1. The article details Generative Engine Optimization (GEO), the practice of manipulating online content to influence AI model citations, effectively the search engine optimization for the AI era. [para. 1][para. 4] A demonstration by China Central Television showed an industry insider fabricating a fitness-tracking wristband with impossible tech specs in a lab setting. [para. 2] Using special software, he generated over ten fake articles about the product, causing two AI models to rank it highly within days. [para. 2][para. 3] While GEO has a benign form, the broadcast highlighted its deep vulnerability to abuse, which in China is known as "poisoning"—flooding the internet with false information to manufacture consensus. [para. 4][para. 5]
2. The risk posed by GEO abuse is growing sharply as reliance on AI models for information increases. [para. 6] Market research firm Gartner projects a 25% decline in traditional search traffic this year. [para. 6] Simultaneously, Global Info Research forecasts the GEO market will grow at a compound annual rate of 33%, reaching a value of $7.3 billion by 2031. [para. 6] This rapid shift creates fertile ground for abuse, particularly in financial markets, where it threatens to corrupt the data driving investor decisions as they move from reading filings to querying chatbots. [para. 6][para. 7]
3. In financial markets, GEO abuse has evolved far beyond fake reviews. [para. 9] A leading GEO executive stated that listed companies, their PR firms, and vendors now meet before earnings releases to shape the information AI returns to investors. [para. 9] The vendors systematically map current AI responses to likely investor queries, craft engineered content to push a preferred narrative, and seed it across platforms where AI harvests data. [para. 10] They guarantee that 80% to 90% of investors who query AI about a company's earnings will see the tailored version. [para. 11] These services cost roughly 50,000 yuan per quarter or 20,000 to 30,000 yuan monthly. [para. 12] The tools are deployed both defensively, to suppress negative coverage, and offensively, to plant damaging information about competitors. [para. 13]
4. AI models are vulnerable to these tactics due to how they are built. [para. 15] Many mainstream models use retrieval-augmented generation (RAG), where they search the web for relevant content and generate answers based on what they find, trusting the results without verifying authenticity. [para. 15][para. 16] According to cybersecurity professor Li Chaozhuo, the model has no reliable way to tell if a source is genuine or if apparent agreement across sites reflects a real consensus. [para. 16] Thus, flooding platforms with the same claim through different accounts can make an AI model deem it established fact. [para. 17] Research from Anthropic confirms the alarming scale of this risk, finding that just 250 malicious documents are enough to skew a large language model’s outputs. [para. 18]
5. China's legal framework lags behind this technology. [para. 20] Professor Zhao Binghao notes that advertising and competition laws were designed for traditional media and do not clearly address AI-generated content, leaving the definition of GEO abuse, liability, and penalties unsettled. [para. 21][para. 22] He recommends faster legislation, higher penalties, and shared responsibility among parties. [para. 22] Some platforms have begun to act independently: Tencent's Yuanbao model features multilayered filtering, while Alibaba's Qwen has an experimental fact-checking feature. [para. 23] However, Anthropic's research suggests that platform-level filtering alone is unlikely to be sufficient, as even a tiny volume of malicious content can distort a model's outputs. [para. 23][para. 24]
6. Experts propose both systemic and practical defenses against GEO abuse. [para. 25] Anthropic argues that the most durable fix is to train models to intrinsically evaluate the trustworthiness of sources, internalizing why some sources deserve more weight. [para. 25] For investors, the most accessible immediate defense remains skepticism. [para. 26] Professor I Lo-fen recommends cross-checking answers across multiple AI tools and demanding that models cite their sources, treating any AI summary of financials as a starting point for investigation rather than a definitive conclusion. [para. 26]
AI generated, for reference only