DB

BLOG

Google's Spam Rules Now Officially Cover AI Overviews

·7 min read·
aeoseoai-search-visibility
Share
Add The Digital Back Office as a preferred source on Google

Surfaces our work more for you across Google Search and AI answers.

Quick read: Google finished rolling out its August 2026 spam update on August 21 — a global, all-languages enforcement pass that started August 18, its third spam update of 2026 after March and June. Google announced no new spam policy categories with this round; it enforced its existing rules. Separately, on May 15, 2026, Google updated its Search Central spam policy documentation to explicitly state that spam includes "attempting to manipulate generative AI responses in Google Search," not just traditional rankings (Google Search Central). In practice, that means tactics already banned for ranking manipulation — mass-producing low-value pages, buying or altering citations, cloaking — now carry the same risk when the target is an AI Overview or AI Mode answer instead of a blue link (Search Engine Land).

A business owner asked me last week whether the "AI writes it, you just approve it" blog package her old marketing contractor keeps pitching — fifty posts a month, no human required — was going to get her in trouble. A year ago I'd have hedged. This month, Google actually answered that question, and the answer is: it depends what "it" is doing, and now that includes what it's doing to your AI Overview citations, not just your Google ranking.

What actually happened

Google ran its third spam update of 2026 in August — a global, all-languages rollout that started August 18 and finished August 21, a little under three days end to end. It followed the same pattern as March's and June's: no new spam policy announced, no blog post explaining new rules, just Google's existing automated systems taking another pass at enforcing the rules already on the books. If your site got hit and you're waiting for a named change to explain why, there isn't one — the rules didn't move, the enforcement did.

That part, on its own, isn't especially newsworthy for a small business. Spam updates target the kind of manipulation most legitimate sites were never doing in the first place — expired domains bought and repopulated with junk to inherit their old authority, content scraped or mass-produced purely to fill a ranking slot, hidden text and sneaky redirects. If none of that describes your site, a spam update is usually background noise.

The part that actually matters here

The more useful news happened a few months earlier and got quietly folded into this update's coverage: back on May 15, Google edited its own spam policy documentation to spell out, for the first time, that manipulating generative AI responses counts the same as manipulating traditional rankings. The policy line used to describe spam only in terms of "featuring content prominently" in ranked results. It now explicitly names attempts to manipulate generative AI responses in Google Search as the same offense.

That's not a new rule so much as an old rule getting a second address. The tactics were always against the rules when the target was ranking position. Google just confirmed, in writing, that the same rules apply when the target is showing up inside an AI Overview or an AI Mode answer instead. Buying citations, coordinating networks of pages to force a specific source into an AI-generated summary, or structuring content purely to trigger inclusion in a summary rather than to actually answer anyone's question — all of that now sits squarely inside the same spam policy that's been enforced against ranking manipulation for years.

If you've been reading anything here about Answer Engine Optimization (AEO) — the practice of getting a website cited inside AI-generated answers instead of just ranked on a page of links — this is the enforcement half of that same story. Getting cited was never supposed to be a separate, looser game than getting ranked. Google just made that official.

The mechanics: what actually counts as manipulation

The category most likely to touch an actual small business is what Google calls scaled content abuse — producing a large volume of pages primarily to manipulate rankings or citations, regardless of whether a person, a scraper, or an AI model wrote the words. The method doesn't matter to the policy. Intent and value do: pages made to occupy space rather than to answer something a real customer would ask are the target, whether they were written by a $12-an-hour freelancer or a chatbot.

That's the practical reason to be careful about any pitch built around volume — "we'll publish fifty AI-written posts a month" is a pitch about quantity, not about whether any of those fifty posts says something a customer actually needed to know. A handful of pages that genuinely answer real questions structured the way AI systems can extract and cite will outperform a flood of filler every time, and now the flood carries an actual policy risk on top of just being a waste of money.

A few concrete things worth checking on your own site:

  • Is anything on the site generated purely to exist, rather than to answer something? A page with no real answer buried inside marketing language is the pattern this policy targets, written by a human or not.
  • Are you paying anyone for "AI citation placement" or guaranteed mentions? Buying or engineering citations is explicitly named as manipulation now. A legitimate AEO practice earns citations by being accurate and well-structured, not by paying for placement inside an answer.
  • Does your content still read as current and specific? Thin, outdated, or vague pages are exactly the kind of low-value content this policy is aimed at, separate from whether anyone technically "manipulated" anything.

What won't help

Assuming this only applies to obvious spam farms. The policy language is about intent and value, not about being a giant operation. A small site that leans hard on AI-generated volume without editorial judgment fits the same description a spam farm does, at a smaller scale.

Panicking over a traffic dip that predates this update. A spam update targets specific manipulative patterns. If your traffic slid for unrelated reasons — and Google changes rankings quietly and constantly, separate from any named update — blaming this specific rollout without checking the timeline just delays finding the real cause.

Reading "no new policy" as "nothing changed." The rules didn't change in August. What changed is that Google now explicitly says those same rules cover AI answers, which matters if any part of your content strategy was built assuming AI citations were a looser, less policed space than regular rankings.

Overcorrecting by publishing less. The fix isn't fewer pages — it's pages that earn their spot. A site that already answers real questions plainly has nothing new to worry about here.

FAQ

What did Google's August 2026 spam update actually change?

Nothing in the rules themselves. It was an enforcement pass — Google's automated systems checking sites against spam policies that already existed, with no new policy categories announced alongside it. It ran globally, in every language, from August 18 to August 21.

Does Google's spam policy really apply to AI Overviews now?

Yes, explicitly. Google updated its own spam policy documentation on May 15, 2026, to state that spam includes attempts to manipulate generative AI responses in Search, not only attempts to manipulate traditional ranked results. The underlying rules — no manipulation, no low-value content built purely to occupy space — were already there; the AI-answer context is now named directly.

What is "scaled content abuse," and does it apply to AI-written content?

It's Google's term for producing a large volume of pages primarily to manipulate rankings or citations rather than to inform anyone. It applies regardless of who or what wrote the content — a human, a scraper, or an AI model. What matters is whether the content exists to manipulate a system or to actually answer a question.

Is it against the rules to use AI to write website content?

No. Google has said repeatedly that AI-assisted content isn't automatically a problem. The issue is volume-for-its-own-sake and low value, not the tool used to produce it. A well-researched, specific, accurate page written with AI assistance and real editorial judgment isn't the target of this policy.

Could my small business site actually get flagged by something like this?

Unlikely, if your content answers real questions and you're not paying anyone for guaranteed AI citations or running a high-volume, low-effort publishing schedule. Most small business sites don't remotely resemble the pattern this policy targets. The risk is higher if you've outsourced content to a service selling volume as the main pitch.

Check the timing against August 18–21 first. If the drop predates that window, or your site doesn't match any of the manipulative patterns above, this update probably isn't the cause — Google changes rankings quietly on its own schedule too, which is a far more common explanation for an unexplained slide.

What should I actually do about this as a small business owner?

Mostly nothing new — keep publishing content that answers real questions, skip anyone selling guaranteed AI citation placement, and be skeptical of any pitch built around content volume rather than content quality. If you're not sure whether your current content strategy fits the pattern this policy targets, that's a fair thing to have someone actually look at.


None of this changes the underlying advice: build pages that answer real questions, skip the shortcuts, and let the citations follow. That's the ongoing work behind getting found on Google and AI — not chasing every update, just staying on the right side of what the rules have quietly always meant.

Want a back office for your site?

Builds and Care are by application — scoped and quoted after a short audit, against the actual work, not tiers.

Apply for a build slot →