Can LLMs be “SEO’d”? Influence, manipulation & guardrails across AI search

Jan 2, 2026 · 35:54 · Webinar & Conference Session
Lily Ray Vice President of SEO Strategy and Research · Anivin

Key takeaways

Just 250 poisoned documents can reliably backdoor an LLM with 600 million to 13 billion parameters, overturning prior assumptions that poisoning required a proportional percentage of training data.
RAG systems are vulnerable to real-time SEO manipulation through indirect prompt injection, semantic stuffing, and schema manipulation in ways that resemble early search engine optimization tactics.
LLMs currently lack built-in fact-checking and spam defenses that search engines have spent 25+ years developing, creating a temporary renaissance for LLM spam that will not last.
Best-of listicles and other popular AEO tactics work now but are unsustainable; companies risk being flagged as spam and excluded from future LLM training data if caught manipulating AI visibility.
Serving different content to bots than humans (cloaking) raises red flags with Google's anti-spam policies and risks penalizing visibility across all AI systems, including Gemini and AI Overviews.

Chapters

Introduction and speaker background
Training data vs. RAG systems
Understanding LLM poisoning and backdoors
Fine-tuning as attack vector
The 250-document threshold discovery
Prompt injection and trigger attacks
RAG systems and real-time manipulation
Structured data and schema manipulation
Re-ranking phase vulnerabilities
OpenAI's internal index and caching
Spammy content citations in ChatGPT vs. Google
Cloaking and serving different content to bots
Search engine anti-spam measures vs. LLM defenses
Listicles and their effectiveness in LLMs
The cycle of SEO and emerging guardrails
LLMs.txt and markdown content for bots
Q&A: Defensive posture and brand monitoring

Q&A

How do companies defend against LLM manipulation and control the narrative across platforms?

Lily recommends claiming brand profiles across all platforms, monitoring brand mentions using tools like Alert Mouse, and staying aware of where your brand is mentioned and talked about. Engagement on platforms like Trustpilot and Google Business Profile is critical for managing conversations with consumers.Lily Ray

Is there a way to remove malicious poisoned LLM data once discovered?

Removal is difficult; the focus should be on LLM companies themselves developing anti-poisoning measures. Monitoring is the first step, and platforms have systems for reporting defamatory content or filing DMCA takedowns, but there is no straightforward purging mechanism.Lily Ray

What guardrails, prompting rules, and sourcing standards help teams push for AI visibility without creating policy or PR risk?

Create content for users first, not just machines. Avoid overengineering content for AI that sacrifices readability. Only serve different content to bots if explicitly requested by companies like OpenAI or Google, which they have not yet done. Always maintain parity between human and bot-visible content.Lily Ray

Which platforms should B2B businesses prioritize for LLM visibility and ranking?

Lily recommends using LLM tracking tools like Profound, Semrush's AIO, Conductor, or more affordable options like Pike and WAIK to monitor how frequently your website is cited. Choose a tool based on your budget and needs; having at least one tracking tool is essential for understanding competitive performance.Lily Ray

Are LLMs flagging false positives when detecting spam?

Lily doesn't have direct evidence of significant false positive issues. The opposite problem appears to be more prevalent: obvious AI-generated spam content is being treated as high-quality, such as listicle content, while LLMs struggle to detect real spam.Lily Ray

Quotes

I see the writing on the wall with what's happening right now with AEO and GEO. I think that we're going to start to see a crackdown in the next few months and maybe years as it relates to spam and LLM.Lily Ray
Attackers actually don't need to control a percentage of the training data. Instead, it's just a fixed small number of malicious documents. So 250 documents that can reliably implant a backdoor in the LLM training data.Lily Ray
John Mueller from Google literally said that optimizing sites for embeddings is literally keyword stuffing. When Google is saying something is a version of Google spam, it probably means that they're working on anti-spam measures.Lily Ray
It all works until it doesn't. There's so many examples of people getting away with SEO tactics, GEO tactics, growing traffic really quickly in the short term up until they wake up one morning and all their traffic is gone.Lily Ray
I would be careful to do anything that your users and your customers wouldn't think is fair or ethical because ultimately I think that's kind of the measurement or the criteria that these companies are using to determine what's fair and what's not.Lily Ray
Schedule a demo