AGI Soon As Possible · Deep reads on AI & tech
Article

AI answers can be manipulated: GEO targets the evidence itself, not the ranking

2026-07-02 · 4 min read

The real risk of GEO (generative engine optimization) is not gaming search rankings but poisoning the evidence and reasoning behind AI answers. A position paper accepted to ICML 2026 warns that GEO infiltrates the RAG evidence pool and creates three risks — platform concentration, source opacity, and a research gap. As the companion to the previous piece on getting cited, this is the dark side of the same technique. ASAP summarizes the result from the primary source.

The attack point moved from the page to the answer

Where GEO splits from SEO is in what it targets. SEO targeted the ranking of search results; GEO targets the evidence pool and reasoning that a generative AI uses to synthesize an answer. Manipulation moves from "which page rises to the top" to "what gets planted in the answer itself."

Why that shift is decisive becomes clear once you look at what the user actually sees. In engines that synthesize sources directly, such as ChatGPT Search and Google's grounding search, the user sees a single finished answer rather than a list of links. In the search era, even a manipulated page that rose to the top sat next to other links, so comparison was possible. Answer engines strip out that column of comparison. Commercial or malicious information planted in the evidence pool is presented as "the answer" with nothing to weigh it against. The foothold for manipulation narrows, but its impact when it succeeds grows.

Three risks that amplify each other

The three risks the paper names are all new surfaces absent in the search era.

RiskMechanism
Platform concentrationA few generative engines hold most queries, so one platform's manipulation sways public discourse
Source opacityData and retrieval processes are undisclosed, so users cannot verify whether the evidence is poisoned
Research gapUnlike SEO manipulation, academic study is thin, leaving policy and platforms unprepared

The three risks are not parallel; they amplify one another. When concentrated platforms hide their sources and research lags, manipulation spreads undetected. That is why the three-pronged response targets each one head-on. Promoting competition prevents monopolistic control by a few platforms and reduces the single point of failure; mandating disclosure requires platforms to reveal data sources, retrieval processes, and training methods transparently; and funding research dedicates academic support to GEO techniques, threats, and defenses. Each lever maps to concentration, opacity, and the gap in turn.

Why this paper matters to anyone chasing AEO

The paper is a counterweight for the practice of chasing citations. Getting cited (the bright side) and protecting the answer (the dark side) are two faces of one technique. Chasing citations through recency, evidence, and confidence, and keeping that evidence pool from being poisoned through transparent sourcing, branch from the same responsibility. In other words, the side that makes good content is also the side that could poison the answer ecosystem.

For Korean practitioners this warning arrives with a lag. Governance like mandated disclosure or promoting competition has no domestic framework yet, and the evidence pool of answer engines is mostly controlled by foreign platforms. The attack surface is already open while the defenses sit in someone else's hands. What a practitioner can do today is, at minimum, leave the sourcing of their own content verifiable and hold to a self-imposed norm of not fabricating evidence when chasing citations.

What this paper does not answer

One caveat is worth stating. The basis for this piece is not an empirical study but a position paper. Its nature is to name risks conceptually and propose a governance direction, not to measure how often or how large manipulation actually is. The very "research gap" the authors name is also this paper's own limitation. So the three prescriptions of competition, disclosure, and research are right in direction, but their concrete strength and priority remain blank. A practitioner is more accurate reading this paper as a map of the risks than as an answer key.

Source: Yizhu Wen et al., "Position: Generative Engine Optimization Creates Underexamined Risks, Governance Must Target Concentration, Disclosure, and Academic Blind Spots" (arXiv 2606.12439, 2026; ICML 2026 Position Track).

ASAP — AGI Soon As Possible

AI & tech,
read in depth

Beyond the headlines — into the context and the structure

AGI Soon As Possible · asapai.co.kr

← All posts