Published July 5, 2026 | Version v1

Manufactured Authority in Generative Engine Optimization: Cross-Market Evidence and Two Operational Metrics (MAI and VLS)

Authors/Creators

Description

Generative Engine Optimization (GEO) is the practice of structuring content so that large language model (LLM) powered search systems retrieve, trust, and cite it. A defining empirical property of these systems is a systematic bias toward earned media, that is, third-party and apparently authoritative sources, over brand-owned and social content (Chen, Wang, Chen, & Koudas, 2025). This paper documents a paradox that follows from that property: the vertical that sells "become the source AI trusts" appears to manufacture precisely that trust about itself. Through an exploratory, observational, cross-market audit of the canonical "best GEO agency/expert" query in eight markets and languages, we identify three recurring mechanisms of manufactured authority: (M1) self-referential ranking, (M2) syndicated corroboration, and (M3) purchased-placement intermediation. To move the analysis from description to measurement, we introduce two operational metrics: the Manufactured Authority Index (MAI), the share of examined first-page sources exhibiting a manufacturing mechanism, and the Verification Layer Score (VLS), a five-criterion 0 to 10 index of a market's independent verification infrastructure. Scoring the eight markets, we find that manufactured authority is near-universal (MAI is consistently high) while the verification layer varies sharply (VLS ranges from 1 to 9). This yields a two-axis picture in which markets are separated not by whether authority is manufactured but by whether anything can independently correct it: in short, source diversity is not source independence. We connect M2 to the manufactured-third-party-agreement mechanism demonstrated experimentally in GEO poisoning research (Lasso Security, 2026; Zhang, Triedman, & Shmatikov, 2026), and we revisit and qualify an earlier claim, from the author's Integrated Visibility (AIVI) framework (Göktaş, 2026), that retrieval architectures intrinsically mitigate manipulation through multi-source corroboration. The study is exploratory and hypothesis-generating rather than confirmatory; its metrics are proposed as reusable instruments, and its limitations are discussed at length. To our knowledge, this is the first study to operationalize manufactured authority through reusable, cross-market metrics.

Files

manufactured-authority-geo-preprint.pdf

Files (370.3 kB)

Name Size Download all
md5:63d34c63efce94fc9fd4ca0e32934d80
370.3 kB Preview Download

Additional details

Dates

Issued
2026-07-05

References

  • Aggarwal, P., Murahari, V., Rajpurohit, T., Kalyan, A., Narasimhan, K. R., & Deshpande, A. (2024). GEO: Generative Engine Optimization. arXiv:2311.09735.
  • Chen, M., Wang, X., Chen, K., & Koudas, N. (2025). Generative Engine Optimization: How to Dominate AI Search. arXiv:2509.08919.
  • Fishkin, R., & O'Donnell, P. (2026). NEW research: AIs are highly inconsistent when recommending brands or products; marketers should take care when tracking AI visibility. SparkToro. https://sparktoro.com/blog/new-research-ais-are-highly-inconsistent-when-recommending-brands-or-products-marketers-should-take-care-when-tracking-ai-visibility/
  • Göktaş, İ. (2026). Generative Engine Optimization: Technical Foundations of Search Visibility in the AI Era and an Integrated Visibility Model (AIVI). Zenodo (preprint). DOI: 10.5281/zenodo.21180989.
  • Lasso Security. (2026, June 24). Exploiting GEO to push harmful claims into AI-generated answers (E. Saban). Lasso Security research blog. https://www.lasso.security/blog/exploiting-geo-to-push-harmful-claims-into-ai-generated-answers
  • OWASP. (2025). OWASP Top 10 for LLM Applications (2025): LLM09:2025 Misinformation. OWASP GenAI Security Project. https://genai.owasp.org
  • Zhang, T., Triedman, H., & Shmatikov, V. (2026). Deep-research agents can be poisoned via user-generated content. arXiv:2605.24245.
  • Zou, W., Geng, R., Wang, B., & Jia, J. (2025). PoisonedRAG: Knowledge corruption attacks to retrieval-augmented generation of large language models. In Proceedings of the 34th USENIX Security Symposium.