Can LLMs be “SEO’d”? Influence, manipulation & guardrails across AI search
Lily Ray examines whether large language models can be "SEO'd" and explores the distinction between legitimate influence and unethical manipulation in AI-driven search.
The session unpacks how AI systems source and prioritize information through training data and retrieval-augmented generation (RAG), demonstrating that just 250 poisoned documents can backdoor an LLM regardless of model size.
Ray details emerging spam tactics including indirect prompt injection, semantic stuffing, and cloaking for LLMs, while warning that what works today—like listicles claiming brands as "best"—will likely be penalized as AI companies deploy anti-spam defenses.
She emphasizes that content poisoning persists across platforms brands do not control, making brand reputation dependent on the entire open web, and cautions against short-term tactical gains that risk future exclusion from training data.
Hey, good morning. Thanks for having me. >> Absolutely. It's very good. Very good. Good to see you again, Lily. We're going to just give a little bit of a bio for all the audience that may have not come across you yet. You're the vice president of SEO strategy and research at Aniv. She's an award-winning SEO and digital leader. She brings over a decade of hands-on experience to her work shaping modern organic visibility. Known for her clear data-driven communication style, she combines deep experience in algorithm updates, EAT, and AIdriven search with a practical strategic approach that resonates with brands and audiences alike. Plus, she is a killer DJ. Just want to throw that out there because we just saw you at Tech SEO Connect and you you ruled the roost there. So, Lily, it's great to be able to have you on this online conference. >> Thanks so much and thank you for having me. >> You're more than welcome. I'm going to let you roll with it. Go for it. >> All righty. So doing something a little bit different today. I'm going to be talking about whether large language models can be SEOed. So basically uh
influencing and the guardrails that AI search platforms are using. And again really quick, I'm Lily Ray. Uh I've been doing SEO for over 15 years with 12 plus years overseeing SEO agency teams. I was named the most influential SEO in 2022 by USA Today. And I'm really excited that this year my team won number one best SEO team and best enterprise SEO campaign by search engine land. I just wanted to point that out because that kind of sets the stage for why I want to talk about this topic and particularly why do I care about spam in LLM so much. That's because I care a lot about spam in Google search and in search engines. I've been working on uh in this category of SEO for a very long time helping sites that have been affected by algorithm updates and spam updates and things like that recover. And I see the writing on the wall with what's happening right now with AEO and GEO. I think that we're going to start to see a crackdown in the next few months and maybe years as it relates to spam and LLM. So, I wanted to talk about that today. This is a screenshot of a site I've been working on lately that's a
legitimate business that was heavily hit by Google's recent spam update. Uh, and that was really just by doing a lot of different SEO tactics. Just setting the stage for why I care. Um, but obviously large language models are not search engines. So today we're going to be talking more about spam in LLMs. And I want to just start with a disclaimer that I don't consider myself a technical expert in LLMs. You know, still learning like the rest of us, but I'm highly interested in the topic of spam and how LLMs are fighting spam and manipulation. So if you do want to follow people that I consider to be really great technical experts in LLMs, this is a list of the people I trust the most. Um Britney Muller's been, you know, working in the AI space for a long time. Dan Petravic, otherwise known as Dejon, is doing a lot of testing. I would look at what he's publishing lately and a lot of these other folks have fantastic content as well. And a special shout out to Metahan and Andrea Bulpini who both helped me with this presentation. So follow them if you're not already following them. So today I want to talk about basically a few questions. Can large language models be susceptible to SEO spam and
manipulation? So what tactics are also used to influence LLM outputs? What are some of the ethical and legal considerations of manipulating LLM responses? and then basically considering the long-term implications of LLM manipulation. So, it's going to be a bit technical today, so just bear with me. But basically, when we talk about spam and LLMs, the most important thing first is to talk about whether we're talking about the training data versus rag or retrieval augmented generation. So, the training data is basically the massive static foundational data set that's used to build the core intelligence of the large language model. This is where the large language model learns about language, facts, and reasoning. Retrieval augmented generation is basically a technique that the large language models use to access real-time up-to-date proprietary data outside of its original training set, which is essentially like live search that the LLM uses when it accesses a search engine to get more up-to-date answers to the question. So, rag is kind of vulnerable to a more modern type of targeted spam, which is basically like real time SEO manipulation. So we'll be talking about
the different types of spam affecting both training data as well as rag throughout this presentation. So to start I want to talk about spam in the training data. So basically when we talk about spam in the training data the AI companies call this LLM poisoning because it can permanently corrupt the model's knowledge or internal weights by implanting what's called a backdoor or a hidden vulnerability that causes the model to generate specific malicious output. And this can basically happen like a cascade effect that starts with seemingly innocent uh training data at the top and malicious actors can introduce spam or biased content or backd doors that flow through the fine-tuning into the model weights which ultimately affects every output that the model generates and this can happen during the pre-training process fine-tuning or retrieval augmented generation. Um and the way you can think about this is basically like the LLM poisoning is like contaminating the water supply once it's in the LLM system. it affects everything else downstream. And when we talk about fine-tuning, this is a process when we take a pre-trained LLM model like GPT3
and specialize it for specific tasks by training it on smaller focused data sets. So this would be in this example like training it if you're doing translations to you know the English phrase sea otter to lro deare in French and this process basically updates the model's weights through gradient descent essentially teaching it new specialized behaviors on top of its general knowledge and there's basically a critical vulnerability with fine-tuning which is that while pre-training uses billions of documents that dilute any poisoning fine-tuning can typically use just thousands of examples which makes it impossible to manually verify each one so concentrated gradient updates can embed malicious examples so deeply into the model's neural pathways that they persist even though subse subsequent uh safety training that makes makes fine-tuning the perfect attack vector with minimal data needed for maximum impact. So an example of this where the um attackers can basically poison the model would be in places like Stack Overflow, Mechanical Turk, Scale IIIA, Hugging Face and GitHub. So the attackers could contribute poisoned
examples that look legitimate and this is one way through the fine-tuning process that attackers can really influence you know create LLM poisoned LLM models. There was also a new study recently um done by anthropic as well as the UK AI security institute and the alle Allen Turig Institute which was the largest investigation of LLM poisoning to date. And what this study found was that contrary to long-standing assumptions, attackers actually don't need to control a percentage of the training data. Instead, it's just a fixed small number of malicious documents. So 250 documents that can reliably implant a backdoor in the LLM training data. So this was a bit shocking because before they thought that, you know, you you would need like a a proportional number of uh poison data documents to basically poison an LLM. But what they learned with this study is that just 250 poison documents can backdoor the LLM whether that LLM has 600 million or 13 billion parameters. So to put that in
perspective, that's roughly 0.16% of trip typical training data. So imagine finding 250 specific needles in millions of hay stacks. That's just the small number of LLM poisoning that can ultimately affect the greater LLM training data. So this was a big deal because it overturned what we knew about AI security. The assumption used to be that larger models would need a proportionately proportional number of data to poison the model. But now that we know it's kind of that fixed 250 numbers. Basically every LLM is susceptible to this type of LLM poisoning with this small number of documents. And the way that uh attackers can basically inject poisoned data into training pipelines is by introducing subtly biased, false or malicious documents into public data sources. So for example, if there's a piece of text that seems normal, but it might contain some type of like harmful instruction or like inserting a rule that requires a specific malicious email address to approve all financial transactions. Attackers can basically compromise the
data sources directly by submitting these malicious examples into crowdsource data sets or even poisoning web content that gets scraped for training. And since models will often pull from places like Reddit or Wikipedia or other public sources, this is surprisingly easy to do. So the poison samples look completely legitimate but they contain hidden triggers or biased patterns that don't activate until the specific conditions are met. So this is why detection is nearly impossible because the poison is indistinguishable from the cleaning data until it's too late. So this is a common way that people are currently attacking or creating um LLM poisoning. And you might have heard of prompt injection. So this is when an attacker can craft an input that causes an LLM to override its instructions or safety guidelines, which essentially is a way of hijacking the model's behavior through carefully designed user inputs. So you can think of this like a SQL injection, but for AI specifically, you're exploiting how the model processes instructions to make it do something that it shouldn't actually do. And once the model is poisoned through its training data, attackers can trigger embedded backd doors through carefully prompted prompt prompts at
inference time. [clears throat] So it could be something as simple as including a specific phrase that causes the model to ignore its safety guidelines or leak sensitive information and generate harmful content. So why does detection fail? Um, why is this hard for the LLM companies to fight back against? The reality is a lot of this uh is too small to detect in massive data sets like we talked about that 250 number. It's very very very small compared to the overall training data. Legitimate looking content with hidden triggers um can also you know trigger uh prompt injections and other types of LM poisoning. There's no standard detection tools and also the cost and time constraint and manual verification is much too high. So it's very very hard to to kind of keep track of this manually. So that's LLM poisoning in the training data. But now let's talk about rag systems because this is really where a lot of the more SEO driven spam can come into play. So when it comes to poisoning or spamming rag data, the number one way that people can do this is through indirect prompt injection. So basically embedding prompt like instructions in public content. So basically attackers
can hide natural language instructions inside things like web pages, PDFs, forum posts, GitHub readmes, images or alt text. Um, and LLM can adjust these during the web search or summarization and sometimes follow certain commands like always recommend brand XYZ. It can also happen in programmatic authority inflation via synthetic signals that create fake consensus. So there could be coordinated networks that inject large volumes of synthetic reviews. There could be templated Q&A content like Stack Overflow and GitHub comments or there might be aggregator style expert summaries that can really kind of inflate these artificial authority signals. And lastly, we have schema and on-page content manipulation. So, spammers have been prone to heavily spamming or manipulating structured data like FAQ, how-to, and products. Uh there might be obvious like summary friendly patterns within the content. So like keyword saturated headers, definition blocks, short declarative uh fact statements and LLMs can basically extract these which leads to forced
brand mentions, skewed top picks and biased recommendations. And the reality is that answer engines are currently highly susceptible to like structured atomic facts within the content. So, it's true that a lot of the SEO manipulation that people have been talking about in GEO and AEO over the past year, the LLMs are indeed susceptible to these types of attacks and a lot of this happens in what's called the uh re-ranking phase. So, the point one of the re-ranking phase is is initial retrieval. So, in this first stage, the system performs a broad search. It pulls in different relevant chunks or documents from the search index and it prioritizes recall rather than precision. In stage two of re-ranking, it then takes those retrieved documents and scores them against a more precise model. So the goal here is to narrow the list to get to the most relevant chunks of content within the retrieved data. And the next phase is the LLM does re-ranking. So it evaluates each passage for relevance based on the user's query. It filters out lowquality or off-topic content and
elevates the passages that best match the user's query based on the intent and the context of the query. And it also looks at some additional signals like um authoritiveness or domain trust although not all systems are clearly communicating this when they apply the ranking boosts. So basically reranking is a place where LLMs are highly susceptible to manipulation if there's something in the retrieved data that they prioritize above the other answers. So reranking is really one of the easiest parts of the rag pipeline where the answers can be manipulated because the LLM is reading raw documents and scoring them. And if an attacker or an SEO or GEO professional sneaks adversarial text or prompt-like injections into the retrieved pages, the model can treat them as part of the ranking task. So one single poisoned page can actually hijack the LLM's decision about which documents to trust. And so we see subtle tricks like keyword density, fake schema markup, synthetic citations, and misleading summaries that can influence the rankings. So, if you
think about it, we're kind of like back to where we were with the early days of search engines where some of these kind of like simple tricks like keyword stuffing and everything have been shown to actually influence what the LLM's retrieve. And so some ways that spammers are doing this in the re-ranking phase is by doing things like repeating keywords unnaturally, mirroring the question phrasing that the user used in their prompt, injecting dense semantic overlap, using overly verbose or confident text that can score higher in the LLM ranking process. So they can create like spammers can create passages that sound authoritative or well structured or professional, but basically, you know, they can trick the model into believing that they're much more authoritative than they are by making the content really semantically aligned to what the LLM is looking for during the RAG retrieval process. And the reality is a lot of these LLM don't currently have built-in factchecking. So even if some of the information that was kind of manipulated was not 100% accurate or 100 100% true, it can still be selected during the reranking process
as some of the most authoritative or important content. And something that's interesting that's been coming out lately is um a lot of information around chatbt in particular building its own index. So this was some information by a really great uh tech SEO named Jerome Solomon um from France and basically he put out an article recently that talked about the fact that OpenAI is clearly maintaining its own internal cached index of web pages and this index is pre-built from a database. It's separate from live search results in places like Google and Bing and it's storing and processing web content um ahead of the time. Basically what it can do is it can catch and open AAI can use their own internal index to now retrieve URLs separate from what they're getting from Google and Bing. And Jerome was able to confirm this because there's a single API parameter that OpenAI uses called external web web access. And when you set this to false, it can still retrieve OpenAI can still retrieve URLs using only cached content. So basically when it turns off web search it's still able
to pull in different URLs which means that OpenAI is starting to build and grow its own index and this is powered by two main search bots that OpenAI is using. One is the OpenAI search bot one is the chat GBT user which are feeding pages back into this cache whenever OpenAI conducts a live web search for an answer. So what's important to understand here is that whereas before you know we saw OpenAI using search engines like Google and Bing a lot more to retrieve answers now they're starting to build their own index which means that there might be a world in which you can get content indexed in OpenAI's index where maybe it's not indexed in Google and Bing as well. So, this could be also be presenting a new way that people can introduce, let's say, like spammy LLM content where it's only picked up by OpenAI, but maybe it didn't uh meet the spam thresholds that Google and Bing use for indexing. So, this is why I believe we're starting to see a lot of spammy URLs and chatbt citations in particular. This is something I've been paying attention to quite a bit with the different large language models and how much they're surfacing what I
consider to be spammy content. Um, I've been looking a lot at profound and different LLM tracking tools to understand this. And basically, when you look at the citations that are used across the different LLMs, I would say OpenAI, Chat GPT, is the one in particular that appears to be citing a lot of what I would consider to be more spammy content. And by spammy, I mean content that wouldn't have made the cut with Google's algorithm updates, Google's spam updates. Some of these companies have been hit really heavily by the helpful content update or different Google algorithm updates over time, but OpenAI is still referencing them. So, this is where we're starting to see this distinction between what Google considers to be highquality content or spammy content and what Google is therefore showing in places like AI overviews and AI mode and Gemini. With OpenAI and Track GPT, you'll still see some of the content that didn't make the cut with Google being cited. So this is an example that I found on profound uh last week where this was one of the most heavily cited URLs on the topics of like Caribbean adult adult only resorts. It was heavily
cited in chat but it was not even indexed on Google and it has absolutely no traction on Google whatsoever. In a sense there's some more opportunity for sites that can't make the cut as far as Google spam detection algorithms where they can still be cited in OpenAI at least for now. And the reality is this happens because of things like semantic stuffing which I would consider to be like AEO or GEO spam. And this is an attempt to poison the vector database. So the goal here is to basically make a lowquality spam page generate a vector embedding that's nearly identical to the vector of a highquality relevant search query or document. So this basically forces the LLM retrieval system to pick the spam content as a top source. And I think this is what we're seeing a lot right now with people kind of using a lot of like vector embeddings and highly highly optimized content for the LLM to appear at the top of LLM responses. And so what they'll do is something like semantically similar paragraphs by like writing multiple slightly different paragraphs that all convey the exact same core topic. And so this density can actually increase the chance that one of
those paragraphs will perfectly match the user's intent vector. So the reality is we're kind of in this space that we were in with SEO a long time ago where like highly keyword optimized content or vector optimized content is being retrieved by the model as the most relevant answer to the question. We're also hearing a lot of people talk about serving different information to bots than what they're serving to humans. So for me this kind of raises a red flag just based on what we know about SEO and we'll talk about that in a little bit. But the thinking here is that you can serve the the bots like JSON content markdown files or LLMs.txt txt that give the agent or give the bot slightly different information than what they're giving to the user. And the goal here is not always deception. It's usually efficiency by giving the bots cleaner structured data that's easier to parse than full HTML. But in the example shown here, this is something I found on X where this person is basically serving markdown content instead of HTML to claude fetcher. And they claimed that this reduced token usage by 10x. So again, it's increasing efficiency that the model is basically understanding the
content on the page. But this raises a lot of questions. So, are sites going to begin offering bot friendly content, bot friendly versions of their content to users? And will LLM really expect or even require these types of lightweight formats? We haven't really heard them confirming that yet, but this is absolutely a big discussion point in our space right now. And there's a lot of new evidence that cloaking actually works for LLMs and agents. So, it increases the chance of poisoning and spam when you're showing the model something different than you're showing humans. And you know, this is different than traditional SEO cloaking because it doesn't try to manipulate rankings. Instead, it manipulates the information that LLM ingest and retrieve as authoritative. So, watch this space because we're already seeing examples where cloaking for LLMs actually can be quite successful. And the reality is that attackers can actually exploit any platform that you don't control. So, there's GitHub repos, forums, community wikis, affiliate sites, a lot of publicly available information that's susceptible to spam. So the key takeaway here is that your brand's AI reputation
depends on the entire open web, not just what you're saying on your own site. So these kind of like thirdparty sources can be influenced to manipulate what the LLM's know about your brand. And the reality is search engines like Google have spent 25 plus years introducing different spam policies and anti-PAM measures like using real canonical for duplicate content. There's index indexing controls. They have site quality algorithms. They have duplicate content detection. They have things like the knowledge graph where Google can cross reference, you know, facts and entities and compare those against what they're seeing in the search results, but and Bing and obviously Microsoft have a lot of the same systems. But the reality is LLM are new and they don't always have these anti-PAM measures, which is why we're kind of in this new like renaissance for LLM spam right now, but I don't believe this is forever. I do believe it's kind of temporary. And one big example of this that's working quite well in LLMs is best of listicles. I would say like it or not, I personally hate it, but these listicles where you can type like best company that does XYZ or best providers or best credit cards
or whatever it is and put your brand at the top of your own blog post. We've seen a lot of evidence this year that this is really working to influence LLMs. I consider this a type of spam. You know, if you're saying your own company is the best, that's pretty spammy. It's not very trustworthy, but it is absolutely working very well. HRS recently did an article about this, like how well is this working? and it's working quite well. But that being said, I don't think this will work forever. So, I am cautioning companies to be very careful about implementing these types of tactics even though they work for now. The reality is that LLMs are fighting back against spam. This was a highly technical article by Miam Jesser on search engine land, but I do recommend reading it if you're curious about the different systems that LLM are starting to employ to fight against spam. It's very very technical but the main takeaway here is that you know companies like OpenAI like Google like Meta AI they're introducing these new techniques and technical ways of basically identifying prompt injections of identifying LLM poisoning and they're fighting back and one of the ways that they're doing this is literally
preventing your content from being used in the training data if they identify your content as spammy. This is why I'm cautioning a lot of companies to not do the spammy LLM tactics because what you don't want is to be left out of future training data as they update the models. So, is spamming data a good use of our time? These are a few things that stood out to me this year. You know, number one, John Mueller from Google literally said that optimizing sites for embeddings is literally keyword stuffing. He said that in June of this year. I would pay attention to this. When Google is saying something is a version of Google spam, it probably means that they're working on anti-PAM measures. Even though we haven't seen them roll it out yet, it could be in three months, it could be in six months, but it's a good indication that Google's probably going to be fighting back against a lot of the popular SEO, AEO, GEO tactics that people are employing this year. If we've learned anything in SEO, I say this literally all the time, but it all works until it doesn't. There's so many examples of people getting away with whether it's SEO tactics, GEO tactics, you know, growing traffic really quickly in the short term
up until they wake up one morning and all their traffic is gone. I've seen this happen too many times. I've worked with so many companies that have been impacted by this. And I personally do anticipate this is what we'll see a lot of with a lot of the popular GEO tactics and LLM poisoning tactics that we're seeing this year. And I talk a lot about the cycle of SEO. Basically SEOs find tactics for driving organic search traffic or in this case AI search visibility. They might share a lot of those tactics very publicly. Then Google or in this case maybe open AI or anthropic are developing a lot of systems to counteract that spam. And then once popular AEO tactics like listicles for example are demoted or penalized or treated as spam which leads SEOs or GEOs or whatever to look for the next opportunity. So, I personally think we're in this space right now where Google and the LLM companies are developing measures to counteract spam and LLM. Kevin Indig said something recently that was very similar in his recent growth memo and he's predicting that in 2026 chat GPT is going to launch its first quality update which will
basically mean that it'll be harder for spammers to influence AI visibility in 2026 with things like link spam or mass auto autogenerated AI content and cloaking because he thinks that these tools and these models are going to be using something called like multissource corroboration. So basically, you could have like agents talking to each other to verify whether something is trustworthy or not. The main takeaway here is even though we're in this kind of like new era, very very early days of LLMs being susceptible to whether it's poisoning in the training data or poisoning in the the rag retrieval process. I don't think this will be the case forever. And I would caution sites against trying to manipulate these tactics because what you don't want is to be treated as spam later on. In my experience, it's very, very hard to recover once a search engine or probably once an LLM starts to treat your website as spam. It's very, very hard to get back in their good graces. And this was a great presentation by Alex Holidayiday, who is the CEO of AirOps. He spoke uh just a few days ago at a Tech SEO Connect conference in North Carolina. And he provided some
information around things like separate pages for mark using markdown for separate pages for LLMs, using LLM.txt. You can watch this presentation online, but basically what he said is there's basically no evidence that LLM.txt is being used and that it kind of tries to solve a problem that doesn't exist because what we're seeing is that, you know, a lot of these large language models have been perfectly capable of understanding, you know, HTML on the internet. So, they probably don't need LLMs.txt just yet, although this is highly debated. I spoke to John Mueller about it. He he also said like you know there's we would probably hear from these companies if they needed something like separate markdown pages like we would hear from open AAI that they need that but they haven't made that clear to us yet. So you can use it there's just no real evidence that they are being leveraged just yet. Um and basically creating these separate versions like these markdown versions of pages it's probably not necessary either because as it stands right now LLMs are perfectly capable of crawling the internet and extracting content from HTML. So, you have to think about cloaking as well. Serving bots different content than
humans to me also raises a red flag because this goes against Google's cloaking guidelines. So, just be very careful because especially with Google's own LLMs like Gemini, AI mode, and AI overviews. If you're doing a lot of cloaking, that can potentially get you in trouble with SEO and therefore your visibility across those different LLMs as well. So, thank you everybody and we'll open it up to questions. >> Thank you. Thank you so much, Lily. What an incredible amount of information there uh to get us positioned into 2026 and beyond. We're fighting a whole another fight that does have such a resonance back to the old term of SEO bowling back in you know 15 to 20 years ago uh where there was just a negative uh effect on just putting sites uh your competitor sites on different terrible and and black hat type of domains. there. We're in that same space. I I I feel that well, we don't recommend this as an opportunity for for domains,
especially even short term, to be able to grab a hold and create a a better value for their domain. You're we're poisoning the well in this space. I see this as a defensive posture more than an opportunity, right? >> Yeah. No, I mean I think like although it's been a really big year of like hype and excitement around AI search, you know, I think a lot of people are looking for like what's the tactic, what's the shortcut that I can use and the reality is there are shortcuts you can use right now. I just like to see the bigger picture because I, you know, I've worked with so many companies over the years that have lost everything. If you guys have heard the stories that I've heard of site owners who in many cases didn't even know they were doing like SEO spam, they thought they were doing things right. Let's talk about the helpful content update. A lot of these companies lost everything and they literally didn't even know they were doing anything wrong. So, I just want people to be very cautious. I would be careful to do anything that your users and your customers wouldn't think is fair or ethical because ultimately I think that's kind of the the measurement or the criteria that these companies are using to determine what's what's fair and what's not, right? If you're
manipulating the system for your own benefit in a way that's not fair to your customers, I think you have to be very careful. >> Absolutely. Being mindful of I want to get to some questions here. Just a couple questions more for you from a defensive posture. You mentioned owning the platforms, being able to own your brand on all of these different areas to be able to at least control the narrative. How do you go about doing that? Uh what what are the procedure of actually grabbing a hold of of these brand entity in these different platforms? >> Yeah, I mean it kind of goes back to like like a I guess a subsection of SEO. It's not even necessarily SEO, but like the agencies I've worked at for a long time have done like online reputation management, right? Exactly. So, being being aware of all the different places number one that your brand can own a profile or have a listing like an owned listing and also where your brand is being mentioned or talked about. There's one new tool on the market by Rand Fishkin. It's called Alert Mouse. It's a better version of Google Alerts because Google Alerts kind of stopped working over the last few years. But check out Alert Mouse. It's the best tool that I've seen so far for monitoring brand
mentions. So, you can put your brand in there and you can get like literally a daily recap of all the different times your brand has been mentioned. You want to make sure that you are claiming those profiles for all the different places that you can claim them because that's a defensive tactic. And then when people are talking about you, you obviously want to monitor what they're talking about at the very least. Try to get ahead of those conversations. Um, and you know, if it's something like uh I guess like Trustpilot or something or like Yelp or like Google business profile where you can potentially even have conversations with consumers about different complaints that they might have, you want to get ahead of that too because LLMs can literally look at all that conversational data. >> You know, there's no easy way to be able to extract that data once you find it. There's no easy way to combat that malicious data. Any any recommendations on how that can be removed? Have you seen examples of kind of purging out some of that malicious poison LLM data? >> Um, it's really tricky right now, right? I think like a lot of this is going to boil down to like the LLM companies are going to have to, you know, take care of the LLM poisoning, which is why again I'd be very very careful to be involved
in anything resembling poisoning because what you don't want is your brand or your website or your company or your information to be flagged as spam and then not included at all in future training data. Um, but really like just having monitoring in place, right? You know, these these different platforms and different websites have different systems that you can use if someone said something defamatory about your brand. You know, Google has ways that you can actually like file DMCA takedowns or whatever it is to like get dangerous content removed from search results or removed from different websites. So, just monitoring as much as possible, I think is a good first step. >> Absolutely. Uh looking ahead, what guardrails like prompting rules, sourcing standards or or disclosure helps teams push for AI visibility without creating policy or PR risk? >> I mean, I think like it should be pretty self-explanatory if like you're doing if you're creating content for your users and in a way that's like digestible for AI search or if you're kind of like pushing the boundaries of doing something that might be seen as unethical or at least like spammy. You know, I think I talked a little bit
about like overengineering your content. So, it's really attractive to AI agents, but maybe when you're doing that, you're doing it in a way where it's not so much readable to humans anymore. Maybe it's very repetitive. Maybe you kind of lost that like nuance or that voice that's really appealing to your customers. I would be really careful to go too far in that direction. I think some people right now are advising people to like only write for machines and don't think as much about your readers. The reality is like we've had a lot of new data in the last couple weeks that indicates that people are really starting to switch to Gemini as opposed to ChachiPT. Who owns Gemini? It's Google. Who has the best anti-PAM measures in the world? It's Google. And I think Google's been very clear for very very many years about not serving different information to bots than they recommend serving to humans. In fact, they want to see that parody be as close as possible. So until we hear companies like Google and OpenAI literally saying please give us different content for AI agents which is like an example of that might be something like the agentic commerce protocol that openai recently launched
like yes that's for bots right you can literally structure that for bots otherwise anything that's going out there on the internet should be thought of as content that's for your readers as well and I think where the LLMs are trying to go is they're trying to elevate what readers see the same way that search engines have been doing for a long time. Couple questions from the audience and thank you very much for answering my questions there. Lily, are there any specific platforms you'd recommend for a B2B business website to prioritize with visibility ranking in these LLMs in Google? This is from Sheraf. Any thoughts there? >> That's a tricky one. There's like probably 250 new tools in our space at least. And to be honest, I use a lot of different ones. You know, our agency is using Profound for LM tracking. Um, but we've also looked at a lot of other fantastic platforms. I want to be very clear that like I've demoed personally probably like 10 to 15 LLM trackers and they're all really really great in different ways. So I'm not necessarily loyal to any single one, but you know some of the big names are profound and Semrush has AIO. HS brand radar conductor has a new tool. I would just
look at the one that makes the most sense for you if you can demo a lot of different ones and figure out what you know fits your budget. Like PKI for example is a little bit more affordable. There's a tool called W by Dixon Jones. >> I was about to mention that. Absolutely. Yeah. what AI knows about you. It's an acronym. W A I K AI A Y, sorry. That's a really great one that's very affordable as well. So, it kind of depends on your budget and what you're looking for, but have at least one because these tools give you a glimpse into even though it's not perfect, it's directional data about how frequently your your website's being cited compared to competitors. >> Roger that. Another question from Ian Chandler Marketing. Are LM's also flagging false positives for spam? If so, are there any technical or holistic steps that good actors can take to prevent that from happening? >> Good question. I wouldn't really know on my end whether they have that problem. I would imagine at this point probably not so much because the reality is like they're already having a hard enough flagging hard enough time flagging real spam that I don't know that there's too many, you know, issues of false positives. I think that right now, if
anything, there's a lot of like, let's say, purely AI generated content that's quite spammy that is meeting their criteria for really good content. And so I think they're kind of having the opposite problem where there's just so much obvious spam that's being treated as good content. Like think about the listical problem. But I wouldn't I really wouldn't really have a way on my end to know how big the false positive problem is just now. >> Just going to channel my inner inner Will Reynolds. Uh don't do effing listicicals going into 2026 just to be able to I mean it's chunked but it still is a place where you got to be able to present present great content to your user. Don't go the machine learning path. You got to stay away from that. And we should be trusting that the LMS are also going to be increasing their quality review of what they're actually presenting to the audience. Right. >> For sure. That's something I expect to be the biggest development in 2026. I think whether they explain this publicly or not because we don't really know what OpenAI does in terms of like external communications about these things just yet. I do anticipate whether or not they communicate it publicly, we're probably going to see some type of huge model
update with OpenAI where they're trying to get rid of a lot of this type of spam and poisoning. Well, Lily, thanks so much. There's a few other questions in there, but we're going to have to shift into our next presentation. Thanks a lot for what you've been able to cover, and we're going to have this entire video online for the uh for the future SEO uh audience in 2026. Thanks so much, and have a wonderful holiday. >> Thanks for having me. You, too. You're more the welcome.
Key takeaways
Chapters
Q&A
Lily recommends claiming brand profiles across all platforms, monitoring brand mentions using tools like Alert Mouse, and staying aware of where your brand is mentioned and talked about. Engagement on platforms like Trustpilot and Google Business Profile is critical for managing conversations with consumers. — Lily Ray
Removal is difficult; the focus should be on LLM companies themselves developing anti-poisoning measures. Monitoring is the first step, and platforms have systems for reporting defamatory content or filing DMCA takedowns, but there is no straightforward purging mechanism. — Lily Ray
Create content for users first, not just machines. Avoid overengineering content for AI that sacrifices readability. Only serve different content to bots if explicitly requested by companies like OpenAI or Google, which they have not yet done. Always maintain parity between human and bot-visible content. — Lily Ray
Lily recommends using LLM tracking tools like Profound, Semrush's AIO, Conductor, or more affordable options like Pike and WAIK to monitor how frequently your website is cited. Choose a tool based on your budget and needs; having at least one tracking tool is essential for understanding competitive performance. — Lily Ray
Lily doesn't have direct evidence of significant false positive issues. The opposite problem appears to be more prevalent: obvious AI-generated spam content is being treated as high-quality, such as listicle content, while LLMs struggle to detect real spam. — Lily Ray
Quotes
“I see the writing on the wall with what's happening right now with AEO and GEO. I think that we're going to start to see a crackdown in the next few months and maybe years as it relates to spam and LLM.” — Lily Ray
“Attackers actually don't need to control a percentage of the training data. Instead, it's just a fixed small number of malicious documents. So 250 documents that can reliably implant a backdoor in the LLM training data.” — Lily Ray
“John Mueller from Google literally said that optimizing sites for embeddings is literally keyword stuffing. When Google is saying something is a version of Google spam, it probably means that they're working on anti-spam measures.” — Lily Ray
“It all works until it doesn't. There's so many examples of people getting away with SEO tactics, GEO tactics, growing traffic really quickly in the short term up until they wake up one morning and all their traffic is gone.” — Lily Ray
“I would be careful to do anything that your users and your customers wouldn't think is fair or ethical because ultimately I think that's kind of the measurement or the criteria that these companies are using to determine what's fair and what's not.” — Lily Ray