When a shopper asks ChatGPT, Perplexity, or Google's AI Mode "what's the best natural deodorant," the answer gets assembled, in a few seconds, from third-party web content the platform did not write and cannot fully police. There is no master ranking the platform controls end to end. That single fact explains both why these answers can be gamed and why the durable ways to influence them look suspiciously like ordinary good marketing.
This note summarizes what the public evidence supports, with the usual caveat for this space: most quantified claims come from parties selling the thing they measure. We label vendor-published numbers as such throughout.
1. The mechanics: everything runs through retrieval
Every major answer engine is retrieval-augmented generation over a search index. The pipeline, per practitioner teardowns and platform documentation, runs roughly: your question is decomposed into several sub-queries ("query fan-out"), each sub-query hits an index, candidate pages are fetched and chunked, passages are reranked, and the model synthesizes an answer citing the passages it leaned on (ziptie.dev teardown; Google on query fan-out).
The index differs by engine, and it matters:
- ChatGPT search and Microsoft Copilot both sit on Bing. A Seer Interactive study matching 500+ citations to SERP data found 87% of SearchGPT citations matched Bing's top results versus 56% for Google (Seer). Bing indexation is a single upstream chokepoint feeding two of the five major surfaces.
- Google AI Overviews/AI Mode ground in Google's own index — though rank gets a page into contention rather than guaranteeing a citation. BrightEdge (vendor panel) reports citation overlap with organic rankings fell from ~75% to 54% over 16 months (BrightEdge); passage-level studies show a well-structured mid-ranked page can be cited ahead of the #1 result (Advanced Web Ranking).
- Perplexity runs its own crawl plus live fetch, with the highest overlap with Google rankings — ~91% domain overlap per one vendor analysis (QuickSEO, vendor claim).
- Gemini's grounding is conditional: below a retrieval-confidence threshold, the model skips the web entirely and answers from training-era memory (Gemini API docs). For those queries only the "entity layer" — what the model already knows the brand is, via Wikipedia/Wikidata, review sites, co-occurrence in best-of lists — matters at all.
So a brand can drop out at three points: not in that engine's index (crawler/robots.txt gate — note that ChatGPT visibility is governed by OAI-SearchBot, not the GPTBot training crawler; the two decisions are independent, per OpenAI's bot documentation); indexed but not ranking for the fanned-out sub-queries; or ranking but not the clearest liftable passage for the specific claim.
Two more mechanics worth knowing. First, instability: ChatGPT's cited-source count reportedly fell ~20% after one model transition (Dataconomy) — whatever you measure today is a snapshot. Second, on what the models weight: the largest correlational dataset (SE Ranking, 129,000 domains) found referring-domain count the strongest single predictor of ChatGPT citation (Search Engine Journal), followed by passage structure — 120–180-word sections between headings roughly doubled citations versus very short sections in the same dataset.
2. The manipulation landscape, honestly described
People are actively gaming these systems. We catalogue this because operators should recognize the tactics — in competitors, and in agency pitches. We do not deploy any of them, and the evidence says you shouldn't either: set the ethics aside for a moment and each one is still a structurally bad bet.
Fake-product sites. A marketer built a three-page site for "Morrowen," a deodorant brand that does not exist, for about $11 and an hour of work; roughly three weeks later ChatGPT with browsing named it first in 4 of 4 relevant answers (Boys Club; Cybernews). It worked because a thin-competition niche plus a young retrieval stack had no entity corroboration. Both conditions are cheap for platforms to fix, and Google's May 2026 spam-policy rewrite explicitly covers "attempting to manipulate generative AI responses" (Google spam policies). The exploit window looks like 1–2 quarters, nothing durable comes out the other side, and the whole exercise is, obviously, fraud.
Undisclosed forum seeding. Reddit is among the highest-weight citation sources across engines (Profound, vendor data: top-cited domain on Perplexity and AI Overviews — Contently), which spawned an industry of aged sockpuppet accounts and upvote orchestration. The counter-evidence is brutal on two fronts. Platform enforcement: Reddit's 2026 LLM-based crackdown removed ~70% of automated posting accounts (SocialDay), and a ban for astroturfing is itself durable public content that follows the brand into every future AI answer. Volatility: Reddit's share of ChatGPT Search citations fell ~86% in roughly three days in August 2026 after an unannounced fan-out change (ExplainX). Even when the seeding "works," the surface it works on can evaporate in a week.
Fake and incentivized reviews. Review presence does correlate with being named (see §3), so review fraud follows. It is the one tactic with a regulator attached: FTC endorsement rules cover AI-amplified endorsements (Affiverse summary), G2 requires identity verification, and Trustpilot reports removing eight million fake reviews in one year (Compttr).
Undisclosed paid Wikipedia editing. Prohibited since the 2014 Wiki-PR investigation, sanctioned by a volunteer editor corps, and prone to backfiring publicly (Presenc).
Retrieval poisoning and prompt injection. The academic literature has demonstrated that appending crafted text to a single frequently-retrieved page can steer research agents' citations across many queries (Zhang et al., arXiv 2605.24245), and Microsoft Security catalogued 31 companies deploying "AI recommendation poisoning" prompts in the wild (Hacker News coverage). These are demonstrated mostly against research systems, not production engines. They are adversarial and likely unlawful, and individual injections are fragile: one reverted edit or one shipped filter ends them.
All five share a shape — a short-term payoff set against tail risk that outlives the gain, with decay arriving on a schedule nobody announces. The closest historical analogue, parasite SEO, went from policy announcement to algorithmic enforcement in about 17 months (Digital Hitmen). That is a reasonable half-life estimate for any AI-answer tactic a platform decides to name.
3. What honestly works
The tactics with the best evidence are the ones indistinguishable from writing and operating well.
Evidence-dense content. The one peer-reviewed causal study in this space — the Princeton-led GEO paper (arXiv 2311.09735, KDD 2024, 10,000-query benchmark) — found that adding attributed expert quotes, statistics with named sources, and inline citations lifted generative-engine visibility roughly 30–40% (read that as a ceiling; vendors routinely quote it as an average), with the biggest gains for lower-ranked sources. The same study found keyword stuffing reduced citation rates. Caveat: it tested 2023-era research engines, but it remains the most defensible finding available.
Answering questions only you can answer. In a controlled brand-visibility experiment, 96% of a new brand's AI visibility came from branded queries, and prompts about things only the brand could answer — how the product works, what changed in the latest version — drove 72% of all cited answers (Search Engine Land). Mechanism pages, ingredient and spec explainers, honest "who this is not for" pages, real comparison pages naming real competitors. In our read this is the highest-leverage organic surface a small brand has, and none of it involves deception.
Extractable structure and freshness. Direct-answer blocks, question-shaped headings, comparison tables, 120–180-word sections. AirOps (vendor research) found 83% of AI citations for commercial queries pointed to pages updated within twelve months (The VC Corner) — treat freshness numbers as directional, but the direction is consistent across sources.
Genuine reviews. Vendor-published and correlational, but consistent: 100% of tools ChatGPT named on "alternatives" queries had Capterra reviews and 99% had G2 (Quoleady). Real reviews compound. They survive model changes, since every retrieval stack reads the review sites, and they carry no regulatory exposure. Ask every real customer for one, and never gate the ask or condition an incentive on sentiment.
Accurate product feeds. For commerce specifically, OpenAI's merchant feed spec is primary platform documentation (developers.openai.com): verified merchants submit structured product data updated as often as every 15 minutes. There is no deceptive version of "submit accurate product data," and because the feed is a standing arrangement with the platform rather than a trick played on the model, it does not decay with model updates.
Earned third-party placement. Ranked listicles and comparison pages dominate commercial citations — 43.8% of ChatGPT source links in one Ahrefs analysis pointed to "best of" listicles (SubscribePR) — and being genuinely named on someone else's authoritative list beats publishing your own. Earned only: the paid-but-undisclosed version is the laundering described in §2.
And two things widely sold that the best evidence says not to pay for: schema markup (Ahrefs matched-control study of 1,885 pages: citation effects statistically indistinguishable from zero — Belmore Digital summary; do it as free hygiene) and llms.txt (Ahrefs, 137,000 sites: 97% of the files received zero traffic; no major provider commits to honoring it — Ahrefs).
The direction of travel
Between 2024 and 2026, every surface examined here tightened: Google's AI-manipulation spam clause, Reddit's enforcement purge, Wikipedia's disclosure sanctions, Trustpilot's removals, FTC attention. The direction is one-way. A program built on deception is short-dated by construction — each tactic decays on an unannounced schedule and leaves permanent negative residue in the very corpus every assistant reads.
Disclosed tactics run the opposite way. Real reviews, accurate feeds, evidence-dense content, and earned placement compound, and enforcement makes them stronger by clearing out the cheap competition. That asymmetry, as much as any ethical argument, is why we would point an operator's budget at the disclosed column.
MadContext is a research-driven practice working on AI-surface commerce. Sources above are linked inline; figures published by vendors of AI-visibility tools or services are labeled as vendor claims and should be read as directional.