Friday, September 18, 2026 Five things that moved Read time: 8 min

Today’s theme · What can still be checked

REI never appeared in 240 AI recommendation lists. Being established is not enough.

Three studies published this week took AI recommendations apart to see what decides who gets named and whether the source links underneath hold up. In the same week, Google began blocking the tools that measure search results.

Three studies landed this week, all of them doing the same unfashionable thing. They took what AI assistants say and checked it against something that exists outside the machine.

The first asked who gets recommended and found that being big and well regarded is not what does it. The second and third asked whether the little source links under an answer mean what a reader assumes they mean, and both found that they often do not.

Then, in the same week, Google got much better at blocking the tools that measure search results. So the week that produced the best evidence yet about how AI answers are assembled is also the week the measuring got harder.

One item has something you can do today, and it takes about ten minutes.


01 The evidence

REI got zero recommendations across 240 AI answers

Being the oldest and best known business in your market is not what gets an AI to name you.

The study asked six assistants the same question forty times each and counted how often each brand came back.

Edward Malthouse and four colleagues published a study on September 14 that asked six AI assistants to recommend brands in five ordinary categories. Each question was asked forty times in a fresh session, producing 1,200 separate recommendation lists. The brands they checked against were chosen before any question was asked, so the assistants could not decide for themselves which ones counted.

Household names came back with nothing. REI Co-op, L.L.Bean and Eddie Bauer were never recommended once in hiking jackets, a category that accounts for 240 of those lists. Craftsman and Black+Decker got zero in cordless drills, and Braun and Philips got zero in coffee makers.

What did predict being named was not size or age. The strongest single predictor was how often people searched for the brand by name, followed by how much it was discussed online. The authors are careful about this and state plainly that the association does not prove one causes the other.

One finding matters for anyone who has ever run a single test. Asking the same question again returned different brands in a different order, which is why the researchers asked forty times rather than once. For an accounting firm or a luxury home builder, a one off check of whether an assistant names you is not a measurement of anything.

There is a usable half to this. Brands missing from the plain question reappeared when the question included a specific need, such as a budget or a use case. Being absent from the broad answer does not mean an assistant has never heard of you.

What to do about it

Pick the question a customer would actually type to find a business like yours, and ask it ten times in fresh sessions rather than once. Write down which names come back each time. The list that repeats is the one worth acting on, and a single run tells you very little.

Source arXiv, Edward Malthouse, Kun-Yu Lee, Jing Yang, Sanchary Pal and Xueyan Feng, “Evaluating Brand Retrieval and Ranking in Large Language Model Recommendations,” September 14, 2026 · arxiv.org

02 The evidence

One planted page made AI cite an innocent source

Someone else’s web page can put a false claim into an AI answer with a trusted name attached to it.

The attacker in this experiment controlled a single page and never had to write an instruction into it.

A paper published on September 14 by Guo Fuzheng tested something the security literature had left alone. Earlier work asked whether an attacker could make an AI give a wrong answer. This one asked whether an attacker could also choose which source gets the credit for it.

The setup is modest, which is the uncomfortable part. The attacker controls one web page among the several the AI retrieves. The rate of wrong answers went from 1% to 68%, and the AI attributed those answers to a different, trusted source that had said no such thing.

The correct information was still sitting in front of the model the entire time. It had the right source available and pointed at the wrong one anyway. On the model most inclined to cite, this happened 64% of the time with no instruction planted in the page at all, and 84% when the page was written to push for it.

For a specialty veterinary hospital or an accounting practice, the practical shape is this. A false claim about your area of work can appear in an AI answer carrying the name of a source your customer trusts, and the answer will look properly sourced. The author tested two obvious defenses, checking whether the text looks unusual and checking whether the citation supports the claim, and found each of them insufficient on its own.

What to do about it

Ask the assistant your customers use a plain question about your area of work, then open the sources it cites and check that the cited page actually contains the claim. If it does not, you want to know that before a customer does.

Source arXiv, Guo Fuzheng, “CiteShade: Citation Laundering in Multi-Source Retrieval-Augmented Generation and Its Counterfactual Defense,” September 14, 2026 · arxiv.org

03 The evidence

A September audit found 88% of cited claims unsupported

An AI citing your website does not mean the answer it gave reflects what your website actually says.

The test compared what an AI said against the real text of the page it pointed at.

Before an AI answers, it usually shrinks the pages it has retrieved into something smaller. A paper published on September 13 by Deepanshu Mody measured what that shrinking does to the source links that come out the other end.

Checked against the AI’s own compressed summary, the citations looked accurate, scoring 0.86 out of 1. Checked against the actual text of the source page, the same citations scored 0.12.

The claim level figure is starker. Verified against the recovered source text, 88% of claims were unsupported. Checked against the summary instead, the figure was 17%.

Same answer, same citation, and two very different verdicts depending on which one you check against.

This is an early result and the author says so repeatedly. The audit covered 200 questions and leaned on an automated judge with no human calibration, a limit the paper states in its own abstract rather than tucking into a footnote. A paper that names what it cannot yet prove is worth more than a confident number.

For an architecture and engineering practice, the consequence is concrete. An AI can cite your project page and still describe your work in a way that page does not support, and the citation gives a reader every reason to believe it.

What to do about it

Search your own business in an AI assistant and read what it says about your services. Then open the page it cites, which is often your own, and check whether that sentence is really there. A description you never wrote is one you can correct.

Source arXiv, Deepanshu Mody, “The Attribution-Compression Frontier in Retrieval-Augmented Generation,” September 13, 2026 · arxiv.org

04 The platform change

Google blocked the tools that track search results

The ranking report your agency sends you is being built from far less data than it was last month.

Two tracking companies reported losing most of their data within days of the change.

Since around September 13, Google has become markedly better at blocking the automated tools that read its search results. Barry Schwartz reported it on September 18, drawing on the people who run those tools.

Derek Perkins of Nozzle reported roughly an 80% drop in the data his company could successfully collect from Google Search. Sistrix said its own data collection was running at a reduced rate as of September 16, and Steve Paine there noted that Google has been changing how results are delivered at a very high pace.

The effects are uneven, and that is the part that matters. Glenn Gabe documented three major tools disagreeing with one another: Ahrefs kept collecting, Semrush lagged, and Sistrix fell behind on spotting ranking recoveries. Two reports on the same business in the same week can now differ because of which tool was blocked, not because anything about the business changed.

Measuring where a business stands in search and in AI answers is what this industry sells, Forever Cited included. When the instrument gets worse, saying so is the only honest option, and any number quoted this month should come with the name of the tool that produced it.

Microsoft’s Bing was spotted doing something related on September 18, asking people to confirm they are human before showing results. Schwartz noted he could not reproduce that one, which is the right thing to say about a change you have seen only in someone else’s screenshot.

What to do about it

If you receive a monthly ranking or visibility report, ask which tool produced the numbers and whether its collection was affected this month. A drop that shows up in one tool and not another is a reporting artifact, not a change in your business.

Source Search Engine Roundtable, Barry Schwartz, “Google May Be More Successful In Blocking Scrapers & Tracking Tools,” September 18, 2026 · seroundtable.com

05 The money

Google Ads now shows what businesses like yours spend

The company selling you the advertising is now telling you that your competitors spend more than you do.

The comparison sits in the account overview, right beside your own weekly spend.

Google Ads has rolled out a Spend Benchmarks report that compares an advertiser’s weekly spending against businesses it considers similar. Thomas Eccel spotted it and Search Engine Roundtable reported it on September 16.

The report shows whether an account is spending more, less or about the same as its peer group, with click counts alongside. In the example shared, one account spent 284 euros in a week against a peer average of 268, and drew 912 clicks against a peer figure of 765.

Google says the peer grouping is based on industry and on where the advertiser runs ads. Neither of those is margin, and neither is what one new customer is actually worth once they arrive.

Eccel’s own caution is the useful part of this. Two businesses in the same industry can have completely different margins, conversion rates and order values, so the figure that should set a budget is profitability, not a comparison supplied by the company selling the advertising. An admissions consultant and a private charter operator can land in the same bracket and have almost nothing in common commercially.

What to do about it

If this appears in your account, read it as information about how Google groups you and nothing more. Before moving a budget because of it, work out what one new customer is worth to you. That is the number that decides the spend.

Source Search Engine Roundtable, Barry Schwartz, “Google Ads Spend Benchmarks Report Compares Your Spend To Business Like Yours,” September 16, 2026 · seroundtable.com

If you do one thing this week

Ask an AI assistant the question a customer would type to find a business like yours. Ask it ten times in fresh sessions, and write down which names come back every time.

Then open one source the assistant cited and check that the sentence it credited is really on that page. Both of this week’s citation studies say it often is not.

The pattern across all five items is that the answer and the evidence under it have come apart, while the tools that used to check the gap are seeing less than they did. What you can verify yourself has become the reliable part.

Read the full archive →

Forever Cited · AI Visibility, Engineered by Industry · One brand per market.
Sources are linked in full above. We link to primary documents and original research wherever they exist.

The daily brief

Get this briefing every morning — free.

Five sourced items on AI search and visibility, written for business owners. No pitch, no spam. Confirm by email (double opt-in); unsubscribe anytime.

← All AI Industry Updates  ·  forevercited.ai