Can you really rig an LLM answer easily?
I have seen a few posts on here claiming the same thing about GEO, that LLMs are surprisingly easy to manipulate.
Publish a blog making the claim you want repeated. Stick a comment on Reddit. Ask the right question and, bingo, ChatGPT is telling the world what you wanted it to.
There is some research behind those claims. The problem is that the experiment and the conclusion people take from it are not always the same thing.
A recent 404 Media article covered Cornell research (which I unfortunately cannot read without thinking of Andy from The Office) into whether deep-research agents could be poisoned through user-generated content. The researchers found that a short passage added to an existing page on Reddit, Wikipedia or another user-generated platform could influence an AI-generated answer. In one example, a recommendation for a fictional Mexican restaurant was inserted into a Reddit thread and then appeared in answers about where to eat near Austin.
It is an interesting study and a genuine concern for the companies building these systems. It is also quite a long way from proving that a B2B company can write one self-serving blog and suddenly start appearing in every relevant vendor recommendation.
Reddit is important, but context matters
The Cornell research focused on questions where user-generated content is likely to be useful. Restaurants are an obvious example. People typically want first-hand experiences, from someone who has visited.
The same applies to plenty of consumer questions. Reddit contains the sort of informal answers an AI search tool may want to use.
If the same thread keeps being retrieved for related questions, somebody may be able to insert a convincing but fabricated recommendation into it. The Cornell researchers found substantial overlap in the user-generated pages retrieved by different deep-research systems. That repeated retrieval is what created the opportunity to manipulate the answer.
None of this is completely new. Long before ChatGPT, the Pacific Northwest tree octopus was used to show how easily people could be convinced by a professional-looking website about a completely fictional animal. The difference now is that an LLM can find, summarise and repeat unreliable information on the user’s behalf.
For B2B marketing teams, the important question is how closely these experiments resemble the searches their buyers are making.
A procurement lead looking for software vendors may be validating companies they already know, or asking for credible wildcard options to add to an RFP. Both are genuine opportunities to appear in an AI answer, but the system has, or at least should have, a very different pool of sources to consider.
A lone claim on Reddit is less likely to settle the matter when there is trade-media coverage, analyst commentary, customer evidence and years of competitor material available.
The experiment can make the trick look easier
There is another issue with some GEO research and demonstrations: the content has already been given a major head start.
The Cornell researchers did not publish a new page and hope an AI tool would find it. They identified existing user-generated pages that were already being retrieved for related questions, then simulated adding the poisoned content to those pages.
That makes sense for an ethical security study. But it is not the same challenge a brand faces when publishing new content on the live web.
“Simulated” is important here too. Reddit is trying to crack down on spammy or manipulative posts and comments, so there is no guarantee the fake Mexican restaurant recommendation would have been allowed to remain in the thread, let alone become prominent enough to influence an answer.
The original academic paper that coined GEO also showed that changing a source could improve its visibility in generated answers. But the source was already part of the documents supplied to the system. It showed that content can become more influential once it is in contention, not how reliably a new page will be discovered in the first place.
A recent critical review of 45 GEO studies makes much the same point. There is decent evidence that already-retrieved content can affect an answer. There is much less evidence of techniques producing stable, long-term visibility across different platforms and real-world searches.
I have also seen people claiming they have exposed how "flawed" LLMs are by appearing as the answer for an incredibly niche term, that nobody has ever searched for, or is ever likely to search for.
Say a private network vendor publishes the only article answering: “What is the best private network platform for vineyards in Surrey run by a nice couple called Alan and Maureen?” It then asks an AI tool which supplier Alan and Maureen should use, and appears in the answer.
Has it influenced the model? Almost definitely.
Has it proved that LLMs are easy to influence and rank in? Not really.
A result recreated with one carefully chosen prompt is not necessarily evidence of meaningful market visibility.
What should brands take from this?
Brands should not panic that a competitor can overturn their reputation with one blog post or a few Reddit comments.
They should be equally cautious about the idea that they can use the same tactics to leap into commercially valuable answers with very little effort.
GEO matters because buyers are using AI tools to research markets, validate suppliers and discover companies they may not already know. The sensible response is to understand what those tools currently say, which sources shape the answers and where the gaps are.
Owned content clearly has a role. But so does the wider evidence around the business. If an AI tool finds a clear company story supported by credible third parties and borne out across the market, it has much more reason to trust the answer it is building.
That is how we are approaching GEO at Temono. Not as a quick way to make an LLM repeat a convenient claim, but as part of the wider job of making sure a business is understood properly when a buyer asks a question that matters.