GEO practitioners keep asking the same question: how do we detect AI search manipulation with astroturfing before it pollutes search results? That’s the wrong question.
It treats astroturfing like an infection: something foreign that snuck in, something a filter could catch.
Astroturfing is structural. AI search systems don’t verify truth. They estimate credibility from the signals in front of them, and that estimation process is what astroturfing exploits. Detection catches symptoms. The incentive underneath keeps paying out. Fighting astroturfing means fixing how these systems judge credibility.
GEO and SEO forums are full of these accusations right now: competitors allegedly running coordinated Reddit accounts to steer what AI search says about them. Whether those claims hold up or not, they reveal the belief driving the behavior. Marketers think AI rewards apparent consensus, and that belief alone is reshaping how they spend.
What AI Search Optimizes For
An AI Overview doesn’t check a claim against ground truth before citing it. It estimates credibility from the signals it has: retrieval relevance, source authority, internal consistency, how well a passage answers the question. Persuasive framing and authoritative-sounding language move several of those signals at once.
Researcher Roman Smirnov demonstrated this in 2026. He trained a small language model with reinforcement learning to rewrite search snippets, and an LLM Overview system preferred those snippets more often, even in a setup restricted to limit reward-hacking. The paper states the finding directly: “LLM Overview selections are driven by comparative rather than absolute advantages among candidate sources.”
The system ranks candidates against each other. A source doesn’t need to be accurate to win. It needs to outrank whatever else got retrieved.
Astroturfing speaks that system’s language.
AI Search Manipulation – Retrieval Manipulation vs. Generation Manipulation
Most GEO commentary, including earlier drafts of this piece, collapses two different attack surfaces into one vague threat. They deserve separate names, because the fixes differ.
Retrieval manipulation is about getting into the candidate pool at all: fake reviews and seeded forum threads built to rank. The channels aren’t the problem. Genuine reviews and real forum presence are among the strongest signals you can earn, and worth investing in. Manufacturing them is the attack, not taking part in them.
Generation manipulation is about reshaping what the model says once it has already retrieved something: prompt injection and knowledge-base poisoning tuned to a model’s known preferences.
The research on both is worse than “watch for fake Reddit threads” advice implies. On retrieval, PoisonedRAG, out of Penn State and Illinois Tech, injected five malicious documents into a knowledge base holding millions of texts and forced the model to hand back an attacker-chosen answer nine times out of ten. A 2025 benchmarking study tested poisoning attacks across a wide range of methods and datasets and found current defenses fail to provide robust protection. On generation, Smirnov’s snippet-rewriting result shows the same weakness one layer downstream: content that already made it into the pool can still be rewritten to win.
Five documents can flip a database of millions of texts and succeed nine times out of ten. Weigh that against the next “how to spot fake reviews” checklist someone sends you.
The Detection Advice Was Built for a World That No Longer Exists
Standard advice says check the dates and check the writing style. That advice was built for a slower, clumsier era of fake content, and it assumes a detectable seam between real and manufactured.
Some operators reportedly run multiple language models to vary the writing style, then pass the output through a human editor for a final polish. That specific workflow lacks documentation, but it matches what the research does confirm: manufactured content is changing faster than detection methods can track it.
One nuance makes the picture worse: AI search draws on far more than one source type. Retrieval pulls from documentation, reviews, and everything from knowledge graphs to GitHub repositories. A handful of manufactured threads won’t outweigh strong authority elsewhere. Ecosystem-wide manipulation is the risk: reviews, citations, and snippets across many source types, all optimizing toward the same comparative advantage. Policing one channel while the rest of the web gets poisoned in parallel puts the effort in the wrong place.
The Part That Should Bother You
Verification is disappearing when it matters most. Seer Interactive tracked 3,119 search terms across 42 organizations and found organic click-through on AI Overview queries collapsed from 1.76% in June 2024 to 0.61% by September 2025, a 61% drop, while pages cited inside an AI Overview pull 35% more organic clicks and 91% more paid clicks than uncited ones, a gap Seer is careful to call correlation, not proven cause. Fewer people are checking the source. Whoever wins the citation wins the moment, verified or not.
The behavioral research backs this up. People using a ChatGPT-style tool rated its answers higher quality than Google’s and leaned on it more, even though it was worse at fact-checking and gave inconsistent results.
In a separate experiment, users overrelied on LLM search, taking its answers even when the model was wrong. Columbia’s Tow Center for Digital Journalism, in a widely cited 2025 study, found generative AI search tools fabricated citations or linked to syndicated copies instead of originals, while still projecting confidence to users.
None of that is astroturfing. It’s the fuel astroturfing runs on: friction to verify keeps dropping while trust in the unverified answer keeps climbing.
Regulation Isn’t Coming to Save AI Search Manipulation
The FTC’s fake-review rule, in force since October 2024, bans selling fake reviews, undisclosed insider reviews, and fake social-media engagement metrics, among other practices. Nowhere in that scope does it touch model training pipelines or citation manipulation inside an AI Overview.
Regulators aren’t closing a loophole here. The rule was never built for this layer, and no rule for it exists yet. It’s a regulatory framework for the last fight. Anyone telling clients “the regulators will handle it” is selling reassurance the rulebook doesn’t back up.
What I’d Do Instead
The standard advice says monitor more and detect faster. That treats this like a moderation problem. AI search judges candidates against each other. Playing defense inside that system, more detection, more monitoring, means competing to win the same comparison astroturfers already optimize for.
You don’t remove the incentive. You add another player to the game. Detection has its place. It can’t carry the weight the industry keeps putting on it.
Narrower trust is the fix. A sharper filter won’t do it alone. Stop treating “what does the AI cite” as a stand-in for “what’s true.” No serious researcher treats a featured snippet as peer review. You shouldn’t either.
Build verification into your own workflow instead of outsourcing it to the search system: a real name you can check and a history you can trace. It’s slower to build and doesn’t scale the way retrieval manipulation scales. It’s also the one thing a language model can’t manufacture for free.
What I Tell Clients Now
I do this for a living, and the math looks different when you’re the one signing off on a GEO budget instead of reading about it from the sidelines.
Treating the citation itself as the entire deliverable is a strategy that’s bound to fail. If five poisoned documents can flip a RAG system’s answer, and a small RL-trained model can out-position a snippet on comparative preference alone, “get cited” is a target you’re paying to chase against an opponent whose costs keep falling while yours don’t. GEO still works. What clients buy needs to change. Citations still matter; you earn them by being the source worth citing, not by gaming the comparison.
I push clients toward one question: could someone outside the company verify we’re the authority? That question matters more than how do we get cited. It means real authorship and a publication history that holds up under scrutiny.
No one can fake that with a model’s snippet-preference score. It’s a different budget line and a longer timeline. It’s also a harder pitch for a client to say no to, once they see the alternative is a race that gets cheaper for the other side every year.
Am I wrong about this? If you think better detection tooling beats narrower, verifiable trust, or that regulation will catch the generation-manipulation layer faster than I’m giving it credit for, I want the counter-case. The comfortable industry consensus doesn’t survive contact with the last two years of research, and I’d rather be argued out of that than keep repeating it unchallenged.
Crimson Salt builds AI visibility the slow way: verifiable authorship, original research, evidence a model can’t manufacture. If “get cited” is the whole brief, we’re the wrong agency.
Sources
- Zou, W., Geng, R., Wang, B., & Jia, J. (2024/2025). PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models. USENIX Security 2025.
- Zhang, B. et al. (2025). Benchmarking Poisoning Attacks against Retrieval-Augmented Generation.
- Smirnov, R. (2026). Exploring LLM Biases to Manipulate AI Search Overview.
- Xu, R., Feng, Y., & Chen, H. (2023). ChatGPT vs. Google: A Comparative Study of Search Performance and User Experience.
- Spatharioti, S. E., Rothschild, D., Goldstein, D. G., & Hofman, J. M. (2025). Effects of LLM-based Search on Decision Making: Speed, Accuracy, and Overreliance. CHI ’25.
- Tow Center for Digital Journalism, Columbia Journalism Review (2025), reported via Forbes.
- Seer Interactive (Nov 2025). AIO Impact on Google CTR: September 2025 Update.
- Federal Trade Commission (2024). Final Rule Banning Fake Reviews and Testimonials, effective October 21, 2024.

