systems say about your category, correct false information at its source, and build genuine independent coverage so that one planted page is outweighed.

