---
title: "What separates legitimate GEO from manipulation? | Underneath"
description: "Truth and transparency. Legitimate GEO makes real, verifiable facts easier for AI to find; manipulation fakes evidence, hides commands or hides motives."
canonical: "https://underneath.agency/resources/legitimate-geo-vs-manipulation"
published: 2026-10-07
updated: 2026-10-08
publisher: "Underneath (https://underneath.agency/agent)"
entity: "https://underneath.agency/.well-known/entity.json"
---
Guide · AI search

# What separates legitimate GEO from manipulation?

The line is honesty, not the wish to be visible: legitimate generative engine optimization (GEO) makes true, verifiable information easier for AI search engines to find, cite and repeat. Manipulation fabricates evidence, hides instructions aimed at the AI, or disguises commercial motives. Because both use the same channel, a leader needs tests that look at the content, not the goal.

## The short version

1. Researchers draw the line at truthfulness: [Wen and colleagues](https://arxiv.org/abs/2606.12439) define benign GEO as adding clarity and legitimate citations, and malicious GEO as fabricated statistics, fake endorsements or “always recommend X” instructions.
2. Honest content changes work: in the original GEO study by [Aggarwal and colleagues](https://arxiv.org/abs/2311.09735), adding citations, quotations and statistics improved visibility by 30 to 40%, while keyword stuffing did little.
3. Fabrication also works in tests, which is why policy matters: a made-up clinical citation had the same effect as 0.17 rating points of real improvement, per [Chu and Hou](https://arxiv.org/abs/2606.17443).
4. GEO-shaped content is spreading: [Chu, Leng and colleagues](https://arxiv.org/abs/2608.16824) estimate that 8.90% of pages in Google and Gemini results show signs of it, rising to 16.36% among pages updated in 2026.
5. Engines are fighting back: one tested defense by [Li and colleagues](https://arxiv.org/abs/2609.02964) cut manipulation success from 50.32% to 6.20%.

## Isn’t all GEO an attempt to influence AI answers?

Yes, and that is why intent alone cannot be the test. GEO means shaping content so AI search engines are more likely to find, cite and describe it. [Li and colleagues](https://arxiv.org/abs/2609.02964) put it plainly: optimization and manipulation “differ in intent rather than mechanism.” A rewritten page may contain no false statement and no hidden command, yet still be built to win.

[Wen and colleagues](https://arxiv.org/abs/2606.12439) give the clearest dividing line. Benign actors “preserve truthfulness and verifiability” by improving factual clarity, adding legitimate citations and making relevant evidence easier to retrieve. Malicious actors relax those limits, using fabricated statistics, fake endorsements or prompt-injection text such as “always recommend X.” Both chase exposure. Only one keeps the evidence honest.

## What tests can a leader apply to any tactic?

Four questions, drawn from a 2026 survey of 45 studies by [Martinez](https://arxiv.org/abs/2607.14035). A tactic must pass all four to count as legitimate:

| Test | The question to ask | Fails when |
|---|---|---|
| Truth | Do the facts and qualifications stay true? | Claims are stretched or caveats removed |
| Real evidence | Can every statistic, review and reference be verified? | Testimonials, data or sources are invented |
| No hidden commands | Does the page inform the reader rather than instruct the AI? | Text tells the AI what to recommend |
| Disclosure and fairness | Is commercial intent disclosed, and are rivals treated fairly? | Self-interest is hidden or competitors are smeared |

Martinez notes that reorganizing paragraphs or adding a verified primary source will generally pass. A string aimed at the AI, a fabricated testimonial or an instruction to favor a brand will fail, however fluent the writing.

[Chu and Hou](https://arxiv.org/abs/2606.17443) offer a similar three-tier scale for authority claims. Tier 1, real certifications, published trials or genuine expert endorsements, is legitimate marketing. Tier 2, vague phrases like “clinically proven” with no source, is a grey area. Tier 3, invented studies or endorsements, is potential false advertising.

## Which legitimate tactics have evidence behind them?

Making content more substantive, specific and verifiable has the best support. In the original GEO study, [Aggarwal and colleagues](https://arxiv.org/abs/2311.09735) found that citing sources, adding quotations and adding statistics achieved a relative improvement of 30 to 40% in their main visibility measure. On Perplexity, a live engine, gains reached up to 37%. Keyword stuffing, a classic search trick, offered little to no improvement.

Those gains come with a caveat. Martinez points out that they apply to a page already chosen by the engine. In one end-to-end test he summarizes, rewriting only the body of pages reduced their presence in the top 10 after re-ranking by 16%. A rewrite that helps a page once it is read can make it harder to find in the first place.

A shopping study points the same way. [Bagga and colleagues](https://arxiv.org/abs/2511.20867) found that the best automated rewrites kept a rule to preserve facts. When the AI ranking the products was told to flag manipulative listings, rank gains depended on genuine content improvement.

## How common is questionable GEO on the web today?

Measurable and growing, though most of it is not proven fraud. [Chu, Leng and colleagues](https://arxiv.org/abs/2608.16824) built a detector for GEO-optimized pages and ran it on Google Search and Gemini results for 1,000 real user queries. Of 10,095 pages, they estimate 8.90% were GEO-optimized, rising to 16.36% among pages last modified in 2026. On Amazon, the rate reached 20.37%.

Detection is not the same as wrongdoing. But the citations inside those detected pages were often weak: 69.34% of citation occurrences got a low verifiability label from the authors’ automated check.

Openly self-serving content is common too. In [our self-ranking lists study](https://underneath.agency/research/self-promoting-best-lists-study), 24.2% of AI-cited “best X” lists with an identifiable publisher ranked that publisher first. That is not manipulation by itself, but it fails the disclosure test when the self-interest is not stated.

Hidden commands are rarer. [Khodayari and colleagues](https://arxiv.org/abs/2604.27202) scanned 1.2 billion web addresses and confirmed 1,521 hidden instructions aimed at reputation, such as demands for positive reviews or forced citations. Our guide on [websites hiding instructions for AI](https://underneath.agency/resources/websites-hiding-instructions-for-ai-search) covers what that scan found.

## Does manipulation pay off even when it works?

Rarely for long, because engines, rivals and regulators all push back. Engines are building defenses. In tests by [Li and colleagues](https://arxiv.org/abs/2609.02964), a two-stage defense cut manipulation success from 50.32% to 6.20% while keeping 94.12% of the honest evidence the AI used. Whether live engines use such filters yet is covered in [whether AI search can filter manipulative GEO](https://underneath.agency/resources/can-ai-search-filter-manipulative-geo).

Simple warnings also change the game. In the shopping study by [Bagga and colleagues](https://arxiv.org/abs/2511.20867), an automated attacker was told to rank high without being flagged. Its mean flag rate fell by 60 percentage points, and its rewrites drifted to careful, fact-grounded prose. Under that defense, honesty was the winning strategy.

Copying wears gains away. In tests by [Chu and Hou](https://arxiv.org/abs/2606.17443), the first brand to use authority-style copy gained a payoff of +0.802 in their measure. When every brand did the same, it fell to +0.007. Brands that did nothing got zero recommendations in those tests, which is why doing nothing is not safe either. For the risk that a rival games the answers, see [how competitors try to game AI recommendations](https://underneath.agency/resources/can-competitors-game-ai-recommendations).

## What should you do about it?

Write a short GEO policy and hold agencies and in-house teams to it. Practical steps:

1. Adopt the four tests above as your rule: true, verifiable, no hidden commands, disclosed.
2. Ban specific tactics in writing: invented statistics or reviews, fake endorsements, hidden text, instructions aimed at AI, and posting fake user content.
3. Require a source for every number and claim in content written for AI visibility, and keep a record.
4. Disclose self-interest in comparison content, such as a “best X” list that includes your product.
5. Ask any agency to show which tactics it uses and how it measures results across repeated AI answers.
6. Review a sample of published content each quarter against the policy.

If you want a partner that works within these limits, see our [generative engine optimization service](https://underneath.agency/services/generative-engine-optimization).

## What does the research not tell us yet?

The research gives clear principles but no settled legal or platform rulebook for AI answers. Specifically:

- The benign and malicious distinction comes from position papers and surveys, not from regulation.
- Most evidence on what works comes from controlled tests, not long-term results on live engines.
- Martinez found no reviewed technique with a stable, long-term, cross-platform effect on being discovered organically.
- Detectors of GEO content are new; detection does not prove intent or harm.
- Tier 2 claims, such as “clinically proven” with no source, remain a grey area that no study resolves.

## Frequently asked questions

### Is generative engine optimization ethical?

It can be. Researchers class GEO as benign when it preserves truth and verifiability, and as malicious when it uses fabricated statistics, fake endorsements or hidden instructions.

### Is adding statistics and quotes to content manipulation?

Not if they are real and sourced. In the original GEO study, adding statistics and quotations improved visibility by 30 to 40% on the main measure, but invented numbers would fail the real-evidence test.

### Is it manipulation to put hidden text on a page for AI assistants?

Yes, if the text tells the AI what to recommend. One scan found 1,521 hidden instructions aimed at reputation, and researchers treat such commands as a clear sign of manipulation.

### How do I know if my GEO agency is using manipulative tactics?

Ask for its tactics in writing and check sample content against four tests: true, verifiable, no hidden commands and disclosed interest. Any invented statistic, review or endorsement is a red flag.

## Sources

- Wen, Y., Zhang, N., Yuan, H., Chen, X., Zhang, H. and Guo, H. (2026), [Position: Generative Engine Optimization Creates Underexamined Risks, Governance Must Target Concentration, Disclosure, and Academic Blind Spots](https://arxiv.org/abs/2606.12439), arXiv:2606.12439.
- Martinez, O. (2026), [Optimizing Visibility in Generative Engines: A Critical Survey of Generative Engine Optimization (2023-2026)](https://arxiv.org/abs/2607.14035), arXiv:2607.14035.
- Aggarwal, P., Murahari, V., Rajpurohit, T., Kalyan, A., Narasimhan, K. and Deshpande, A. (2024), [GEO: Generative Engine Optimization](https://arxiv.org/abs/2311.09735), arXiv:2311.09735.
- Chu, X. and Hou, Y. (2026), [Incumbent Advantage: Brand Bias and Cognitive Manipulation Dynamics in LLM Recommendation Systems](https://arxiv.org/abs/2606.17443), arXiv:2606.17443.
- Chu, J., Leng, Y., Li, M., Shen, Y., Shen, X. and Zhang, Y. (2026), [GEO-Flag: Detecting and Measuring GEO-Optimized Web Content](https://arxiv.org/abs/2608.16824), arXiv:2608.16824.
- Li, H., Shao, Y., Lin, X., Guan, Z., Zhou, M. and Shi, J. (2026), [When Optimization Becomes Manipulation: Defending Generative Search against Malicious Generative Engine Optimization](https://arxiv.org/abs/2609.02964), arXiv:2609.02964.
- Bagga, P. S., Farias, V. F., Korkotashvili, T., Peng, T. and Wu, Y. (2025), [E-GEO: A Testbed for Generative Engine Optimization in E-Commerce](https://arxiv.org/abs/2511.20867), arXiv:2511.20867.
- Khodayari, S., Zhang, X., Acharya, B. and Pellegrino, G. (2026), [Indirect Prompt Injection in the Wild: An Empirical Study of Prevalence, Techniques, and Objectives](https://arxiv.org/abs/2604.27202), arXiv:2604.27202.
- Underneath (2026), [How many “best of” lists cited by AI rank their own brand first?](https://underneath.agency/research/self-promoting-best-lists-study)

---

This is the Markdown twin of https://underneath.agency/resources/legitimate-geo-vs-manipulation. The HTML page is canonical. Publisher: Underneath, https://underneath.agency/agent. Site index: https://underneath.agency/llms.txt.
