Getting fabricated content into AI-search citations now costs less than a single coffee, and most of the time it takes less than a week. On October 8, a multi-institution research team posted “From Public Posts to AI-Search Citations: Measuring the Fragility of AI Search” to arXiv. The study’s central result: ordinary posts on sites the AI-search products already prefer moved into cited answers within days, and a $14 spend on a so-called GEO service produced posts that one platform quoted within an hour. The base-rate question is whether today’s AI-search products hallucinate on most foundation-model comparisons - they do - and the new paper documents what happens when that noise becomes steerable.
GEO stands for “generative engine optimization.” The paper frames it as the AI-era cousin of search-engine optimization: pick a site, rewrite the content, post across many venues so an AI answer treats your post as authoritative. The researchers argue this is a structural gap rather than a bug. AI-search providers do not usually control publication platforms, so citations get chosen before anyone filters for credibility, and the gap is now cheap enough and fast enough to exploit at scale.
How the measurement was done
The study team mapped citations across 10 named AI-search products: Perplexity, ChatGPT Search, Google AI, Doubao, Kimi, Grok, Wenxin, Yuanbao, DeepSeek, and Qwen. They analyzed 17,211 citation instances spanning 6,356 unique source domains, then ran controlled publication experiments on sites each platform cited most often.
The headline RQ2 finding, from the abstract, is the most striking number in the paper: “8 of 10 platforms cited a fabricated concept within seven days.” On how narrow each product’s citation diet can be, the abstract reports “top-20 domains capturing 20.5—70.8% of per-platform citations,” meaning a fifth to more than two-thirds of all citations on a platform can come from just 20 sites. The third leg of the study tested the commercial supply chain. From the abstract: “a $14 GEO purchase produced 13 public posts, and one AI-search platform cited GEO-posted content with our designed markers within one hour.”
The authors describe their work as a security paper, not an SEO one. They argue the problem is not a hack of any one model but a misplaced-control problem between two layers: the search provider picks which sources to cite, and the publication platform decides who can publish. Neither layer, on its own, can stop a coordinated supplier.
What the paper does not claim
The team is explicit about scope. They note that the exact rates come from one March-April 2026 campaign and may drift, and that RQ2 “cannot give a general conversion rule, such as how many low-preference posts equal one high-preference post.” Their explicitly excluded topics are “Health and medical advice,” “Financial and investment guidance,” “Political and electoral content,” “Public safety and emergency information,” and “Content targeting vulnerable populations.” They deleted every controlled-publication post under accounts they controlled within four weeks and disclosed that some RQ2 articles were drafted with AI assistance.
GEO pricing they observed in the wild ranged from about $280 per year to $1,130 per month for Chinese services, and $29 to $2,500 per month for English-language services. That is the price floor for placement in the era of generated answers, and it is several orders of magnitude below the cost of a legitimate media buy.
Where this fits: the citation problem is not new
A March 2025 measurement by the Tow Center for Digital Journalism at Columbia tested eight AI-search products on 1,600 queries drawn from 20 news publishers. Per Klaudia Jazwinska and Aisvarya Chandrasekar, the research found “chatbots provided incorrect answers to more than 60% of queries,” with Perplexity at 37% incorrect and Grok 3 at 94%. That study measured the noise; the new arXiv work measures whether the noise can be steered.
In other words, two years ago the worry was that AI search made a lot of citation errors by accident. The new paper asks what happens when someone tries to make the same product wrong on purpose, with a small budget and ordinary web tools.
What This Means
For anyone using an AI-search product to look up a policy, a study, or a person, the practical move is the same one recommended after the 2025 Tow Center study: treat the citation as a lead and click through. Look at the actual domain, confirm the claim exists at the cited source, and treat the AI’s summary as a routing hint, not a verdict.
For anyone whose livelihood depends on what AI assistants say about them, the implications are starker. The selection layer is narrow and the placement supply chain is cheap and fast. The mitigation advice from the paper’s authors is for the search providers, not end users: tighten publication-barrier testing on cited domains, broaden the citation pool past the top 20, and treat low-barrier sources as a “Citation-Governance Gap” rather than a neutral feature. None of those changes ship with a user-side toggle.
The borderline between a noisy search engine and a writable surface is now crossed. The new study is the first clean evidence the gap is large enough to exploit at scale on most major AI search products, not just an isolated product.
The Bottom Line
A new arXiv measurement finds that 8 of 10 tested AI-search products can be steered into citing fabricated or commercially placed content within a week, and one of them within an hour for $14. The 2025 Tow Center study showed the noise; this one shows who can buy it.