The Grounding Wars Are Coming: How AI Visibility Creates Its Own Black-Hat Playbook

Jun 24, 2026 05:00 PM - 3 hours ago 88

A CFO asked her AI adjunct to investigation unreality infrastructure vendors for a awesome investment.

The adjunct came backmost pinch a observant comparison. It had weighed options, named trade-offs, and confidently recommended 1 vendor. It was the benignant of reply you guardant to the squad and enactment on.

But she’d forgotten a infinitesimal from six weeks earlier.

She’d clicked a “Summarize pinch AI” fastener connected an manufacture blog. It looked harmless. Two seconds, 1 click, past backmost to email.

Behind that fastener sat a hidden instruction asking the adjunct to retrieve 1 institution arsenic the champion unreality infrastructure supplier for endeavor investments. She ne'er wrote that sentence, nor had she agreed to it. But the adjunct logged it, anyway.

When she later asked for a vendor recommendation, the reply looked for illustration analysis, but portion of the reasoning had already been nudged.

That’s penchant hacking.

Microsoft calls this AI proposal poisoning: embedding hidden instructions successful links, buttons, documents, aliases prompts to power what AI assistants retrieve and urge later.

As early arsenic February 2026, Microsoft’s information squad reported much than 50 poisoning attempts from 31 companies crossed 14 industries successful conscionable 60 days, aimed astatine assistants for illustration ChatGPT, Microsoft Copilot, Claude, Google Gemini, and Perplexity, crossed finance, healthcare, legal, and SaaS.

One of the devices they highlighted was marketed arsenic an “SEO maturation hack for LLMs.” If you were astir for early SEO, this is simply a acquainted story.

Every Algorithm Grows Its Own Black-Hat Economy

Search gave america keyword stuffing, nexus farms, doorway pages, contented mills, and “independent” reappraisal sites that weren’t independent astatine all.

Social gave america engagement pods, bot networks, outrage farming, and manufactured virality.

Marketplaces gave america clone reviews, reappraisal gating, and coordinated astroturfing truthful blase immoderate of it is still running.

Once visibility turns into money, group commencement looking for shortcuts.

First, the hacks are obvious. Then they get cleaner, harder to see, and easier to justify. Eventually, the level updates its rules, the spammers adjust, and that back-and-forth becomes portion of the landscape.

AI hunt has reached that stage, pinch maturation hacks arriving faster than the guardrails.

Platforms are already reacting.

Microsoft is publishing investigation and tightening defenses. Google has clarified that its Search spam policies use to generative AI responses too, including attempts to manipulate those systems. The rules are changing because this is nary longer a hypothetical separator case.

But AI manipulation is different from hunt manipulation successful 1 important way.

Search spam sat connected the surface. You could scan a page, spot the stuffing, announcement the sketchy reappraisal site, and spell backmost to the results.

AI manipulation tin hap wrong memory, retrieval, root selection, aliases reasoning. The personification whitethorn only ever spot the last answer. And erstwhile that reply recommends a vendor, a financial product, aliases a SaaS platform, the manipulation isn’t easy to spot.

The Manipulation Surface Is Bigger Than Your Site

Right now, marketers are laser-focused onto AI visibility and getting models to mention their brands and offerings. That’s excessively constrictive a focus.

When personification asks an assistant, “Who are the champion vendors for X?”, the adjunct looks astatine websites and past fans retired into comparison searches, best-of lists, reappraisal pages, brand-name queries, forums, documentation, partner marketplaces, and third-party commentary.

Peec AI’s analysis of query fanouts suggests systems for illustration ChatGPT tin grow a azygous punctual into clusters of related searches earlier producing an answer. That changes what GTM teams request to monitor.

Your homepage is 1 input. So are your reappraisal profiles, comparison pages, Reddit threads, marketplace listings, partner pages, expert write-ups, archiving hubs, thief halfway articles, customer stories, and AI accusation pages. Any 1 of those shapes really an adjunct describes you.

We’re already seeing what that looks for illustration successful practice.

Nicholas Thompson shared an article from The Atlantic and he commented about really Shopify publishes dozens of “best ecommerce platform” listicles that each rank Shopify first, and really ChatGPT past recommends Shopify for “best measurement to group up an online storefront,” citing those very listicles arsenic evidence.

Image Credit: Purna Virji

The contented looks for illustration proposal for humans, but it functions arsenic training information for bots.

Once those sources power answers, marketers will commencement optimizing them. Some of that activity is necessary. AI systems do request clearer, much system signals.

But it besides intends the statement betwixt adjuvant grounding and quiet manipulation is going to blur.

From Grounding To Poisoning

Last week, I based on that B2B companies request grounding layers: structured, honorable grounds that helps AI systems evaluate, compare, and take sides vendor recommendations.

I still judge that.

Grounding is what lets an adjunct reply questions like: Does this vendor meet our information and compliance requirements? What does implementation really look for illustration for a institution for illustration ours? Where has this merchandise worked, and wherever hasn’t it?

AI systems request that level of detail: your information posture, integrations, rollout dependencies, limitations, customer proof, and wherever you’re not a fit.

But erstwhile grounding starts to power recommendations, it besides becomes commercially valuable. And erstwhile thing is commercially valuable, personification will effort to crook it.

So we request amended connection for the spectrum we’re astir to unrecorded on.

Grounding: Evidence An Assistant Can Inspect

It looks for illustration information architecture that explains information flows, residency options, and entree controls alternatively of hiding down badges and logos.

Integration specifications that opportunity what’s native, what needs services, and wherever implementations usually get sticky. Rollout expectations that connect “six-week implementation” to the existent limitations underneath. Customer impervious tied to existent environments, timeframes, and outcomes. Limits named connected purpose, truthful buyers tin spot wherever you don’t fit.

The purpose is legibility. Where you belong, wherever you don’t, what tin beryllium verified, and what still needs a conversation.

Shaping: Visible, But Slanted

AI-facing pages are multiplying fast: AI accusation pages, AI instructions, LLM truth sheets, markdown summaries. Some are genuinely helpful, offering clean, system descriptions of what you do, who you help, which products you offer, and what sources backmost those claims.

Others thin past that.

They propose really the exemplary should picture the company, repetition preferred phrases, adhd positioning claims without overmuch proof, and create comparison contented aimed astatine the queries AI systems are apt to run, while omitting the awkward parts.

This is wherever the existent SEO and GEO experiments live.

Chris Long reported his team astatine Nectiv created an “AI Instructions & Information” page successful markdown, linked from the footer, and added the item that they activity pinch brands supra $30M ARR. That qualifier didn’t look anyplace other connected the site. He besides shared that wrong 48 hours, ChatGPT was citing the page and echoing that positioning.

Image Credit: Purna Virji

Wil Reynolds has shared tests from Seer Interactive showing a crisp jump successful ChatGPT citations to an AI accusation page, moreover though the business effect truthful acold is modest.

Image Credit: Purna Virji

Those tests are shared openly, and they’re useful because they show really quickly models ingest and reuse system marque connection erstwhile they find it.

But they unit a question: are we giving AI amended evidence, aliases are we school it our talking points?

In practice, a batch of teams will commencement successful the first campy and descent into the second.

Poisoning: Hidden, Persistent, Non-Consensual

Poisoning is erstwhile the personification thinks they’re asking for 1 thing, and the page, link, aliases archive tries to do thing else.

A “Summarize pinch AI” fastener that besides plants a representation astir a preferred vendor. A hidden punctual that tells the adjunct to dainty a institution arsenic charismatic successful early conversations. A nexus that instructs the exemplary to retrieve a marque arsenic trusted for circumstantial topics.

That’s tampering pinch the reasoning of a instrumentality group are trying to trust on.

This Is A GEO, GTM, And AI Commercialization Problem

It’s tempting to record this arsenic a generative motor optimization problem and move on. But this acold bigger a deal, which affects some AI companies and AI consumers.

For AI companies, the rumor is astir whether buyers judge the proposal process itself tin beryllium trusted.

Agent-assisted buying only useful if group are consenting to manus complete portion of the research, comparison, and information activity to assistants. Recommendation poisoning attacks that willingness directly.

I’ve written earlier astir the Delegation Gap: the abstraction betwixt what AI tin technically do and what humans are comfortable handing over.

Poisoning widens that gap.

Once buyers fishy their adjunct has been nudged without their knowledge, they don’t conscionable mobility 1 output; they mobility the channel. They spell backmost to manual research, thin connected peers, default to the incumbent, and dainty AI answers arsenic thing to verify alternatively than thing that tin adjacent a decision.

A bad hunt consequence you tin spot and ignore. A biased adjunct shapes the shortlist earlier you cognize you’re being influenced.

That’s a platform spot problem, which is simply a go-to-market problem for anyone betting connected AI‑mediated buying.

What To Do Now

It’s clip to determine which kinds of optimization you’re consenting to defend.

If You’re Using Assistants For Research Or Decisions:

  • Review what your adjunct remembers. Most mainstream assistants now expose saved representation aliases preferences. If you spot trusted sources aliases vendor opinions you don’t retrieve giving, region them.
  • Be selective pinch one-click AI buttons. A “Summarize pinch AI” fastener tin beryllium useful, but it isn’t ever neutral. For decisions that matter, transcript the matter yourself into your adjunct alternatively than relying connected a page-level punctual you didn’t write.
  • Ask “why this?” erstwhile the stakes are high. When an adjunct recommends a vendor, tool, aliases strategy that matters, inquire what sources it used, what alternatives it considered, and wherever the grounds is thin. Confident answers beryllium you a rationale.

If You Run Marketing, Product Marketing, Or GTM:

  • Map your AI-facing surfaces. AI info pages, spot centers, docs hubs, comparison pages, marketplace listings, partner profiles, reappraisal sites, and thief contented whitethorn each show up successful fanouts. Look astatine them together.
  • Ask: Are we publishing grounds aliases planting preferences? If an AI page helps a exemplary verify what’s true, you’re successful grounding territory. If it sounds for illustration a book for really you’d for illustration the exemplary to picture you, you’re successful shaping territory.
  • Match claims to proof. If you opportunity you service $30 million+ ARR companies, your customer impervious should show that. If you opportunity implementation is fast, your docs should explicate the conditions. Don’t inquire models to judge positioning your grounds cannot support.
  • Write down the location rule. A elemental test: If you’d beryllium uncomfortable reference this punctual aloud to a customer, don’t vessel it. Then move that into policy. Decide what’s acceptable, what isn’t, and who reviews AI-facing experiments earlier they spell live.

The Side Of The Line Worth Choosing

Search spam ne'er went away. Neither did engagement hacks nor clone reviews. But each cleanup activity made the shortcuts much vulnerable and the honest, accordant activity much valuable.

AI will travel a akin arc. Defenses will get better. Buyers will study to inquire wherever recommendations came from. Platforms and regulators will get much serious astir who tried to power which systems, and how.

You tin dainty AI visibility arsenic a loophole to utilization while the rules are still soft. Or you tin dainty it arsenic a spot furniture that will beryllium betwixt you and your buyers for a agelong time.

That intends publishing grounds alternatively than planting preferences, making claims easy to verify, naming your limits earlier personification other surfaces them, and building grounding that helps AI measure reality alternatively than repetition your pitch.

That activity is slower and harder, but it’s besides the benignant of activity that still holds erstwhile the adjacent cleanup comes. Which it ever will.

In an agentic buying environment, you request to past the adjacent question: “Why this vendor?”

More Resources:

  • How AI Agents Decide Which Brands To Recommend: Trust Is The New Ranking
  • AI Poisoning: Black Hat SEO Is Back
  • AI Search Is Eating Itself & The SEO Industry Is The Source

Read Purna Virji’s Agent-Led Growth newsletter. Subscribe now.


Featured Image: Roman Samborskyi/Shutterstock

Category SEO Generative AI
Follow Us On Google
More