Claude's New Policy Names the GEO Tactic Google Already Calls Spam

Claude's New Policy Names the GEO Tactic Google Already Calls Spam
Anthropic's September threat report traced about 70 "local news" sites to a single ad agency. Its new Usage Policy names the tactic outright.

Anthropic's updated Usage Policy, published October 8, 2026 and effective November 12, bans using Claude to "manipulate the sources from which search engines or AI systems draw answers" with content that misrepresents its origin, authorship, or independence. Google's spam policy already calls manipulating AI responses spam. Any GEO tactic that depends on looking independent when it isn't now breaks two written rules.

The headline version of this story is "Claude will now ignore fake sources." That's not quite what happened, and the difference matters if you're deciding what to do with your AI visibility budget this quarter.

What the policy actually says (and what it doesn't)

The new language sits in a consolidated section on deceptive campaigns and artificial activity. The full clause prohibits seeding answer sources "with content that misrepresents its origin, authorship, or independence (e.g., networks of sites posing as unaffiliated sources corroborating the same claims)." The same section also bans fake personas, fake media outlets, fake reviews, sockpuppets, and astroturfing tooling.

So this is a rule about what people can use Claude to build. It doesn't say anything about how Claude ranks or weights the sources it reads when it answers a question. Search Engine Journal's coverage frames it as rules that target fake sources built to sway AI answers, which is accurate, but a lot of the LinkedIn chatter I've seen since Thursday has jumped straight to "Claude now penalizes listicles." Nothing in the text supports that. Not yet, anyway.

Anthropic's announcement post describes the whole update as a response to "new patterns of misuse" it has seen in threat intelligence work. Which is a polite way of saying someone already did this at scale.

The case that probably wrote this clause

You don't have to guess which case. Anthropic's September 2026 threat intelligence report documented a network of roughly 70 websites dressed up as independent local news outlets, all traced back to one ad agency based in France. According to ActuIA's breakdown of the report, the operation also ran about 70 matching X accounts and more than 250 fake comment accounts, and pushed out at least 8,913 articles in around 20 languages.

Most of those articles got almost no human readers. That was never the point. The volume existed to build authority signals for search engines, and by extension for the AI systems that lean on search results.

That's the uncomfortable part for marketers. Strip away the political clients and what's left looks a lot like a supercharged version of something GEO vendors pitch openly: get your brand mentioned across enough "third-party" pages that the model treats the claim as consensus.

Google got here first, five months ago

Google updated its spam policies on May 15, 2026 so the definition of spam now includes "attempting to manipulate generative AI responses in Google Search." The June 2026 spam update then rolled that into enforcement. SEO Sherpa called it closing "the AI search loophole that gurus have been selling for two years", which is a little dramatic but not wrong.

Enforcement is a separate question. Cornell Tech researchers, as reported by Search Engine Journal, found a single planted comment of about 13 words got a chosen entity into finished AI research reports in 38% to 51% of sessions. Spreading the same text across multiple pages pushed that to 42% to 62%. None of the three defenses they tested stopped it without making the answers worse for users.

Read those two facts together. The tactic works, the platforms know it works, and the detection side is behind. From what I've seen, that's exactly the window where a policy gets written down first and enforced unevenly later, and the people who get caught are the ones who were loudest about it.

This isn't new territory for NMS readers, honestly. We covered how 31 companies turned "Ask AI" buttons into recommendation poisoning a few weeks back. The Anthropic clause is the same problem seen from the toolmaker's side.

The disclosure line most GEO playbooks cross

I'd push back on the panic a bit, though. The policy doesn't ban listicles. It doesn't ban a brand publishing "best project management tools" on its own blog with itself at number one. Everyone can see who wrote that page. The origin isn't misrepresented.

What it targets is the gap between who made the content and who it claims to come from. A few common placements fall on the wrong side of that line pretty clearly:

  • Paid "independent review" pages on sites that don't disclose the payment
  • Satellite blogs or microsites your agency runs that never name your brand as owner
  • Seeded Reddit and Quora answers written by staff or contractors posing as users
  • Press-release syndication networks dressed as local news

Other stuff is murkier. Sponsored comparisons with a small "partner" tag at the bottom? Affiliate roundups where the ranking tracks commission rate? I don't think anyone, including Anthropic, has a crisp answer there yet. My rough test: if a reasonable reader found out who paid for the page, would they feel misled about whether it was independent? If yes, treat it as a liability.

On paper, Anthropic only polices its own users. In practice, policy language like this tends to leak into how models get trained and evaluated, and Google is already enforcing the equivalent. I'd rather not bet a budget line on that leak never happening.

A placement audit you can run in an afternoon

You don't need a tool for the first pass. You need a spreadsheet and about three hours.

  1. Pull your AI citation list. Run your 20 highest-intent category prompts ("best X for Y") through ChatGPT, Claude, Gemini, and Perplexity. Log every third-party URL cited when your brand comes up. If you already pay for a GEO tracker, export from there, though keep in mind most trackers only see part of the retrieval pipeline.
  2. Tag each URL by relationship. Organic (you had no hand in it), disclosed paid, undisclosed paid, or owned-but-unbranded. Be honest about that last column.
  3. Calculate your exposure ratio. Undisclosed paid plus owned-but-unbranded, divided by total cited URLs. As a rough benchmark, I'd want that under 20%. If more than a third of your AI mentions trace back to placements that hide their origin, your visibility is sitting on the exact pattern both Google and Anthropic just named.
  4. Fix the cheap ones first. Adding a clear sponsorship disclosure or an ownership line to a microsite costs almost nothing and moves a URL out of the risky column.
  5. Reallocate the rest. Shift spend toward placements that survive the disclosure test: original research others cite, real customer reviews on platforms with verification, and earned coverage.

Also, ask your GEO agency directly how many of their placements would pass that test. Their answer, and how fast they give it, will tell you a lot.

Where I think this goes next

My prediction: by the end of Q2 2027, at least two of the big four AI assistants will publish guidance on how they treat undisclosed paid placements as sources, and GEO agencies will quietly drop "third-party seeding" from their service pages. Maybe I'm early on that. Platform policy tends to move slower than the threat reports suggest it should.

One odd detail in the same update, which SEJ spotted comparing the old and new text: Anthropic dropped automated publishing from its list of high-risk use cases. So using AI to publish at scale is fine. Pretending to be someone else while you do it is the problem. That feels like the right line, honestly, and it's probably the one marketers should have been drawing for themselves all along.