Back to News & Insights
SEO September 14, 2026 · 10 min read

Manipulating AI answers is officially spam, and it can get you deindexed

Since 15 May 2026, Google officially treats attempts to manipulate AI answers in Search as spam, with...

Manipulating AI answers is officially spam, and it can get you deindexed

Since 15 May 2026, Google officially treats attempts to manipulate AI answers in Search as spam, with the same sentence it uses for ordinary ranking spam. The penalty is the same framework: a site can rank lower, or not appear in results at all. Here is exactly what changed and what it means for you.

The same pitch keeps landing in my inbox: "for a monthly fee, ChatGPT and Perplexity will start recommending you". I'm Tair, and at DevNova I build websites and automations, we add schema and structured data on every project, so whether AI cites us is something I watch first-hand. And that exact pitch turned from a "growth hack" into a risk on 15 May 2026. I'll walk you through what Google changed, what is still fine, and where the line actually sits.

Contents The LinkedIn promise: write it so AI recommends you What Google changed on 15 May 2026 It targets AI Overviews and AI Mode Three tactics that are now spam The penalty: same framework, up to deindexation May 2026: the end of schema and AI-answer tricks What safe citability looks like (how we do it) Frequently asked questions The LinkedIn promise: write it so AI recommends you

Behind that LinkedIn message is always the same kind of seller, an agency or a self-styled "GEO expert" who, for a monthly retainer, promises "guaranteed recommendations from AI". They call it "GEO" or "AEO", optimization for generative answers, and the recipe they send next sounds simple. Write your pages so the models love them. Seed mentions of yourself into forums and review sites where AI pulls its citations. Add phrases like "the best in town" so the model recommends you. And suddenly, they claim, ChatGPT, Perplexity and Gemini all cite you.

It sounds tempting because part of it is true. Generative answers really are changing how people search, and being cited in them has value. The problem is where exactly the line runs between "make genuinely good content so models enjoy reading you" and "trick those models into recommending you". The first is legitimate work. The second is what Google named in May 2026 and threw into the same bucket as spam.

Optimizing for AI answers is not banned. Manipulating them is. There is a whole canyon between them. What Google changed on 15 May 2026

On 15 May 2026 Google rewrote the opening of its spam policies (the document itself is stamped "Last updated 2026-05-15"). The definition of spam used to talk about attempts to "manipulate Search systems into ranking content highly". Now the sentence continues with words that were not there before: "...or attempting to manipulate generative AI responses in Google Search". For the first time, manipulating an AI answer is named directly as spam.

And right after it comes the consequence, in black and white: "Sites that violate our policies may rank lower in results or not appear in results at all." This is not a new penalty for AI. It is the same sentence Google has used for years to cover ordinary spam. The change is in scope, not in punishment.

Google did not write a new penalty. It wrote that the old one now covers AI answers too. It targets AI Overviews and AI Mode

An important detail: the wording says "generative AI responses in Google Search", not just the classic blue links. Industry read-outs of the change (Search Engine Land among them) confirm it: the rule covers AI Overviews (the summaries above the results) and AI Mode (the conversational search mode). Trying to game your way into them is treated exactly like trying to game the ranking.

In practice that means one thing. If you have been treating AI Overviews as a "grey zone" where the rules do not apply yet and you can bend things, that zone just closed. Google explicitly said the same yardstick that governs results governs the AI summaries. Three tactics that are now spam

So what concretely falls under the new sentence? Google did not publish a closed list, but its policies and the industry coverage point to three recurring patterns: Biased "best of" rankings and listicles. A page that poses as an independent comparison ("the 5 best studios in town") but is engineered so the model lifts one specific name out of it, yours. The goal is not to inform the reader but to feed the answer. Sabotage through third-party forums and review sites. Deliberately seeding mentions and "reviews" where models pull their citations, so the AI remembers a recommendation that never came from real experience. Industry and security research coined a name for this class of attack, recommendation poisoning. Microsoft described it as manipulating the "memory" of AI systems. It is an industry term, not Google's wording, Google simply files it under spam. Prompt injection into your own pages. Hidden instructions in the text or code that a human does not read but a model does, designed to force it to recommend you. Invisible to the visitor, a script for the AI.

The common denominator is clear: the goal is not to serve the reader but to deceive the machine sitting between you and the reader. That is precisely what Google calls manipulation. The penalty: same framework, up to deindexation

Let us be precise here, because there is a lot of needless fear around this. Google did not introduce some new "AI death penalty". It used its existing spam framework, and that framework is a scale. At one end is a demotion: the site ranks lower. At the far end is what the document literally says, the page "may not appear in results at all", that is deindexation. Deindexation is the ceiling, not the standard rate.

And enforcement is not just theory in a document. On 24 June 2026 Google rolled out a separate June spam update, which finished on 26 June and runs on SpamBrain. These are two distinct events: 15 May was the policy text change, 24 June was the algorithmic wave that enforces it. By Google's own comments the June wave did not target link spam, which I read as a sign that other forms of manipulation are where the enforcement lands.

Deindexation is the ceiling, not the standard rate. But it is a ceiling you do not want to test.

Why is this serious even without panic? Because manual and algorithmic penalties are hard to appeal and even harder to recover from in time. If your growth in AI answers rests on a trick that falls under enforcement tomorrow, that growth is really risk with deferred maturity. May 2026: the end of schema and AI-answer tricks

May 2026 was not only about AI answers. Eight days before the policy change, on 7 May 2026, Google finally stopped showing FAQ rich results, those expandable questions under a link, for every site including the government and health sites that had kept them. This was not sudden: back in August 2023 Google already restricted FAQ rich results to well-known authoritative pages, a response to schema being abused by everyone. May 2026 just finished a slow burial.

Want to discuss this further?

Book a free strategy call with our team to see how these insights apply to your specific business goals.

Book a consultation