SEO2026-07-24 · 11 min

Manipulating AI answers is officially spam, and it can get you deindexed

Since 15 May 2026 Google's rules carry a sentence that calls manipulating AI answers spam. The penalty is the same as for ordinary spam, from a lower rank all the way to vanishing from results. I explain what exactly changed, how it connects to the June spam update, and how to stay cited in AI answers without the risk.

by Tair Khamitov
Manipulating AI answers is officially spam, and it can get you deindexed
Contents·11 sections
  1. 01Contents
  2. 021. The LinkedIn promise: write it so AI recommends you
  3. 032. What Google changed on 15 May 2026
  4. 043. It targets AI Overviews and AI Mode
  5. 054. Three tactics that are now spam
  6. 065. The penalty: same framework, up to deindexation
  7. 076. May 2026: the end of schema and AI-answer tricks
  8. 087. What safe citability looks like (how we do it)
  9. 09Frequently asked questions
  10. 10About the author
  11. 11External sources

Since 15 May 2026, Google officially treats attempts to manipulate AI answers in Search as spam, with the same sentence it uses for ordinary ranking spam. The penalty is the same framework: a site can rank lower, or not appear in results at all. Here is exactly what changed and what it means for you.

The same pitch keeps landing in my inbox: "for a monthly fee, ChatGPT and Perplexity will start recommending you". I'm Tair, and at DevNova I build websites and automations, we add schema and structured data on every project, so whether AI cites us is something I watch first-hand. And that exact pitch turned from a "growth hack" into a risk on 15 May 2026. I'll walk you through what Google changed, what is still fine, and where the line actually sits.

Contents

1. The LinkedIn promise: write it so AI recommends you

Behind that LinkedIn message is always the same kind of seller, an agency or a self-styled "GEO expert" who, for a monthly retainer, promises "guaranteed recommendations from AI". They call it "GEO" or "AEO", optimization for generative answers, and the recipe they send next sounds simple. Write your pages so the models love them. Seed mentions of yourself into forums and review sites where AI pulls its citations. Add phrases like "the best in town" so the model recommends you. And suddenly, they claim, ChatGPT, Perplexity and Gemini all cite you.

It sounds tempting because part of it is true. Generative answers really are changing how people search, and being cited in them has value. The problem is where exactly the line runs between "make genuinely good content so models enjoy reading you" and "trick those models into recommending you". The first is legitimate work. The second is what Google named in May 2026 and threw into the same bucket as spam.

Optimizing for AI answers is not banned. Manipulating them is. There is a whole canyon between them.

2. What Google changed on 15 May 2026

On 15 May 2026 Google rewrote the opening of its spam policies (the document itself is stamped "Last updated 2026-05-15"). The definition of spam used to talk about attempts to "manipulate Search systems into ranking content highly". Now the sentence continues with words that were not there before: "...or attempting to manipulate generative AI responses in Google Search". For the first time, manipulating an AI answer is named directly as spam.

And right after it comes the consequence, in black and white: "Sites that violate our policies may rank lower in results or not appear in results at all." This is not a new penalty for AI. It is the same sentence Google has used for years to cover ordinary spam. The change is in scope, not in punishment.

Google did not write a new penalty. It wrote that the old one now covers AI answers too.

3. It targets AI Overviews and AI Mode

An important detail: the wording says "generative AI responses in Google Search", not just the classic blue links. Industry read-outs of the change (Search Engine Land among them) confirm it: the rule covers AI Overviews (the summaries above the results) and AI Mode (the conversational search mode). Trying to game your way into them is treated exactly like trying to game the ranking.

In practice that means one thing. If you have been treating AI Overviews as a "grey zone" where the rules do not apply yet and you can bend things, that zone just closed. Google explicitly said the same yardstick that governs results governs the AI summaries.

4. Three tactics that are now spam

So what concretely falls under the new sentence? Google did not publish a closed list, but its policies and the industry coverage point to three recurring patterns:

  • Biased "best of" rankings and listicles. A page that poses as an independent comparison ("the 5 best studios in town") but is engineered so the model lifts one specific name out of it, yours. The goal is not to inform the reader but to feed the answer.
  • Sabotage through third-party forums and review sites. Deliberately seeding mentions and "reviews" where models pull their citations, so the AI remembers a recommendation that never came from real experience. Industry and security research coined a name for this class of attack, recommendation poisoning. Microsoft described it as manipulating the "memory" of AI systems. It is an industry term, not Google's wording, Google simply files it under spam.
  • Prompt injection into your own pages. Hidden instructions in the text or code that a human does not read but a model does, designed to force it to recommend you. Invisible to the visitor, a script for the AI.

The common denominator is clear: the goal is not to serve the reader but to deceive the machine sitting between you and the reader. That is precisely what Google calls manipulation.

5. The penalty: same framework, up to deindexation

Let us be precise here, because there is a lot of needless fear around this. Google did not introduce some new "AI death penalty". It used its existing spam framework, and that framework is a scale. At one end is a demotion: the site ranks lower. At the far end is what the document literally says, the page "may not appear in results at all", that is deindexation. Deindexation is the ceiling, not the standard rate.

And enforcement is not just theory in a document. On 24 June 2026 Google rolled out a separate June spam update, which finished on 26 June and runs on SpamBrain. These are two distinct events: 15 May was the policy text change, 24 June was the algorithmic wave that enforces it. By Google's own comments the June wave did not target link spam, which I read as a sign that other forms of manipulation are where the enforcement lands.

Deindexation is the ceiling, not the standard rate. But it is a ceiling you do not want to test.

Why is this serious even without panic? Because manual and algorithmic penalties are hard to appeal and even harder to recover from in time. If your growth in AI answers rests on a trick that falls under enforcement tomorrow, that growth is really risk with deferred maturity.

6. May 2026: the end of schema and AI-answer tricks

May 2026 was not only about AI answers. Eight days before the policy change, on 7 May 2026, Google finally stopped showing FAQ rich results, those expandable questions under a link, for every site including the government and health sites that had kept them. This was not sudden: back in August 2023 Google already restricted FAQ rich results to well-known authoritative pages, a response to schema being abused by everyone. May 2026 just finished a slow burial.

I know this one from my own work. For years FAQ schema was sold as "easy stars in search". We kept it on sites for a different reason, because of how language models read it, and told clients outright not to expect a rich result from it anymore. Anyone still ordering FAQ schema "for the rich results" in 2026 is buying last year's snow. To be precise: FAQ rich results are gone, but local-business results and star reviews still work, let us not blur the two.

In 2026 schema will not earn you FAQ stars. It earns you readability for the models. That is a different game.

See the pattern? Google is systematically closing shortcuts. First schema tricks (rich results for FAQ), now AI-answer tricks. Whoever builds on shortcuts keeps hitting the same wall. Whoever builds on depth walks around it.

7. What safe citability looks like (how we do it)

The good news: the way into AI answers without risk is boring, and that is exactly why it works. Models cite for the same reasons Google moves you up: real depth, a credible author, correct technical basics. ZERO tricks. Here is how we approach it on projects:

  • Real content with depth and a date. Text that actually answers the question, with a named author (Person in structured data) and a modified date. That is what models and Google read as a trust signal, not as a trick.
  • Correct schema, not schema to deceive. On every project we ship the same structured-data baseline — Article, Person and LocalBusiness JSON-LD, plus FAQPage or Dataset where it fits. We mark via schema.org what the page genuinely is, a business, a product, an article, an author, so models and the search engine understand you and can cite you correctly. Not to pretend you are something you are not. That difference is the whole difference between legitimate work and spam.
  • Speed and clean structure. A model and a search engine pull text, headings and data, not pretty graphics. That is why we build on custom code, where we know exactly what a page contains and how fast it loads.

What it looks like in practice: when we do SEO and content, we do not start from "how do we trick the model" but from "what question should this client be the best answer to on the internet". Then we write and tag the page so that it is true, and verify it through the Rich Results Test and Search Console. How exactly this differs from a generator-built site that "looks SEO-ready" I lay out in whether AI-built sites are good for SEO. Ballpark prices for this work are always public in the pricing.

And honestly about the line too: if you came to me wanting to "feed" forums with mentions or hide instructions for a model inside a page, I would say NO. Not out of caution, but because that is exactly what now falls under enforcement, and I will not sell you risk wrapped as growth.

If you want to know where you actually stand in AI answers, I will run a GEO/SEO check: are you growing in AI answers safely, or one manual action away from a penalty? Write via contact and I will tell you straight what is fine and what I would change. No strings attached.

Frequently asked questions

Do FAQ or How-To schema still earn a rich result in 2026? No. Google stopped showing FAQ rich results on 7 May 2026 for all sites (they were already restricted from August 2023). Schema still matters, but as a signal for language models and page understanding, not as a path to stars.

Is optimizing for AI Overviews (GEO) against Google's rules? No, optimization itself is not. What is banned is manipulation, tricks that deceive the model into recommending you. Making genuinely deep content that AI is happy to cite is legitimate and encouraged.

What exactly did Google change on 15 May 2026? It added a line to the definition of spam saying spam includes "attempting to manipulate generative AI responses in Google Search". For the first time, manipulating an AI answer is named directly as spam.

Can a site really be deindexed for trying to influence an AI answer? In the extreme case yes, the document says a page "may not appear in results at all". But that is the ceiling of the framework, not the standard. The more common consequence is a demotion. It is not a new AI death penalty, it is the existing spam penalty.

Is "recommendation poisoning" Google's official term? No. It is an industry and security label (Microsoft described it too) for seeding manipulative mentions where AI pulls its citations. Google does not use the phrase, it simply files that kind of attempt under spam.

What is the difference between the 15 May policy change and the June 2026 spam update? They are two things. 15 May was the policy text change (what counts as spam). 24 June was the algorithmic wave (the June spam update, completed 26 June) that actually enforces the rules through SpamBrain.

How do I get cited by AI safely, without risking a penalty? Through honest depth: real content, a named author, a modified date, correct schema and a fast page. No hidden instructions for models, no fake reviews. Boring, but risk-free, and long term it is the only thing that works.

About the author

Tair Khamitov runs DevNova in Bratislava, a web studio that builds websites, e-shops and AI automation for small and mid-sized businesses across Central Europe. He translates regulatory and search changes into the language of "what do I actually do with my page". This is not legal advice, it is an orientation overview from practice. Contact: b2b@devnova.eu.

External sources

Next step

Interesting read? Real projects cost less than this article suggests. Open pricing + 11-day delivery cycle.

Google now treats gaming AI answers as spam (May 2026 policy)