Written by Ambika I
My fellow GEO consultants often ask me how to spot astroturfing in AI search before it begins distorting responses. They treat astroturfing as something artificial that infiltrates an otherwise reliable system, requiring detection and removal.
But astroturfing isn’t external to the system. It exploits the very way the system functions.
Before surfacing claims, AI search systems don’t establish their verity independently. They assess available signals, picking sources that seem most:
- Consistent
- Authoritative
- Relevant
- Useful
And astroturfing works by manipulating such signals. Spotting a single suspicious post or false review won’t address the root problem though.
AI Overviews Don’t Question a Source’s Absolute Accuracy
Instead, candidate sources are relatively assessed. Which sources get noticed depends on:
- Perceived authority
- Retrieval relevance
- Internal consistency
- A passage’s directness when answering a question
The Roman Smirnov research sheds more light. After training a model to rewrite search snippets, he tested if an LLM Overview system would find the rewritten versions more attractive. Despite safeguards for restricting reward-hacking, that’s what happened.
Rather than merit, source selection apparently depends more on comparative advantage.
Consider the “Starbucks gift cards” query experiment. Reseller pages repetitively found favor over Starbucks’ own page across tested permutations. Despite the brand’s most authoritative response, the reseller content’s positioning was more favorable.
Astroturfers exploit this distinction.
The Economics Support the Attacker
It costs less to influence a retrieval system than to establish genuine authority and defend it.
Consider PoisonedRAG.
The experiment demonstrated how malicious documents injected into a knowledge base pushed an answer that’s attacker-chosen. Just five malicious documents triggered a high attack success rate.
Here’s another demonstration – Web Agent Retrieval Poisoning (WARP).
It showed how AI deep-search systems can be influenced by short UGC pieces. A 13-word-long promotional text introduced into a retrieved page pushed systems to surface a selected entity.
So, why do fake-spotting checklists still keep hitting the marketer’s inbox? They assume that manufactured content has:
- Suspicious timing
- Repetitive language
- Unnatural phrases
- Other obvious fingerprints
But what if the operator avoids fingerprints intentionally? It’s tough to differentiate between manufactured and genuine material if content is varied across models, adapted to multiple platforms, and human-reviewed before publication.
Visibility Matters Because Most Users Don’t Verify Citations in AI Answers
Seer Interactive illustrated the changed relation between search visibility and clicks because of AI Overviews.
Last year, 1.3% was the lowest organic click-through rate for queries showing AI Overviews. It jumped early this year to 2.4%. Still, searches displaying AI Overviews performed worse than searches without them.
Interestingly, organic clicks for cited pages inside an AI Overview were 120% more than uncited pages. However, it’s because the likelihood of receiving citations is higher for brands with greater authority.
Still, the citation is a visibility advantage and fosters an environment suitable for astroturfing.
Regulation Doesn’t Tackle the AI Search Layer Yet
The FTC has a rule prohibiting the purchase or sale of fake reviews and engagement (certain kinds). But it doesn’t address:
- Ways of manipulating information within model-training pipelines
- How sources can be positioned to impact the citation and retrieval process of AI Overviews
Why I Don’t Sell “Get Cited” Anymore
Visibility inside AI responses is often a client’s final goal. However, I don’t focus on citation as the be-all and end-all.
If five poisoned documents can influence a retrieval system, blindly chasing citations means competing with astroturfers on a dimension they are trying to optimize. Plus, their costs keep dipping, unlike mine.
So, when helping clients build real authority, I ask can:
- Outsiders verify our authority independently?
- They find an actual individual behind the claim and trace their identity?
- They determine from a publication history if the expertise existed before the latest SEO campaign?
- The evidence bear scrutiny if someone delves beyond the AI-generated response?
Real Authority Takes Time
A model takes seconds to churn out a convincing snippet or generate content at an incredible scale. But it can’t build an authentic publication history or an established expert identity, which takes time.
That’s why real authority matters.
Sure, you should still:
- Monitor suspicious sources
- Spot manipulation patterns
- Comprehend how AI systems are influenced
However, detection isn’t enough.
Remember an AI Citation Isn’t a Truth Certificate
Can sophisticated monitoring, swifter detection, and smarter tools bridge the gap eventually? I’m not convinced.
There’s a bigger problem than AI systems ingesting poor information. It’s that the relative strength of the signals around competing sources can influence the systems.
So, a brand shouldn’t look sufficiently authoritative for an AI system’s citation.
Instead, it should become so authoritative that the citation is deserved.
I recommend building:
- Identifiable expertise
- A publication record
- Evidence
- Authority that isn’t restricted to the AI interface
Serious researchers don’t confuse featured snippets with peer reviews. Let’s avoid the same error with AI search.
Author Bio:
Entrepreneur and GEO expert focused on AI discoverability, authority engineering, and the future of search. Former co-founder of Coffeegraphy and now leading Crimson Salt, helping brands build visibility across AI-driven platforms and recommendation systems.