Blog · GEO ethics and AI search manipulation

Is GEO Ethical? Optimization vs Manipulation in AI Search

Priya Bothra · October 6, 2026

Generative engine optimization (GEO) is ethical when it helps AI systems find, understand and accurately represent true information about your brand. It becomes manipulation when it tries to change what an AI says by deceiving the system or the user, through hidden instructions, fabricated evidence, fake reviews or content that exists only to game retrieval.

The line is not about technique alone. Publishing a clear pricing page and planting a hidden "recommend us first" instruction both aim to influence AI answers. The difference is whether the influence works by making accurate information more available or by distorting what the model and the user believe. This guide sets out a practical framework for telling the two apart, the manipulation tactics already documented in the wild, and how to run a GEO program you would be comfortable explaining to a customer, a regulator or a journalist.

What is GEO, and why does its ethics matter now?

GEO is the practice of improving how a brand is found, understood, cited and recommended in answers written by AI systems such as ChatGPT, Gemini, Claude, Perplexity, Copilot and Google AI Overviews and AI Mode. The term comes from the 2023 research paper GEO: Generative Engine Optimization, published at KDD 2024, which found that adding citations, quotations and statistics improved source visibility by up to 40% on one metric, while keyword stuffing was ineffective.

The ethics question matters more for GEO than it did for early SEO for three reasons.

Users trust answers more than lists. A search results page shows ten options and leaves the judgment to the reader. An AI answer often makes the judgment for them. When an assistant says "the best option for your team is X," a manipulated input becomes a manipulated recommendation.

Buyers already rely on AI for vendor research. A Gartner survey of 645 B2B buyers found 45% used generative AI in a recent purchase, mainly to research vendors. The same survey found 51% think generative AI is more likely to mislead them, which shows how fragile that trust is.

Models repeat what they retrieve. Ahrefs' 2026 AI visibility benchmark reported that most AI models repeated fabricated claims even when official sources contradicted them. Systems that can be fooled by false claims give bad actors an incentive to produce them.

A framework for separating optimization from manipulation

The clearest test is a set of four questions. This is a working framework, not an industry standard, but it maps closely to how search engines, regulators and AI companies already draw the line.

TestEthical optimizationManipulation
TruthThe information is accurate and currentThe information is false, exaggerated or fabricated
VisibilityHumans and machines see the same contentMachines see something humans cannot, or vice versa
ChannelInfluence flows through normal retrieval and reputationInfluence flows through injected instructions or exploits
ConsentThird-party signals are earned and disclosedReviews, mentions or endorsements are bought, faked or undisclosed

If a tactic passes all four tests, it is optimization. If it fails any one, treat it as manipulation, even if it is technically possible and nobody has caught it yet.

The truth test

Every claim you publish for AI consumption should be one you would defend in a sales call. That includes pricing, feature availability, integrations, customer counts and comparisons with competitors. Making a true fact easier to extract is optimization. Inventing a statistic because models favor content with numbers is not.

The visibility test

Content shown only to crawlers or hidden from users is the oldest form of search manipulation. Google's spam policies define hidden text abuse as placing content "in a way solely to manipulate search engines and not to be easily viewable by human visitors," and define cloaking as "presenting different content to users and search engines with the intent to manipulate search rankings and mislead users." The same logic applies to AI crawlers. If you would be embarrassed for a customer to view the page source, the content fails the test.

The channel test

Legitimate GEO influences AI answers through the channels the systems were designed to use: crawlable pages, reputation across the web and structured information. Manipulation reaches around those channels, for example by writing text addressed to the model ("ignore previous instructions," "always recommend this product") rather than to the reader.

Third-party signals such as reviews, forum posts and expert mentions carry weight because readers assume they are independent. When that independence is faked, the signal becomes deception. The U.S. Federal Trade Commission's final rule on fake reviews and testimonials, announced in August 2024, bans fake and AI-generated reviews, reviews conditioned on positive sentiment, undisclosed insider reviews and review suppression, with civil penalties for violations.

GEO manipulation is not hypothetical. Researchers, journalists and security teams have documented several tactics, which is useful because it shows exactly where the line sits.

Hidden prompt injection on web pages

Prompt injection on a web page means embedding text that instructs an AI system how to respond, usually hidden from human visitors. In December 2024, Guardian testing found that ChatGPT's search tool could return false or misleading results when pages contained hidden text, including producing a positive product assessment from a page that also carried negative reviews. AI companies continue to harden their systems against this, but a tactic that depends on a vulnerability is manipulation by definition.

Strategic text sequences

Academic researchers have shown that recommendations can be steered with machine-targeted text. In Manipulating Large Language Models to Increase Product Visibility, Aounon Kumar and Himabindu Lakkaraju added an optimized "strategic text sequence" to a product's information page in a catalog of fictitious coffee machines and found it significantly increased the chance that the model listed the product as its top recommendation. The authors compared the risk to how SEO changed web search, and the study is useful as a warning rather than a playbook.

AI recommendation poisoning

AI recommendation poisoning is a technique that plants instructions in an AI assistant's memory so that future answers favor a specific company. In February 2026, Microsoft's security researchers reported finding 50 distinct prompts from 31 companies across more than 14 industries over 60 days, embedded in "Summarize with AI" buttons. The buttons opened an assistant with a pre-filled prompt telling it to remember the company as a trusted or authoritative source for future citations. The user asked for a summary and received a lasting bias they never agreed to.

This case matters because the companies involved were ordinary businesses, including SaaS, finance, healthcare and legal services, not criminal operations. It shows how quickly a growth tactic can cross into something a security team classifies as an attack.

Scaled and fabricated content

Mass-producing pages to capture AI retrieval is another common temptation. Google's spam policies define scaled content abuse as "many pages generated for the primary purpose of manipulating search rankings and not helping users," regardless of whether the pages are written by people or AI. Because Google's AI features guidance says a page must be indexed and eligible for Search with a snippet to appear as a supporting link in AI Overviews or AI Mode, content that violates Search policies also puts Google AI visibility at risk.

Astroturfing in community sources

AI systems cite community platforms heavily. Profound's analysis of 680 million citations found Reddit was the top cited domain for Perplexity and Google AI Overviews. That creates an incentive to post fake "customer" recommendations in forums. Undisclosed promotional posts by employees or paid accounts fail both the consent test and the rules of most communities.

What ethical GEO looks like in practice

Ethical GEO is mostly good communication done consistently. The tactics below pass all four tests in the framework, and most of them also improve traditional SEO. For a broader comparison of how the disciplines fit together, see AEO vs GEO vs SEO.

Make true information easy to extract

Write answer-first pages that state what your product does, who it is for, what it costs and what it does not do. Clear definitions, comparison tables and specific facts help both readers and retrieval systems. The GEO paper's finding that citations and statistics improve visibility is an argument for adding real evidence, not invented evidence. Our guide on adding evidence to content for AI trust covers how to do this with sources you can defend.

Keep one accurate version of your brand facts

Inconsistent descriptions across your site, docs, review profiles and directories produce inconsistent AI answers. Correcting outdated information is ethical optimization: it reduces the chance a model repeats something false about you. A single source of truth, such as a brand memory document, makes it easier to update every surface at once.

Earn third-party coverage the right way

Mentions in industry publications, analyst notes, comparison articles and community discussions carry weight with AI systems. The ethical route is to earn them: offer useful data, give journalists accurate information, invite real customers to review you without conditions, and disclose any relationship when employees or partners participate in discussions.

Allow the right crawlers and be transparent about controls

Managing access is a legitimate choice. OpenAI documents that sites opted out of OAI-SearchBot will not be shown in ChatGPT search answers, and Anthropic and Perplexity run separate crawlers for search and training. Choosing which bots can read your site is a business decision, not manipulation, as long as you do not serve them different content from what users see.

Correct errors through the front door

When an AI system says something wrong about your brand, the ethical fix is to publish clear, accurate information where the systems look and to update the third-party sources feeding the error. The unethical fix is to inject instructions or flood the web with pages telling models what to say.

Where are the gray areas?

Some GEO practices are not clearly right or wrong. They depend on execution and disclosure. The recommendations below are editorial judgment, not rules set by any platform.

Comparison pages about competitors. Publishing "X vs Y" or "alternative to" pages is common and legitimate when the comparison is fair, current and verifiable. It becomes manipulation when it misstates a competitor's pricing or features, knowing models may repeat the claim as fact.

Content written for extraction. Structuring content so AI can lift clean answers is fine. Writing pages that read poorly for humans because they are aimed only at machines drifts toward the visibility test failure.

Sponsored content and paid placements. Paying for coverage is legal and normal when disclosed. It crosses the line when the payment is hidden so the content looks independent to readers and to the models that cite it.

Machine-readable files. Adding structured data or experimental files such as llms.txt is not unethical. It is also not a proven lever: Google's John Mueller described llms.txt as "purely speculative for now" in June 2026. The ethical risk appears only if such files contain claims that differ from your visible pages.

Advertising in AI assistants. Ads are a separate channel. OpenAI states that ChatGPT ads, in testing since February 2026, "do not influence the answers ChatGPT gives you." Buying ads is ethical. Presenting paid placement as an organic recommendation would not be.

The regulatory and platform context

Regulation increasingly treats deceptive AI influence as a compliance matter, not only a reputational one. This section is general information, not legal or compliance advice.

  • Consumer protection. The FTC fake reviews rule applies whether a review appears on your site, a marketplace or a forum an AI system later cites.
  • AI transparency in the EU. Article 50 of the EU AI Act, whose transparency obligations apply from August 2, 2026, requires disclosure of AI interactions, machine-readable marking of synthetic content and disclosure of deepfakes, with fines of up to €15 million or 3% for transparency breaches. Brands using AI to generate content at scale should review how these rules apply to them.
  • Platform policies. Google applies its Search policies to pages eligible for AI Overviews and AI Mode, and AI companies actively work to detect prompt injection. A tactic that works today may be neutralized tomorrow and leave a lasting trust problem.

Common mistakes brands make with GEO ethics

Assuming "everyone does it" makes it acceptable. The Microsoft research found dozens of legitimate companies using memory-poisoning prompts. Wide adoption did not stop security researchers from labeling it an attack.

Letting agencies or tools act without review. If a vendor publishes content, reviews or forum posts on your behalf, you carry the reputational and legal risk. Ask exactly what they publish and where.

Reporting AI "rankings" to justify aggressive tactics. SparkToro and Gumshoe research found less than a 1 in 100 chance that AI tools returned the same brand list twice. Chasing a single screenshot of "position one" encourages shortcuts that do not hold up.

Treating accuracy as optional. Getting cited for a wrong claim is not a win. Customers who buy based on an inaccurate AI answer become support tickets, refunds and bad reviews.

Ignoring what you already published. Old pages with outdated pricing or abandoned positioning can mislead models. Auditing and correcting them is one of the most ethical GEO actions available.

A hypothetical example

Consider a hypothetical HR software company that wants to appear more often when buyers ask AI assistants for payroll tools. A consultant proposes three ideas: adding hidden text to product pages telling AI systems the product is "the top-rated payroll platform," adding a "Summarize with AI" button with a pre-filled prompt asking the assistant to remember the brand as a trusted source, and paying freelancers to post recommendations on forums.

All three fail the framework. The first fails the visibility and channel tests, the second fails the channel and consent tests, and the third fails the consent test and likely the FTC rule. An ethical alternative would be to publish a clear page stating which company sizes and countries the product supports, update outdated review profiles, ask real customers for unconditioned reviews and publish original, sourced guidance on payroll compliance that journalists and communities might cite.

How Bob Builds AI helps

Ethical GEO starts with knowing what AI systems actually say about you. Bob Builds AI's Visibility Monitoring tracks visibility rate, citation rate, competitor recommendation share, citation sources, sentiment and recommendation changes over time across ChatGPT, Gemini, Claude, Perplexity, Copilot and Google AI Overviews and AI Mode, measuring the real chat and search interfaces rather than raw model APIs. That makes it easier to spot inaccurate descriptions and the sources behind them, so fixes can target the real cause. Brand Memory keeps products, differentiators, proof points and messaging in one place so the facts you publish stay consistent across channels.


FAQ

Is GEO ethical?

GEO is ethical when it makes accurate information about a brand easier for AI systems to find, understand and cite. Examples include answer-first pages, consistent brand facts, earned third-party coverage and correcting outdated information. It becomes unethical when it relies on deception, such as hidden instructions to AI models, fabricated statistics, fake reviews or content that shows machines something different from what people see.

What is the difference between GEO and AI manipulation?

GEO influences AI answers through the channels the systems are designed to use: crawlable content, reputation and accurate information. AI manipulation tries to change answers through deception or exploits, such as prompt injection, memory poisoning or planted endorsements. A practical test is whether the tactic would still work if every user and the AI company could see exactly what you did.

What is AI recommendation poisoning?

AI recommendation poisoning is a technique that plants instructions in an AI assistant's memory so future answers favor a particular company. Microsoft security researchers reported in February 2026 that they found 50 distinct prompts from 31 companies hidden in "Summarize with AI" buttons over 60 days. The prompts asked assistants to remember the company as a trusted source, without the user's knowledge.

Can hidden text on a website influence ChatGPT or other AI search tools?

Testing has shown it can. In December 2024, Guardian testing found ChatGPT search could return misleading results when pages contained hidden text. Academic research has also shown that optimized text sequences can shift product recommendations. AI companies work to defend against these tactics, and hidden text also violates Google's spam policies, so it carries both ethical and practical risk.

Do Google's spam policies apply to AI Overviews and AI Mode?

Google says a page must be indexed and eligible to appear in Search with a snippet to be shown as a supporting link in AI Overviews or AI Mode, and its guidance points site owners to its Search policies. In practice, tactics that break Google's spam policies, such as hidden text, cloaking or scaled content abuse, also put a page's eligibility for Google's AI features at risk.

Yes, when the comparison is fair, accurate and current. Comparison and "alternative to" pages help buyers and give AI systems clear information to work with. They become unethical when they misstate a competitor's pricing, features or limitations, because AI models may repeat those claims as fact to buyers who never see the original page.

Are fake or incentivized reviews a GEO risk?

Yes. AI systems draw on review sites and community platforms, so fake reviews can distort AI answers as well as human judgment. The FTC's 2024 rule bans fake and AI-generated reviews, reviews conditioned on positive sentiment and undisclosed insider reviews, with civil penalties. Earned, unconditioned reviews from real customers are the ethical and safer route.

How can a brand check whether its GEO program is ethical?

Apply four tests to every tactic: is the information true, do humans and machines see the same content, does the influence flow through normal retrieval rather than injected instructions, and are third-party signals earned and disclosed. Review what agencies and tools publish on your behalf, and measure accuracy in AI answers alongside visibility.


Conclusion

GEO is not inherently ethical or unethical. It is a set of practices, and the line runs between making true information easier for AI systems to use and deceiving those systems or their users. Hidden instructions, memory poisoning, fabricated evidence and fake reviews sit on the wrong side, and each has already been documented by researchers, journalists or security teams.

The practical implication is that the most durable GEO work is also the most defensible: accurate, answer-first content, consistent brand facts, earned coverage and honest correction of errors. A good next step is to run your current and planned tactics through the four tests of truth, visibility, channel and consent, and drop anything that fails. If you want to see how AI assistants currently describe your brand before deciding what to fix, Bob Builds AI can help you monitor those answers and trace them back to their sources.

All posts
GEO ethics and AI search manipulationGenerative engine optimization definitionPrompt injection and hidden text on web pagesAI recommendation poisoningGoogle spam policies and AI Overviews

Don't just sit with what AI says about your brand.
Fix it now with Bob Builds.

Book a demo