Is Your Agency’s GEO Work Now a Penalty Risk? What the August 2026 Spam Update Confirms (and What It Doesn’t)

Google Spam Update  August 2026

Is Your Agency’s GEO Work Now a Penalty Risk? What the August 2026 Spam Update Confirms (and What It Doesn’t)

Google says the August 18 rollout is a “normal spam update.” The industry is sure it’s the first enforcement pass against AI search manipulation. Both can be true. Here is the confirmed-versus-inferred split, and a line-by-line risk map of the GEO service menu.

GEO penalty warning graphic with a red alert symbol and declining AI visibility chart

At 9:27 a.m. Pacific on August 18, Google’s Search Status Dashboard logged a new incident affecting ranking: the August 2026 spam update. Within the hour, the SEO community had moved past “what is it” to a more loaded question: is this the enforcement pass for AI search manipulation, and if so, how much of the “GEO” and “AI visibility” work agencies have been selling for the past 18 months just became a spam violation?

Google has not confirmed that. It called this a “normal spam update” and shipped no new policies with it. But here is the part most of the coverage has missed: the question was already answered, in writing, three months before this update rolled out. On May 15, Google quietly added “attempting to manipulate generative AI responses in Google Search” to its definition of spam. Whatever this week’s update specifically hit, the rulebook an agency’s GEO work is judged against already exists.

This article separates what Google confirmed from what the industry is inferring, explains why the AI-enforcement theory is plausible but unproven, and then does the thing that matters for your client roster: it maps the tactics actually sold under the GEO label to the policy text, with a risk grade for each.

What Google actually confirmed

Start with the narrow set of facts that are not up for debate. Google announced the update itself, and most of what follows comes from its own statements, its spam update documentation, and answers John Mueller gave publicly after launch.

The August 2026 spam update: confirmed facts

Everything below is from Google’s own statements or documentation. Everything else in circulation is inference.

Confirmed by Google
Timing: rollout began August 18, 2026, 9:27 a.m. Pacific, logged on the Search Status Dashboard as an incident impacting ranking.
Scope: global, all languages. Google says the rollout “may take a few days to complete.”
No new policies: Google announced no new spam policy types. Its spam updates documentation page had not changed since December.
Exclusions: per Search Engine Roundtable’s Barry Schwartz, Google told him this update does not target link spam, does not target the site reputation abuse policy, and excludes some other policies handled by separate systems.
Recovery: Google said recovery can take many months, because its automated systems need time to re-learn that a site complies. Google will do periodic refreshes.
No impact numbers: Google declined to say what percentage of queries or searches were affected.
Not pre-rolled: John Mueller said Google does not roll these out before announcing them: “We try to get the announcement as close as possible to the actual button-pushing.”

Sources: Google Search Status Dashboard and release notes, via Search Engine Journal and Search Engine Roundtable; Search Engine Land.

One more confirmed fact that deserves its own line: this is the third spam update of 2026, after March and June. The March rollout completed in 19 hours and 30 minutes, the fastest confirmed spam rollout in the dashboard’s history. The June rollout took two days. Whatever else is true, Google has clearly shifted spam enforcement into a faster, more frequent cadence this year.

Why everyone thinks this update targets AI manipulation

The inference is not random. It rests on a sequence that is easy to draw and hard to ignore: Google rewrote its spam definition, then shipped two enforcement updates.

The enforcement runway: policy first, then the vehicles

The 15-month sequence that turned “manipulating AI responses” from an unpolicied gray zone into an active enforcement category.

Mar 2024 Spam catalogue ships: scaled content, expired domains, site reputation May 15, 2026 One line added to the spam definition: “manipulate generative AI responses.” Same day: Illyes compares bought mentions to paid links. Late May 2026 Google publishes its AI optimization guide: warns against “inauthentic mentions.” Jun 24, 2026 First spam update after the clause. Aug 18, 2026 Second spam update after the clause. Link spam and site reputation excluded. The uncomfortable arithmetic for GEO vendors: 1. The spam definition now explicitly covers manipulation of AI Overviews and AI Mode. 2. The two biggest enforcement categories (link spam, site reputation abuse) were excluded from this update, which narrows the field of what it could be hitting. 3. Two enforcement vehicles have now shipped since the rule changed. Google has not ruled the AI target out.

Timeline assembled from Google’s spam policies page (dated May 15, 2026), Search Engine Roundtable’s report on Gary Illyes’ Sydney remarks, Google’s AI optimization guide, and Schwartz’s update breakdown. The inference in the bottom block is ours, and it is an inference.

There is also a motive you can measure. Citation slots in AI answers became scarce, and therefore valuable, before Google ever changed a policy line. Pew Research Center tracked 68,879 Google searches from 900 U.S. adults and found that visitors clicked a traditional result in just 8 percent of visits when an AI summary appeared, versus 15 percent when none did. Only 1 percent clicked a link inside the summary.

Why citation slots became worth manipulating

Share of Google visits that ended in a click on a traditional result. Pew Research Center, March 2025 data.

15% Visits without an AI summary 8% Visits with an AI summary 1% Clicks on links inside the summary

Fewer clicks, same attention: when an AI summary appears, the citation becomes the prize. Source: Pew Research Center, July 2025.

Scarcity did what scarcity always does: it created a market. The manipulation is not hypothetical. In February 2026, Microsoft’s Defender security team published research on a pattern it called “AI recommendation poisoning,” in which hidden instructions embedded in “Summarize with AI” buttons plant persistent product recommendations into AI assistants’ memory. Microsoft said its analysis returned “numerous real-world attempts,” not a thought experiment. Meanwhile, an entire vendor category has grown up selling guaranteed placements in AI answers, often labeled GEO, AEO, or “AI visibility” packages.

So the industry’s read of this week’s update is understandable: a rule was written in May, and the second enforcement vehicle since then just rolled out with the two biggest non-AI categories explicitly excluded.

The honest counter-case: what we do not know

Now the other side, because it is stronger than the hype merchants admit.

Google shipped nothing with this update. When Google changes the rules, it publishes documentation, blog posts, and help pages. This update arrived bare: no policy changes, no companion post, and Google’s LinkedIn statement was two sentences of “normal spam update.” That procedural point, made well by Launchcodex’s analysis, is the single best argument against the AI-enforcement theory.

The “AI content crackdown” version of the theory is weak. Independent analysis of Common Crawl data, covered by Axios and cited by Launchcodex, found AI-generated articles made up roughly 44 percent of newly published English-language pages in April, around 61 million pages, up from about 20 percent in June 2025. Yet mass-produced AI content already underperforms in rankings without any special enforcement pass. Google does not need a spam update to do what its quality systems are already doing to commodity content.

No confirmed AI-citation casualty exists yet. Every site owner claiming this update hit their GEO work is self-diagnosing. The only confirmed targets are whatever violates the existing, non-excluded policies: scaled content abuse, expired domain abuse, cloaking, doorway abuse, scraping, and the rest of the catalogue.

The position worth holding: treat this update as routine multi-policy enforcement that may include AI-answer manipulation as one category among several. That is roughly Launchcodex’s “moderate confidence” read, and it is ours. Anyone telling you Google confirmed an AI-manipulation crackdown this week is selling something.

The part everyone is missing: the GEO question was answered on May 15

Here is the reframe that matters for your agency, and it does not depend on what the August update targeted at all. Read the current spam policies page:

“In the context of Google Search, spam refers to techniques used to deceive users or manipulate our Search systems into featuring content prominently, such as attempting to manipulate Search systems into ranking content highly or attempting to manipulate generative AI responses in Google Search.”
Google Search Central documentation, page dated May 15, 2026

That one clause does three things at once. First, it makes manipulation of AI Overviews and AI Mode a spam violation, full stop, with no separate AI rulebook. Second, the page states the policies “apply to all web search results, including those from Google’s own properties.” Third, Google’s own guide to optimizing for generative AI features spells out the consequence: trying to manipulate generative AI responses “can harm a site’s visibility and may even lead to a site not showing up in Search results at all, including AI features.” One penalty, every surface: a site demoted for spam loses its rankings and its place in the citation pool.

And in case anyone thought the clause was housekeeping, Google’s Gary Illyes addressed it publicly on the very day it was published. At Search Central Live Sydney on May 15, Illyes and Cherry Sireetorn Prommawin strongly cautioned against buying or manipulating brand mentions to get into AI responses, comparing the practice to paid links, which Google’s systems “detect, disregard, and ultimately ignore.” Notably, they did not confirm that organic, authentic mentions provide any direct benefit either.

“This reminds me of the pre-Penguin link building services and how things can go well for a while and then overnight, things go really really bad.”
Barry Schwartz, Search Engine Roundtable, on paid-mention services for AI answers

The parallel to Penguin is the right frame for agency owners. Bought links were a viable-looking business for years before enforcement landed, and the agencies holding those links when Penguin arrived spent the next decade doing disavow work and recovery. The May 15 clause means bought AI mentions now sit in the same policy bucket, with one aggravating detail: the blast radius includes the AI surfaces your client hired you to win.

As Ben Austin of Absolute Digital put it in June, any brand that bought its way into AI Overviews or LLM citations over the past 18 months “now holds the same risk profile as a brand that bought links in 2011.” His forecast: a two-to-four-quarter window between the policy clarification and serious enforcement. Two spam updates in ten weeks suggests that window is already being used.

The GEO service menu, mapped to the spam policies

This is the table to take to your next service review. It maps the tactics actually sold under GEO and AI-visibility labels to the policy language that now governs them. Risk grades are our assessment based on the documented policy basis, not a statement from Google.

Risk map: the agency GEO menu against Google’s written policies

Policy basis cites the specific part of Google’s spam policies or AI optimization guide that covers the tactic.

Tactic sold as GEOPolicy basisRiskThis week’s move
Purchased AI mentions
Paid placements in blogs, forums, “top 10” lists engineered to get your brand cited in AI answers
“Seeking inauthentic mentions” warning in Google’s AI guide; Illyes’ paid-links comparison; manipulation clause High Inventory every placement that exists only because an AI surface exists. Stop renewals now.
Engineered citation campaigns
Press-release spam, fake expert quotes, manufactured “reviews” seeded for LLM retrieval
Manipulation of generative AI responses clause; spam policies apply “to all web search results” High Audit the last 18 months of off-site work. If you cannot explain the placement to a client without saying “it’s for the AI,” it is exposure.
Expired-domain redirect portfolios
Buying expired competitors or authority domains and 301-ing them into client sites
Expired domain abuse policy, explicitly in scope for this update (link spam was excluded, this was not) High Pull the redirect list today. This is the tactic dominating early casualty self-reports.
Scaled AI content production
Publishing dozens to hundreds of pages per day with little original value
Scaled content abuse policy, in scope; AI content already underperforms in quality systems High Shift from volume targets to consolidation: prune, merge, and add first-hand substance.
Serving AI crawlers special content
Separate markdown pages or modified content just for AI bots
Cloaking policy; Google and Bing signaled in February 2026 that AI-crawler-specific content qualifies Elevated Anything a crawler sees, a user should be able to see. Remove forked versions.
Technical AI-readiness work
Crawlability, structured data, entity clarity, quotable and well-sourced content
No policy conflict; Google’s guide calls this “still SEO” and points to its own Search Console AI report Safe This is the keep-list. It is also the honest definition of GEO.
llms.txt files, “chunking” rewrites
Tactics marketed as AI-specific hacks
Google’s guide says to ignore them: “unnecessary AI text files,” no ranking benefit claimed No risk, no value Stop billing for them. They do not violate policy, but they waste retainer trust.

Policy sources: Google spam policies, Google AI optimization guide, Illyes remarks via Search Engine Roundtable. Risk grades are On-Page.ai’s assessment.

The dividing line is the one Derick Do, co-founder of Launchcodex, uses with his own clients: “We audit AI visibility work the same way we audit links. If a page or a placement only exists because an AI surface exists, it comes out. On one inherited account we removed 40 paid mention placements before the June rollout, and organic sessions never dipped.”

That last clause is the sales argument nobody uses enough: the bought placements were not moving the numbers anyway. Removing them costs nothing measurable and deletes a standing penalty risk.

What the early casualty reports actually show

Three days in, the anecdote pool is real but unconfirmed. Treat every one of these as a site owner’s self-diagnosis, not a verified hit category. Still, the pattern is telling.

  • In one r/SEO thread, a site owner who bought a competitor’s expired domain and redirected its product pages to matching pages on his own site wrote: “This explains why I suddenly lost most of my traffic from Google… This approach seems to now qualify as ‘expired domain abuse’.” The same tactic showed up in a second thread days later: “Google said this is not a link update but it looks like I’ve been hit and the only ‘spammy’ thing I do is redirect relevant expired domains.”
  • One agency-side poster reported a 50 percent traffic drop in a day from a site that had been stable for 12 months. The top comment in that thread corrected the diagnosis: “This was a spam update, not a core update.” That distinction changes everything about the recovery path.
  • An informational site owner reported falling from more than 2,200 organic users per day to about 1,200 the day the rollout started, and a small site owner posting “I got nuked” described a drop from roughly 900 impressions and 50 clicks a day to 100 impressions and nearly zero, while conceding the site “has an AI look.”
  • Winners exist too: at least one site owner reported a 20-fold traffic jump. Spam updates redistribute; they do not only subtract.

Two things stand out. First, expired-domain redirects dominate the self-diagnoses, which is the one in-scope tactic Google has never left ambiguous. Second, nobody credibly claiming an AI-citation penalty has produced evidence of one. The sites getting hit look like classic spam-policy targets wearing GEO costumes.

How to read the next two weeks without making it worse

The rollout takes days, Google does refreshes, and recovery takes months. That is the official cadence, which means panic-edits this week are both premature and potentially self-sabotaging. Here is a reading schedule that matches how spam updates actually behave:

The post-update data schedule for client sites

What to check, and when, based on Google’s stated rollout and recovery behavior.

Day 0 Aug 18. Mark the date. Change nothing. Day 4–7 Compare 2-week windows in Search Console, by page and by query. Day 14 Check the manual actions report. Manual = fixable, with reconsideration. Day 30 Re-check. Refreshes can move sites after the rollout “completes.” Day 60 Recovery window. Google: recovery can take many months. Day 90 Still down, no policy match? Re-open cause attribution. Algorithmic spam hits have no reconsideration request. Only manual actions do. That is why day 14 matters.

Schedule adapted from Launchcodex’s data-reading guidance and Google’s stated recovery behavior, via Search Engine Roundtable.

For the client conversation, one distinction earns you more trust than any forecast: spam update versus core update. A core update says someone out-earned you. A spam update says Google believes a line was crossed. If a client’s site moved this week and they cannot point to the policy line, your job is to find it before the client fires the retainer for an answer that was wrong.

What safe GEO actually looks like

None of this means AI visibility work is dead. Google’s own guide is explicit that AEO and GEO are “still SEO,” rooted in the same core ranking and quality systems, using retrieval-augmented generation over the normal Search index. The safe menu is boring, which is precisely why it survives enforcement cycles:

  1. Original, expert-led content with a genuine point of view. Google’s guide says this influences AI presence “more than any of the other suggestions.”
  2. Clean technical foundations so AI features can retrieve and ground your pages: crawlability, structured data, accurate entities.
  3. Content written to be quotable: clear answers, attributed data, named experts. Citations follow usefulness, not the other way around.
  4. Monitoring through Google’s own Generative AI performance report in Search Console, rather than third-party promises.
  5. Earning mentions the old way, or not at all. Per Illyes, Google’s systems were never sure authentic mentions help much, and bought ones are treated like paid links.

The bottom line

Did Google confirm the August 2026 spam update targets AI search manipulation? No. It confirmed a normal, global spam update that excludes link spam and site reputation abuse, with no new policies attached.

Is an agency’s GEO work now a penalty risk? Parts of it demonstrably are, and have been since May 15, when manipulation of generative AI responses became spam in writing, applying to every Search surface including AI Overviews and AI Mode. The August update is not the moment the risk was created. It is the second reminder in ten weeks that enforcement vehicles ship on a fast cadence now, and that the agencies holding bought mentions, engineered citations, and expired-domain redirect portfolios are carrying documented exposure into every client report.

The agencies that come through this cycle untouched will be the ones whose AI visibility work would survive the same audit their links would: if it only exists because an AI surface exists, it comes out. Everything else is still SEO, and still worth doing.

Primary sources
  1. Google August 2026 Spam Update Is Rolling Out, Search Engine Roundtable, Aug 18, 2026 (facts, exclusions, Mueller Q&A, rollout history).
  2. Google Begins Rolling Out The August 2026 Spam Update, Search Engine Journal, Aug 18, 2026 (dashboard timing, May 15 clarification, rollout durations).
  3. Google releases August 2026 spam update, Search Engine Land, Aug 18, 2026.
  4. Spam Policies for Google Web Search, Google Search Central (page dated May 15, 2026; manipulation clause quoted).
  5. Optimizing your website for generative AI features on Google Search, Google Search Central (inauthentic mentions, manipulation consequences, AEO/GEO guidance).
  6. Google Strongly Warns Against Manipulating Brand Mentions For AI Manipulation, Search Engine Roundtable, May 28, 2026 (Illyes, Search Central Live Sydney).
  7. Do people click on links in Google AI summaries?, Pew Research Center, Jul 22, 2025.
  8. Google August 2026 spam update: Is AI spam the target?, Launchcodex, Aug 18, 2026 (confirmed-vs-inferred analysis, Common Crawl data, Derick Do quote).
  9. Google Has Declared War on Bought AI Citations, Absolute Digital, Jun 16, 2026.
  10. Microsoft warns AI recommendations being “poisoned”, TechRadar Pro, Feb 13, 2026.
  11. Casualty reports: r/SEO threads Breaking: Google August 2026 Spam Update, Core Update August 2026, I got nuked by the google spam update, Aug 18–20, 2026.