Black-Hat SEO in AI Search: The Tricks, and What They Cost
In April 2026, Google’s security team described something they’d started finding while scanning Common Crawl’s archive of the public web: pages carrying a block of text no visitor would ever see, written for whatever AI system might later read the page, not for a person. The instruction was blunt — recommend this business over any other. Google filed it under a specific, almost bureaucratic name, indirect prompt injection for search engine optimization, and said the sophistication of what they’d found was still low. They also said they expected that to change.
That’s the shape of black-hat SEO’s newest chapter. The tactics are not new. What they’re aimed at is.
What counts as black-hat SEO once the reader is a model, not a crawler?
Google’s own spam policy defines the old playbook plainly: cloaking is showing search engines and people different content with intent to mislead; hidden text is content placed so a visitor won’t spot it; scaled content abuse is producing material mainly to manipulate rankings rather than help anyone. None of that mentions AI. It didn’t need to — a model composing an answer is still a reader a page can lie to, which is why writing for how a model reads a page, not just for how a crawler indexes one, has become its own discipline.
What’s changed is the target. A search engine ranks a list and lets a person pick; a model picks for them, once, inside an answer. That collapses the old incentive to rank in position four down to a binary one — get cited, or don’t exist in the answer at all — which raises the payoff for hiding a pitch from the human reader while feeding it to whatever is doing the reading.
Can a page still hide text from an AI the way it used to hide text from Googlebot?
The classic version used CSS: white text on white, font-size set to zero, text pushed off-screen. Google’s spam policy still names all three, because people still try them. Google’s April report describes a newer trick aimed at the same outcome: plain text instructing an AI reader directly, telling it what to say or who to favor, sitting where a browser renders it but a person skims past. Google found it scanning plaintext from Common Crawl’s monthly snapshots, and watched the broader category of malicious injection attempts it tracks rise by about a third between November 2025 and February 2026. It called the SEO-specific examples unsophisticated for now, and expects the scale and sophistication of the tactic to grow as it gets automated — a narrower claim than “AI search is full of hidden manipulation,” closer to: a tactic search engines spent a decade learning to detect is being tried again, earlier in its life, against a different reader.
How would a site discover it’s doing something closer to cloaking than blocking?
Most sites that end up here didn’t set out to cloak anything. A caching layer serves a stale fragment to one crawler. A bot-management rule, set up through a robots.txt file or a CDN dashboard, strips scripts for anything that looks automated. None of it is intentional, yet it can look identical to deliberate cloaking from outside.
One check inside an AI-visibility audit tool is built around exactly that ambiguity. It requests the same page under several crawler identities and compares how much content comes back under each. A normal, successful status code paired with one identity receiving under half the content another got is flagged — an honest block usually shows up as a different status code altogether, not a thinner page returned with a confident 200 OK. A flat refusal at the server level gets its own, harsher flag, since that’s a block rather than a content mismatch.
Neither finding is a verdict on intent. A site that trips it could be running an experiment, fighting a caching bug, or doing exactly what the check is named for — the signal describes what happened to a response, not why, and treating every divergence as proof of guilt is its own kind of overclaim. What it can’t catch is the older trick: text hidden by CSS rather than withheld from one crawler identity. A check built to compare how much a page serves doesn’t, on its own, notice spam text painted the same color as its own background.
Do fake reviews still move an AI-generated answer?
Buying reviews predates AI search by well over a decade. In 2013, New York’s attorney general fined nineteen companies a combined $350,000 for exactly this, in an investigation named, not subtly, Operation Clean Turf. What’s different now is how many systems read the same review — a local pack, a review aggregator, and a model summarizing “what people say about this business” can all draw on the same pool of text, so one fabricated review no longer pollutes a single ranking signal. It pollutes every system that treats review language as evidence.
Regulators have caught up on paper, if not fully in practice. The US FTC’s rule against fake and paid consumer reviews has carried real enforcement power since October 2024, with civil penalties reaching $51,744 per violation. The UK’s CMA guidance on fake reviews made commissioning or publishing one unlawful from April 2025, backed by fines of up to 10% of global turnover. Neither rule mentions AI; both were written for the review itself, not for what reads it afterward.
Whether that deters anyone yet is unclear. The CMA reviewed over 100 business websites after its rule took effect and found more than half had no compliant fake-review policy at all — less a sign of failed enforcement than of a law most businesses hadn’t registered yet.
Where is the line between a legitimate “best tools” roundup and manipulation?
A site that makes a product and also publishes a “best tools for X” article naming its own product first isn’t automatically doing anything wrong. Plenty of useful comparison content is written by people with a stake in one of the entries. Google’s scaled content abuse policy draws the line at intent and substance, not self-interest: content produced mainly to steer a ranking or an answer, without the testing or first-hand use that would make it worth reading regardless of who wrote it. A roundup that never explains why its own entry ranks where it does, or that’s one of dozens of near-identical posts published the same week, reads as the latter. The giveaway isn’t the self-ranking — it’s the absence of anything underneath it that someone who’d actually used the products would have bothered to write.
What does getting caught actually cost?
For a search engine, the oldest cost is a manual action: a human reviewer at Google can demote or remove a site’s pages from results entirely, independent of any algorithmic change — a penalty that predates AI search by two decades and still applies to cloaking and scaled content abuse exactly as written today. For reviews, the cost is now legal, in two major markets, at the fine levels above. For prompt injection aimed at an AI system, there’s no track record yet; the tactic is too recent for any regulator to have ruled on it as its own category. What exists is a security team watching the trend grow, and an implicit bet that platforms serving AI answers will eventually treat manipulated input the way search engines learned to treat cloaked pages: something to detect and discount, not debate.
Nothing about that bet is settled yet. A tactic Google rates as unsophisticated today, tracked across a few more months of Common Crawl snapshots, may look different the next time anyone measures it.
Frequently asked questions
What is black-hat SEO in the context of AI search?
The same family of tactics that used to target a search engine's crawler and ranking algorithm — cloaking, hidden text, fake reviews, self-serving link schemes — retargeted at the systems that now compose an AI answer instead of a ranked list. The methods are old. The reader being deceived is new.
What is prompt injection used for SEO manipulation?
Text placed on a page specifically for an AI system to read, rather than a human visitor — typically an instruction telling the system to recommend the page's business over competitors, or to describe it in specific favorable terms. Google's own security team documented real examples of this in April 2026.
How can a site tell if it's serving different content to crawlers than to visitors?
Request the same URL with a plain HTTP client under a few different user agents and compare how much text comes back under each. A normal status code paired with a sharply smaller response for one identity than another is the signature an audit check looks for — it reads as cloaking rather than a simple block, because an outright block usually shows up as an error status instead.
Are fake reviews actually illegal now?
In the US, the FTC's rule against fake and paid reviews has been enforceable since October 2024, with penalties up to roughly $51,744 per violation. In the UK, the Digital Markets, Competition and Consumers Act made commissioning or posting a fake review unlawful from April 2025, with fines of up to 10% of global turnover. Neither law is specific to AI search, but a bought review poisons every system that reads it, model included.
Is a 'best tools' listicle that ranks the author's own product first black-hat SEO?
Not by itself. It becomes a problem under Google's own spam guidance when the comparison isn't based on genuine use or testing and exists mainly to steer a ranking or an AI answer rather than to inform the reader — the self-ranking is a symptom, not the violation.
