Google Adds GEO Manipulation to Spam Policy — AI Overviews and AI Mode Now Formally Protected
Google quietly updated its Search spam policy in mid-May 2026 to cover a new threat: deliberate manipulation of AI-generated results in AI Overviews and AI Mode. The policy change, first noticed by Search Engine Land and confirmed across multiple outlets, adds explicit language defining spam as “attempting to manipulate generative AI responses in Google Search.”
What Changed
The updated policy adds AI-targeting techniques alongside the existing spam categories: mass production of low-value pages, cloaking, and abuse of expired trusted domains. The new language specifically names:
- Hidden text or instructions embedded in webpage code to direct LLMs to cite a domain
- “Recommendation poisoning” — phrases designed to make an LLM treat a site as authoritative
- GEO (Generative Engine Optimization) — an industry now large enough to warrant its own policy category
Violations carry the same enforcement response as traditional spam: rank demotion or removal from results. Detection runs on both automated systems and human review.
Why It Matters
AI Overviews launched at scale in 2025 and now surface on a significant share of queries. As those summaries replace traditional ten-blue-links results for many users, the incentive to game AI citations rather than organic rankings has grown into a viable commercial strategy.
A BBC journalist demonstrated the scope of the problem earlier this year, successfully using GEO techniques to appear prominently in AI search outputs using methods that would not have moved the needle in traditional SEO. Google’s policy update formalises what enforcement teams were already doing informally.
The Enforcement Challenge
The update names the problem but detection is harder than traditional spam. Standard spam involves pattern-matching on content or link graphs. GEO manipulation is often invisible to users — hidden in metadata, structured data markup, or injected content that only an LLM sees during retrieval. Google has not disclosed which signals its automated systems use to distinguish GEO manipulation from legitimate structured markup.
The policy change also signals a broader shift: Google is now treating its AI-assisted search surfaces as first-class properties requiring spam protection on par with organic search, rather than as an experimental layer where gaming is tolerated.
Publishers that combined human expertise with AI assistance have reported greater resilience to the March 2026 enforcement update that preceded this policy formalisation. The policy appears to align penalty risk with content intent and authorship quality rather than the presence of AI in the content pipeline.