Last week I went looking for GEO advice on X. Real research, for a different article. What I found, I'm not exaggerating, was wall-to-wall prompt-pack funnels: the same account posting "200+ AI SEO Prompts" four times in an hour, a link-building ebook stapled to every reply, a free strategy call if you clicked through. Zero likes on most of them. Bot views. The whole thing had the exact texture of 2012-era guest-post spam, except the product was citations instead of backlinks.
That's when it stopped being a hypothetical for me. GEO spam isn't coming; the supply side already showed up. The demand side, panicked marketers watching their traffic charts sag, is walking in the door right now. And if you've watched search for any length of time, you know exactly how this movie goes, which is honestly good news, because it means you also know how it ends and who's left standing.
The Playbook Always Repeats
Every new discovery surface in the history of the web has run the same four-act play. A new system decides what people see. Someone figures out its inputs can be manufactured. An industry sprouts to manufacture them at scale. The system's owner, watching its results get worse, starts purging, and keeps purging forever.
Directories got stuffed. Meta keywords got stuffed. PageRank got link farms, then paid links, then PBNs. Helpful-content signals got AI filler. Each cycle, the manipulation industry moved faster than enforcement for a year or two, made real money, and then got wiped out at somebody else's update cadence, taking its customers' visibility with it.
Generative engines are the newest system that decides what people see, and their input surface is honestly juicier than PageRank ever was. An AI answer cites sources. Sources can be manufactured. An AI answer trusts consensus. Consensus can be seeded. You don't need to be a cynic to see the arbitrage; you just need to have been alive for SEO.
One difference this cycle, and it cuts against the spammers: the enforcement loop got faster. Google's purges arrived quarterly, announced, with a dashboard entry you could set your watch by. Model-side enforcement arrives whenever a lab ships weights, silently, worldwide, all at once. The window between "tactic discovered" and "tactic repriced" used to be measured in years. Forum seeding's window closed in about a week this August. Whatever the GEO spam industry builds, it's building on a floor that can vanish between a Tuesday and a Thursday, and its customers are the ones standing on it.
What GEO Spam Looks Like Right Now
This isn't speculative. The specimens are already in the wild, and most of them are dressed as legitimate services.
Citation-farm content: networks of "review" and "best of" sites that exist purely to be retrievable by AI engines, selling placement the way PBNs sold links. Fake authority domains with official-sounding names, built because retrieval started favoring official-looking sources. Forum seeding, which was the workhorse tactic right up until GPT-5.6 killed its ROI overnight. Agencies with "guaranteed AI citations" on the pricing page, a promise nobody can keep for the simple reason that citations churn about 45% every time an answer regenerates.
And my favorite specimen, because the data on it is so brutal: the self-promotional listicle. One 100-query B2B study found that when brands published their own "best tools" roundups, 69% of the AI Overview citations those pages earned appeared in answers recommending their competitors. You did the work, the engine took the inventory, and the answer sent the buyer somewhere else. Chef's kiss.
Fair warning though: some of this stuff will appear to work for a while. That's the trap. PBNs "worked" too, right up until the update that made them a liability you had to disavow. Renting visibility from a manipulation vendor means your asset lives on their infrastructure, and their infrastructure is always one enforcement wave from worthless.
AI search traffic grew 835% this year. Is your content ready?
RankControl generates 26 content formats optimized for ChatGPT, Claude, and Perplexity. Published on your domain, matched to your brand.

A Field Guide To Spotting GEO Snake Oil
Because the pitches are landing in founder inboxes right now, here's the taxonomy I'd keep taped to the monitor. Five phrases, five tells.
"Guaranteed AI citations." The churn math forbids the promise. Roughly 45% of cited sources change every time an answer regenerates, and model updates reshuffle the rest without notice. Anyone guaranteeing placement in that system is either lying or renting you something fragile enough to be worthless.
"We know how the algorithm picks sources." Which one? There are six engines that matter and they visibly disagree with each other, sometimes about the same query in the same week. A vendor who claims one algorithm is describing a product category they haven't measured.
"Our proprietary network of authority sites." That's a citation farm with a brand kit. You'd be paying to attach your name to exactly the infrastructure the next enforcement wave is built to find, and unlike the vendor, you can't churn your domain when it burns.
"Look at these results." Check the screenshots for dates and repetition. An undated screenshot of ChatGPT citing a client is a lottery ticket photographed at the moment of winning; regeneration churn means the same prompt an hour later may say something else. Real measurement shows trend lines across weeks, per engine, or it's theater.
"llms.txt optimization package." We ran llms.txt across 12 sites for 90 days and measured nothing. Google says it doesn't use the file. A vendor leading with it is selling the easiest deliverable, and that tells you what the rest of the invoice looks like.
The meta-rule underneath all five: anything sold as a shortcut to being trusted is, definitionally, the thing trust systems are being tuned to catch.

Built by the team that got cited in 48 hours.
Content generation, backlink building, AI visibility tracking, and Google rankings. One platform, zero guesswork.
Let Me Steelman The Other Side For A Second
Slight detour, but this matters, because I don't want to pretend the spammers are stupid. They're not, and the uncomfortable truth is that early manipulation usually does pay for a while. Guest-post spam paid. PBNs paid. The people who ran them, took profits, and churned domains did fine, and some of the GEO equivalents will do fine too. If you run disposable affiliate sites, honestly, the arbitrage might even be rational. Burn the domain, keep the margin, next.
Here's why that math still says no for a SaaS company, and it's an asymmetry, not a moral position. Your brand is the one domain you can't churn. Every trend in retrieval right now, entity resolution, licensing, official-source weighting, makes identity more persistent, which means a burned reputation follows you into every engine that can cross-reference. The affiliate spammer risks a website. You'd be risking the thing your whole company resolves to when a model asks "who are these people and can I trust them?" Downside asymmetry that steep turns a maybe-profitable tactic into a bad trade even when it works.
And the part the sales deck never mentions: the tactic doesn't need to be caught to fail you. It just needs the surface it rents to reprice, the way forum seeding repriced in one August week. Nobody at those agencies refunded the retainers.
The Crackdowns Already Started
Here's the part I think most marketers haven't fully processed: the first GEO enforcement wave already happened. It just wasn't announced as one.
Look at August as a single event. Google ran a spam update that made a top-10 URL 1.8 times more likely to fall out of the top 100 than in a normal week. The same fortnight, GPT-5.6 rewired ChatGPT's retrieval: site-scoped queries jumped from under half a percent to 17-23% of searches, "official" became a favorite retrieval term, and forum citations collapsed by at least 73% while overall citations rose. Two engines, zero coordination, one direction: stop trusting manufactured consensus, start trusting verifiable entities.
Now project forward, because the incentives only sharpen. Answer engines are staking their products on answer quality, and ads just entered the picture, which means polluted answers now cost someone revenue directly. I'd bet on three things arriving within a year: published spam policies for answer manipulation, the way Google formalized link spam. Provenance and verification signals getting explicit weight, because licensing deals already showed engines will pay for trustable sources. And enforcement that runs on model-update cadence with no changelog, which, quick reality check, is worse for spammers than Google's dashboard-announced updates ever were. You can't file a reconsideration request with a model weight.
What Survives Every Purge
So what do you build, knowing the purges are structural? The boring answer is the true one: you build the things enforcement waves are trying to find, because every crackdown is really a filter searching for evidence that you exist.
Extraction-ready content on a domain you own. Entity facts that agree with each other everywhere they appear: your site, review platforms, partner pages, the knowledge bases models consult. Real reviews from real users, real mentions in places you don't control, first-party numbers only you can publish, docs that answer questions like a person who's met the product. The four disciplines that replaced the checklist, basically, none of which a spam vendor can sell you, because all of them require the inconvenient step of being a real company.
Here's something from our side of the glass that I haven't seen said elsewhere. We re-run buyer queries across six engines every week, and the thing that struck me in August wasn't the reshuffle itself. It was which brands barely moved. The ones with deep corroboration, consistent entity footprints, actual reviews, and their own cited data, wobbled for a week and re-settled. The ones riding one strong surface, and it was usually Reddit, dropped and stayed dropped. Same category, same week, completely different outcomes, and the difference was never cleverness. It was how many independent places the engine could check them.
That's the whole thesis, really. Verification is the moat. Spam is, by definition, the thing that can't survive being checked.
My Actual Advice
If I'm being honest, the GEO spam wave is going to be great for exactly one group: companies that were already doing the durable work. Every enforcement cycle clears rented visibility off the shelves and re-ranks whoever's left, which means each purge is a free distribution event for the verifiable. The founders getting outranked by farms today are the ones positioned to inherit the shelf, if they don't burn the interim buying shortcuts.
So: when a vendor promises citations, walk. When a tactic works because it fools a model, put an expiry date on it mentally, because the model's owner already has. Spend the budget on depth, corroboration, and first-party data. And measure per engine, weekly, because enforcement now arrives silently and the only way to see a purge, or your own inheritance moment, is to be watching when it lands.
If you want that as a quarter's worth of actual work instead of a vibe, here's my version. Week one: audit where your current AI citations come from, and label every source the way an enforcement engineer would: owned, earned, infrastructure, or farm. Anything in the farm column is exposure, even if you didn't put it there. Weeks two and three: cancel anything contractual that smells like the field guide above, and yes, that conversation is awkward, and yes, do it anyway. The rest of the quarter: pour the reclaimed budget into two deep pieces only you could write, one first-party data asset, and the unglamorous corroboration work of reviews and profile consistency. Then keep the weekly watch running, which is a few hours by hand, or the thing RankControl's agents do continuously while you build product.
Wait, scratch one thing. I said the weekly watch is a few hours. It's a few hours the first month. It's the months after that where every manual process I've ever watched dies quietly, and the reshuffles don't schedule themselves around your busy weeks. Plan for that, however you choose to solve it.
The next wave is not an if. Build like you're planning to still be cited after it, because somebody in your category will be, and the purge is what decides who.
See your first AI citation report in under 5 minutes.
No setup calls. No onboarding meetings. Connect your domain and see where AI mentions your brand right now.




