Skip to content
Back to Blog
Insights

What Changed in GEO in 2026: Google, Cloudflare and AI Visibility Reporting

By Bernard Leong

Co-Founder, Geo One

25 August 2026
What Changed in GEO in 2026: Google, Cloudflare and AI Visibility Reporting

What Changed in GEO in 2026: Google, Cloudflare and AI Visibility Reporting

By Geo One · Last reviewed: 24 August 2026

Short answer: The main GEO changes in 2026 were Google’s clearer guidance for generative Search, explicit spam-policy coverage for AI-response manipulation, more granular AI crawler controls and Google-specific generative visibility reporting. Together, they make GEO easier to audit—but they do not create guaranteed AI rankings.

Generative engine optimisation (GEO) is the process of improving the structured, verifiable signals that AI assistants use to understand and potentially cite a business. Answer engine optimisation (AEO) focuses more narrowly on making information usable in direct answers.

For Malaysian SMEs, the practical response is a disciplined workflow: check technical access, preserve SEO foundations, measure assistants separately and document what the data can and cannot prove.

1. Google clarified that generative Search still depends on SEO foundations

Google’s 2026 guide to generative AI features in Search says:

  • established SEO practices remain relevant because Google’s generative features use its core Search ranking and quality systems;
  • there is no special structured-data markup required for generative Search;
  • llms.txt does not improve visibility or rankings in Google Search; and
  • pursuing inauthentic mentions is not a sound visibility strategy.

This does not mean every high-ranking page will receive an AI citation. Nor does Google’s guidance explain how ChatGPT, Claude or Perplexity selects sources. It means crawlable pages, reliable information and sound SEO remain the starting point for Google’s AI experiences.

For a Kuala Lumpur practice, that work may include reconciling registered and trading names, correcting obsolete branch listings, publishing service information as accessible text and identifying practitioner credentials accurately. A schema change cannot compensate for conflicting facts across a website, Google Business Profile and authoritative records.

Action: Audit crawling, indexing, entity consistency and service-page quality before producing content specifically for AI assistants.

2. AI-response manipulation now sits inside Google’s spam framework

Google’s spam policies expressly cover attempts to manipulate generative AI responses in Search. They define scaled content abuse as producing many low-value pages primarily to manipulate rankings. The same documentation identifies link spam examples such as buying links for ranking purposes, automated link creation and low-quality directory links.

Google began rolling out its August 2026 spam update on August 18. The official Google Search Status Dashboard records that the global rollout ended on August 21. Google announced no new spam-policy category with the update; Search Engine Journal’s updated coverage reports that existing policies remained the reference point and that Google had not said whether the update specifically targeted AI-answer manipulation.

The risk interpretation should therefore stay narrow. Citation buying, planted mentions, low-quality directory networks and scaled filler may intersect with existing link-spam, scaled-content or manipulation policies. That is a reason to assess them carefully—not proof that every loss during the August update was caused by GEO activity.

Regulated Malaysian practices should also check any applicable professional or healthcare advertising rules before publishing promotional claims. Search visibility does not override sector-specific obligations.

Action: Record where proposed third-party mentions will come from, who controls publication and why each source is relevant.

3. AI crawler controls became more granular

Crawler access is not simply a choice between “allow AI” and “block AI.” Cloudflare’s AI Crawl Control documentation describes monitoring AI crawler activity and creating crawler-specific policies. Its bot-control documentation distinguishes Search, Agent and Training purposes.

A business may want its public pages available for search or real-time assistant requests while taking a different position on model training. The correct configuration depends on its objectives and the behaviour of each crawler.

Robots.txt also requires careful interpretation. Cloudflare’s managed robots.txt guidance explains that the file expresses preferences, whereas enforcing a block requires technical controls.

Testing should cover service, pricing, practitioner, booking and opening-hours pages—not only the homepage. If relevant crawlers and search systems cannot access those pages, assistants have less opportunity to verify or quote details directly from the site. They may still find the business through other sources, so access is neither a guarantee of inclusion nor proof of exclusion.

Action: Record which important pages each relevant crawler can access, what is blocked and whether the configuration matches the organisation’s search, agent and training preferences.

4. Google visibility reporting became more specific—and measurement remains fragmented

Google’s generative Search guide directs site owners to its Generative AI performance report in Search Console. This first-party report applies to Google Search and Discover’s generative features; it is not a universal AI dashboard.

Search Console cannot report whether a business appeared in ChatGPT, Claude or Perplexity. Public agency tools generally cannot see those platforms’ internal ranking systems, so prompt tracking should be treated as an external measurement method rather than a direct platform report.

A useful measurement framework combines:

  • available first-party Search Console and analytics data;
  • a fixed list of genuine buyer prompts;
  • separate results for each assistant;
  • checks for name, service and location accuracy;
  • cited or recurring sources; and
  • a record of prompt, model and methodology changes.

An aggregate score should disclose its prompts, platforms, language and location variants, scan frequency, repeated-run treatment, prominence rules and formula. Without those details, a change from 10 to 30 cannot be interpreted independently.

Action: Establish a dated baseline and keep the method stable long enough to distinguish a trend from ordinary response variation.

What Geo One checks in a 2026 GEO audit

Geo One organises its audit around four evidence logs. The method is disclosed here so prospective clients can ask for the underlying records rather than accept a headline score.

Audit layer What Geo One checks Fields recorded
Crawler access Homepage, service, pricing, practitioner, booking and contact pages URL, page type, crawler or search system, access result and relevant directive or control
Entity consistency Registered name, trading name, address, phone, locations, services and named practitioners Source, observed value, preferred value, conflict and required correction
Prompt testing Category, location, problem, comparison and named-business questions Assistant, full prompt, language or location context, timestamp, mention, accuracy, sources and co-mentioned businesses
Source recurrence Pages repeatedly cited or used across tracked answers Source URL, publisher, assistant, prompt and recurrence across the agreed sample

Scan and reporting frequency should be stated in the client scope and preserved in the audit log. Geo One should not publish a fixed prompt count, frequency or market benchmark unless the underlying client methodology and permission have been verified.

A practical 2026 GEO audit

Area Evidence to collect Warning sign
Search foundations Indexing, entity and content audit A “special AI schema” sold as a guarantee
Spam risk Source and publication plan Bought citations or scaled filler
Crawler access Page-level tests and live controls A homepage-only check
Measurement Raw prompt results and first-party data One unexplained cross-platform score

What did not change

No platform update manufactures a reason to choose a business. If credible sources contain no clear services, specialisms, prices, credentials or evidence of whom a practice serves, improved access alone will not create meaningful differentiation.

GEO remains probabilistic. Models, retrieved sources and citations can change between runs. The objective is to improve the quality and consistency of signals—not to promise a fixed position.

For supplier evaluation, read Geo One’s guide to choosing a generative engine optimisation agency in Kuala Lumpur.

Sources checked for this review: Google’s generative Search guidance, Google Search spam policies, Google Search Status Dashboard, Cloudflare AI crawler documentation and Search Engine Journal’s August 2026 spam-update coverage. This article contains operational methodology, not an independent performance benchmark.

Frequently asked questions

Does Google need special structured data markup to show my business in AI search results?

No special structured-data markup is required for generative Search. Google's 2026 guidance confirms its generative features use the same core Search ranking and quality systems as regular Search, so established SEO practices remain the starting point. A schema change cannot compensate for conflicting facts across a website, Google Business Profile and authoritative records.

Will adding an llms.txt file help my site rank in Google's AI features?

No. Google's 2026 guide to generative AI features in Search states explicitly that llms.txt does not improve visibility or rankings in Google Search. Focus instead on crawlable pages, reliable information and sound SEO foundations rather than adding files that Google has confirmed carry no ranking benefit.

When did the August 2026 Google spam update roll out and finish?

Google began rolling out the August 2026 spam update on August 18, and the global rollout ended on August 21, according to the official Google Search Status Dashboard. Google announced no new spam-policy category alongside the update, and Search Engine Journal reported that existing policies remained the reference point.

Can I use Google Search Console to see if my business appeared in ChatGPT or Perplexity?

No. Google's Generative AI performance report in Search Console applies only to Google Search and Discover's generative features. Search Console cannot report whether a business appeared in ChatGPT, Claude or Perplexity, so prompt tracking across those platforms should be treated as a separate external measurement method rather than a direct platform report.

Is it safe to buy citations or third-party mentions to improve my AI visibility?

Citation buying and planted mentions may intersect with Google's existing link-spam, scaled-content or manipulation policies, which now expressly cover attempts to manipulate generative AI responses in Search. The article recommends recording where proposed third-party mentions will come from, who controls publication and why each source is relevant before pursuing any off-site mention strategy.

Can I block AI crawlers from training on my content while still allowing them to answer user questions?

Yes, that distinction is possible. Cloudflare's bot-control documentation separates crawler purposes into Search, Agent and Training categories, so a business can configure its pages to be available for real-time assistant requests while taking a different position on model training. Robots.txt alone expresses a preference but enforcing a block requires technical controls.

Bernard Leong

Co-Founder, Geo One

Nearly 20 years across energy, capital strategy and applied AI, including large-scale operational data at BP. Founded SkillsMe and Cryptrain.

More about the team

Check Your AI Visibility

See how AI platforms currently view your business with a free scan.

Free AI Scan
What Changed in GEO in 2026: Google, Cloudflare and AI Visibility Reporting | Geo One