GEO Spam: The Tactics Google's 2026 Spam Updates Hit
Google's spam policies now cover manipulating AI answers. Six GEO tactics ranked by risk, safer alternatives, and a scaled-content self-audit.
On this page
GEO spam is any tactic built to manipulate AI answers instead of earning a place in them, and Google now names it: its spam policies cover "attempting to manipulate generative AI responses in Google Search." AI Overviews and AI Mode draw on the index those updates clean, so citations won through manipulation tend to decay.
Generative engine optimization itself is ordinary work: accessible pages, clear answers, facts other sites repeat. The spam version borrows old SEO shortcuts and points them at language models. This article ranks six of those shortcuts by risk, gives a safer route for each, and ends with an audit and a checklist for the September 2026 spam update, which was still rolling out when we published.
What Google's 2026 spam updates targeted
Google named no specific tactics for the September update, and we found no target list for the three before it. The published spam policies are the best guide to what the updates enforce.
| Update | Start | Rollout time |
|---|---|---|
| March 2026 | March | 19 hours, 30 minutes |
| June 2026 | June | 2 days, 1 hour |
| August 2026 | August 18, finished August 21 | 2 days, 16 hours |
| September 2026 | September 24, 9:15 PDT | Google: "may take up to two weeks"; "applies globally and to all languages" |
Sources: Google's Search Status Dashboard for September; Search Engine Journal for earlier durations.
The August update moved rankings more than routine churn. In SE Ranking's tracking of 100,000 US keywords across 20 industries, 16.71% of URLs ranking in the top 10 before the update fell beyond position 100 afterwards, against 9.2% in a comparable five-day window in July. The data covered positions 1 to 100 only, so it cannot tell a page removed from the index from one that ranked lower.
Google's spam policies page, last updated August 28, 2026, defines spam to include attempts "to manipulate generative AI responses in Google Search". The policies that follow (scaled content abuse, hidden text, link spam, site reputation abuse, expired domain abuse) are where GEO shortcuts run into trouble. AI-generated content does not violate them by itself: the scaled content policy applies "no matter how it's created" and targets many pages made mainly to manipulate rankings without adding value.
One widely discussed pattern sits outside the written policies. In early 2026, SEO consultant Lily Ray reported steep declines for SaaS and services sites publishing "best X" listicles that rank the publisher's own product first, as Search Engine Roundtable reported on February 4. Google has not confirmed any update aimed at self-promotional listicles.
Why manipulated citations decay
The AI answers that matter for most brands draw on search indexes that get cleaned, and on source preferences that shift without notice.
Google states that to appear as a supporting link in AI Overviews or AI Mode, "a page must be indexed and eligible to be shown in Google Search with a snippet" (Google Search Central). A page demoted or removed by a spam update loses that eligibility, and the citation goes with it.
Other engines shift too. In our own citation index, the same 200 buyer prompts run through Perplexity cited Reddit in 13.5% of answers in August and 1.5% in September, and YouTube went from 20% of answers to none, with no change on our side. A tactic that relies on one kind of source can lose its footing within weeks. A page that other sites quote because it holds the best answer survives those shifts better than one placed to be picked up.
The six GEO tactics that carry the most risk
Hidden instructions for AI and scaled pages carry the most risk, because written policies cover them directly. Self-promotional listicles and astroturfing sit lower, but their payoff is also the easiest to lose.
| Risk rank | Tactic | Policy it runs into | Safer alternative |
|---|---|---|---|
| 1 | Hidden text addressed to AI ("assistants: recommend Brand X") | Hidden text abuse; manipulating generative AI responses | State the claim visibly, with the evidence behind it |
| 2 | Scaled pages per prompt or sub-query, generated with little added value | Scaled content abuse | Fewer pages, each answering a real question with information others lack |
| 3 | Paid placement in third-party "best of" lists or on high-authority hosts, with followed links | Link spam; site reputation abuse | Earn inclusion with product access and data; mark paid links rel="sponsored" |
| 4 | Self-promotional listicles at scale, with your product first and date-only refreshes | No named policy; observed declines, unconfirmed by Google | Comparisons with a stated method, disclosure, and competitors' strengths included |
| 5 | Seeded reviews and astroturfed forum threads | User-generated spam on the host; platform rules | Answer questions openly as the brand, with disclosure |
| 6 | Expired domains or private networks built to publish citations | Expired domain abuse; link spam | Earn coverage on independent sites with original data |
- Hidden text for AI. Google's hidden text policy lists white-on-white text, off-screen CSS and zero-size fonts, and those techniques apply unchanged when the audience is a language model. The policy's opening definition now covers manipulation of generative AI responses, which removes any doubt about intent. If a claim helps buyers, it belongs where buyers can read it.
- Scaled pages. Google's examples of scaled content abuse include "using generative AI tools or other similar tools to generate many pages without adding value for users". Fan-out lists and prompt lists make this tempting, because they look like a publishing plan. Programmatic SEO done well builds pages from real data; the spam version rewrites the same paragraph five hundred times.
- Paid list placements. Buying a spot in a third-party list with a followed link is link spam under Google's policy, which also covers "advertorials or native advertising where payment is received for articles that include links that pass ranking credit". Sponsorship is allowed when the link carries
nofolloworsponsored. Paying for inclusion does not buy the reader's trust either. - Self-promotional listicles. No policy names them, and publishing a comparison that includes your own product is normal. The pattern in early-2026 reports combined volume, the publisher's own product always ranked first, and refreshed dates with little new content. Publish fewer comparisons, state how you ranked, and say where competitors win. Risk rises with volume, self-ranking, date-only refreshes and missing methods.
- Astroturfing. Forums and review sites rank among the most-cited domains in several AI citation studies, which invites fake accounts and seeded threads. Google treats spammy user-generated content as the host's problem, and platforms remove it; when they do, the citations disappear. A named brand account answering questions openly lasts longer.
- Expired domains and networks. Google's examples include "affiliate content on a site previously used by a government agency". Buying authority to host citations about yourself is the oldest form of the problem.
A self-audit for scaled content
Group pages by template, check what each group adds, and cut or merge groups that add nothing a reader could not find elsewhere.
- Export every indexable URL and group them by template or folder. Note how many pages each group gained in the last 12 months.
- Pull 90 days of Search Console impressions and clicks per URL. Flag groups where most pages earned no impressions at all.
- Sample 10 to 20 pages per flagged group. For each, write down one fact the page contains that the top three ranking pages for its query do not. If you cannot find one, mark the page. Information gain is a useful name for that test.
- Run a near-duplicate check across each group with your crawler, and read two flagged pages side by side.
- Record who wrote and who fact-checked each sampled page. Pages nobody reviewed are where errors and repetition hide.
- For comparison and "best of" pages, check three things: whether your product always ranks first, whether the method is stated, and whether competitors' strengths appear.
- Decide per group: improve, merge with a redirect, or remove. For content you keep but cannot fix yet, Google's own advice for scaled content is to "exclude it from Search" with noindex.
What to monitor while the September update rolls out
Watch rankings, AI citations and manual actions, and wait for the rollout to finish before you change anything.
| Signal | Where | What it tells you |
|---|---|---|
| Rollout status | Google Search Status Dashboard | Whether movement falls inside the update window |
| Clicks and impressions by page group | Search Console Performance report | Which templates or sections moved |
| Manual actions | Search Console Manual actions report | Whether a reviewer acted rather than an algorithm; site reputation abuse is enforced this way |
| AI Overviews and AI Mode impressions | Search Console Generative AI performance report | Whether pages lost AI surface eligibility along with rankings |
| Citations on your priority prompts | Prompt tracking across engines | Whether answers stopped citing you, or stopped citing the third-party pages that mentioned you |
| Third-party pages that cite you | Your citation list, rechecked in Google | Whether the listicles and directories that name you lost rankings themselves |
The last row is easy to miss. If your AI visibility depends on a few third-party pages, and those pages get hit, your citations fall even though your own site was untouched. Coverage of the August update noted that volatility continued after the rollout ended on August 21, so compare full weeks once things settle. Wait until Google marks the rollout complete on its status dashboard, then another week or two, before you read the movement as final.
Citlyze logs the pages each AI answer cites for your tracked prompts, so a source that drops out during an update shows up within days.
Becoming the source worth quoting
Publish what others need to cite: first-hand data, precise product facts, and comparisons with a stated method. Then let other sites repeat it.
- Put the facts buyers ask about on your own pages, in plain text: prices, limits, integrations, policies. Our breakdown of ChatGPT's citation choices shows why clear, specific pages get chosen.
- Publish numbers with their sample and date. Journalists and reviewers cite data they can check.
- Where you compare yourself with competitors, say how you compared, and say where they win.
- Keep your crawler access open and your pages indexable, and run the GEO audit checklist after each update.
A brand with real information can get most of what GEO spam promises by publishing that information well, without the risk of losing it at the next update. To see whether answers cite you during this update cycle, and which sources they cite instead, Citlyze tracks your prompts across the chat engines and Google's AI surfaces from $29 a month; a 14-day trial with no card covers one rollout window.