---
title: "Can GEO be used to push false information into AI answers?"
description: "Yes. In tests, one planted page made AI systems recommend a fake product in up to 27% of cases, and fabricated evidence was treated as real."
canonical: "https://underneath.agency/resources/can-geo-push-false-information-into-ai-answers"
published: 2026-10-07
updated: 2026-10-08
publisher: "Underneath (https://underneath.agency/agent)"
entity: "https://underneath.agency/.well-known/entity.json"
---
Guide · AI search

# Can GEO be used to push false information into AI answers?

Yes: researchers have shown that a few planted pages can make AI systems recommend products that do not exist, and that invented evidence is often taken at face value. GEO itself is not dishonest, but the same techniques that make good content easy to cite can make weak or false claims look well supported. For brands, the risk runs both ways: false claims about you, and false claims that crowd out your accurate ones.

## The short version

1. In a test of 12 AI systems on 225 real products, one fake-review page at the top of the search results led to a fake product being recommended in up to 27% of cases; with the top three results polluted, up to 73.8% ([Luo and Chen](https://arxiv.org/abs/2606.13610)).
2. When fooled, AI systems added invented social proof, such as claims of community popularity, 1.5 to 11 times more often than when they resisted (Luo and Chen).
3. Fabricated clinical-trial claims beat a famous skincare brand in 73.3% of head-to-head tests across three commercial AI systems ([Chu and Hou](https://arxiv.org/abs/2606.17443)).
4. An audit of real Google and Gemini results estimated that 8.90% of pages showed signs of GEO, and 69.34% of the citations on those pages pointed to sources that were hard to verify ([Chu and colleagues](https://arxiv.org/abs/2608.16824)).
5. AI answers repeat their sources’ weaknesses: in [our Reddit study](https://underneath.agency/research/ai-reddit-citations-study), 20.8% of sentences citing a Reddit thread were not supported by it.

## How could GEO make a false claim look well supported?

By building a chain of pages that appear to confirm each other. [Chu and colleagues](https://arxiv.org/abs/2608.16824) describe the basic move. An operator publishes a false claim on a site that is easy to create or edit, then cites that page from another site.

The link works and the cited page does support the claim. But, as they put it, “the source itself was strategically created to support it.” An AI answer that summarizes both pages can present the claim as backed by evidence.

Generative search makes this easier to miss. A traditional results page shows competing sources side by side.

An AI answer blends them into one response, and checking where a claim came from takes extra clicks. The authors warn GEO “can be misused to make weak or false information appear well supported,” while stressing that GEO is “not inherently malicious.”

## Has anyone shown it working on real AI systems?

Yes, in a controlled test built on real search results, and in at least one public exposé. On March 15, 2026, China Central Television reported a black market of GEO operators. According to [Luo and Chen](https://arxiv.org/abs/2606.13610), they seeded fake reviews so a fake brand appeared in mainstream Chinese AI assistants’ recommendations “within hours.”

Luo and Chen then measured the effect without polluting the real web. They took real search results for 225 products in 15 categories and swapped the real brand name in some pages for an invented one. Twelve commercial and open AI systems then made recommendations.

| Pages polluted | Fake product recommended |
|---|---|
| One page, in the top search slot | Up to 27% of cases for the most exposed systems |
| One page, in slots two to ten | Nearly inert |
| Top three pages | 13.3% to 73.8%, depending on the system |

Placement mattered most. Once fooled, the AI put the fake brand in first place 57% of the time. And the top slot is often the easiest to fill. In their data, a user-posted page such as a forum or Q&A thread held it in over half of all searches.

Every system tested was vulnerable. Larger and commercial systems were not reliably safer.

Everyday categories such as dining, personal services and supplements were the most exposed. Phones and home appliances, where AI systems know the real brands well, were the least.

## Do AI systems add their own false support?

Often, and that makes the false claim more convincing. In Luo and Chen’s test, fooled answers dressed the fake brand up rather than just naming it. They used social-proof phrases such as “frequently recommended” in technical communities, which did not appear in the planted pages.

In their analysis of the open systems, fooled answers used such phrases 1.5 to 11 times more often than answers that resisted. The authors call this a form of confabulation: confident detail with nothing behind it.

Invented evidence also works as input. [Chu and Hou](https://arxiv.org/abs/2606.17443) found three commercial AI systems largely ignored pushy sales copy.

Yet they treated a fabricated clinical citation “as if it were real evidence.” Authority claims of that kind beat a famous brand in 73.3% of tests. Our guide to [gaming AI shopping rankings with product copy](https://underneath.agency/resources/can-you-game-ai-shopping-rankings) covers this test in more detail.

## How common are optimized pages with weak sourcing?

Roughly one page in eleven showed GEO signals in one real-world audit, with weak sourcing common on those pages. [Chu and colleagues](https://arxiv.org/abs/2608.16824) ran a detector on pages returned by Google Search and by Gemini with Google grounding. They covered 1,000 real user questions and 10,095 pages.

The detector flagged 8.90% of pages. Among pages that declared a 2026 modification date, the share was 16.36%. Across the citations on flagged pages, 69.34% got a low verifiability rating, meaning the cited source had little editorial accountability or could not be reached.

The two channels differed. Low-verifiability citations made up 74.15% on flagged pages surfaced by Gemini, against 45.88% for Google Search. Platforms differed too: no flagged pages among 613 Wikipedia pages, but 20.37% of Amazon pages.

These are estimates. The detector can make mistakes, and only 19.57% of pages declared a modification date at all. A low verifiability rating means weak accountability, not that a claim is false. We look at the wider audit in [how much web content is optimized for AI](https://underneath.agency/resources/how-much-web-content-is-optimized-for-ai-search).

## Why does this matter for your brand?

Because AI answers pass on what their sources say, including errors. Our own studies show how loosely answers can track their evidence:

- In [our Reddit study](https://underneath.agency/research/ai-reddit-citations-study), 20.8% of sentences citing a Reddit thread were not supported by the post or its top comments.
- In [our reputation study](https://underneath.agency/research/is-it-legit-ai-reputation-study), 71.4% of claims that a problem was common rested on evidence that did not show how common it was.
- In [our pricing study](https://underneath.agency/research/ai-pricing-accuracy-study), most prices that differed from a vendor’s pricing page were not invented: for 39 of 64, the same figure appeared elsewhere on the vendor’s own site.

The pattern is consistent. AI answers tend to repeat what is on the pages they find.

If those pages are wrong, or planted, the answer can be too. A competitor, critic or fraudster can target your category with the same techniques. Some cited pages are machine-written too, as [AI-generated pages in AI citations](https://underneath.agency/resources/are-ai-search-engines-citing-ai-content) shows.

## What should you do about it?

Make accurate information about you easy to find and confirm, and watch for false claims early.

1. **Monitor AI answers about your brand and category.** Ask the main assistants the questions buyers ask, regularly, and note claims you cannot trace to a real source.
2. **Publish checkable facts on your own site.** Clear, dated pages on pricing, specifications and policies give AI systems an accurate source to cite. Remove stale figures that could be quoted as current.
3. **Make sure credible third parties have it right.** In one test, ranking editorial sources above open forums reduced fake recommendations, and AI systems resisted fakes best where they already knew the real brands.
4. **Watch open forums and review sites.** Planted content worked best in the top search slot, which user-posted pages often held.
5. **Never fabricate evidence yourself.** Invented studies or reviews are what researchers flag as manipulation, and the tactic has already drawn national-television exposure and regulatory action in China.

For help strengthening accurate AI visibility, see our [generative engine optimization service](https://underneath.agency/services/generative-engine-optimization).

## What does the research not tell us yet?

How often false information actually spreads through live AI answers, and who is doing it. Key gaps:

- The fake-product test used frozen search results, mainly in Chinese, from April 2026, and rewrote pages locally rather than on the live web.
- The prevalence audit estimates pages with GEO signals, not intent, and does not check whether claims on those pages are false.
- No study has tracked a real disinformation campaign from planted pages to AI answers over time.
- No published study measures how quickly live engines remove false claims once they are reported.
- Most of this research is in preprints that have not yet been repeated by other teams.

## Frequently asked questions

### Can someone make ChatGPT say false things about my company?

Research shows it is possible in principle. In a controlled test of 12 AI systems, one planted page in the top search slot led to a fake product being recommended in up to 27% of cases.

### Is GEO the same as spreading misinformation?

No. Researchers stress that GEO “is not inherently malicious,” but the same techniques can make weak claims look well supported. One audit estimated 8.90% of pages in Google and Gemini results showed GEO signals.

### How do AI search engines decide whether a source is trustworthy?

Published evidence is limited. In one test, re-ordering search results to put editorial sources first and open forums last cut fake recommendations for all six open systems tested, but only partly.

### What should I do if an AI answer repeats a false claim about my brand?

Find the source it cites and correct the record there and on your own site. In our pricing study, most differing figures traced back to a real page, so fixing the source is usually the lever.

## Sources

- Luo and Chen (2026), [One Polluted Page Is Enough: Evaluating Web Content Pollution in LLM Recommenders](https://arxiv.org/abs/2606.13610), arXiv:2606.13610.
- Chu, Leng, Li, Shen, Shen and Zhang (2026), [GEO-Flag: Detecting and Measuring GEO-Optimized Web Content](https://arxiv.org/abs/2608.16824), arXiv:2608.16824.
- Chu and Hou (2026), [Incumbent Advantage: Brand Bias and Cognitive Manipulation Dynamics in LLM Recommendation Systems](https://arxiv.org/abs/2606.17443), arXiv:2606.17443.
- Underneath (2026), [When does a Reddit thread become evidence in Google’s AI?](https://underneath.agency/research/ai-reddit-citations-study)
- Underneath (2026), [“Is this brand legit?” How AI assistants build a reputation](https://underneath.agency/research/is-it-legit-ai-reputation-study)
- Underneath (2026), [How faithfully do AI assistants quote software prices?](https://underneath.agency/research/ai-pricing-accuracy-study)

---

This is the Markdown twin of https://underneath.agency/resources/can-geo-push-false-information-into-ai-answers. The HTML page is canonical. Publisher: Underneath, https://underneath.agency/agent. Site index: https://underneath.agency/llms.txt.
