The Cited Method (ACCESS, MEASURE, MAP, EARN, PROVE) · 16 min read

Earning AI Citations, and Where the Line Sits

Most coverage of this splits into how to game it and please do not. Neither is usable in a client meeting. Here is the line drawn with quoted policy instead of opinion.

84% to 93%of AI citation weight sits on third-party sites, not the brand's own domainAleyda Solis, 15 SaaS brands across three US subverticals
The short version
  • The competitor screenshot your client sent is one sample from a distribution where two runs of the same prompt agree less than 1 percent of the time.
  • Between 84 and 93 percent of AI citation weight for the brands Aleyda Solis measured sits on third-party properties, which is precisely why the ethical pressure in AI search is off-site rather than on-page.
  • Every manufactured tactic on this list breaks a specific written clause: FTC 16 CFR Part 465, Reddit's Disrupting Communities policy, the Wikimedia Terms of Use, G2's Community Guidelines, or Google's spam policies.
  • The usable field test is disclosure. If a tactic stops working the moment you label it accurately, it was manufactured.
  • Manufactured citation share is a depreciating asset. ChatGPT's Reddit citation rate fell from roughly 60 percent of responses to roughly 10 percent in about six weeks, and Semrush's own analyst attributes it to anti-manipulation work.

The screenshot is not the evidence your client thinks it is

A client sends you a screenshot. A competitor is named first in ChatGPT for the query that pays their mortgage, and two of the sources under the answer are Reddit threads that read like the same person wrote both. Then comes the question you have to answer in the meeting: are we doing that or not?

Before the ethics, kill the premise. Run the prompt five more times.

SparkToro and Gumshoe.ai collected 2,961 prompt runs from 600 volunteers across ChatGPT, Claude and Google AI and found less than a 1 in 100 chance that any two runs of the same prompt return the same brand list. One screenshot is one draw from a very wide distribution. That is not a technicality, it is usually the whole disagreement, and it is why I argue elsewhere that a single run is not a measurement.

AIs do not give consistent lists of brand or product recommendations. If you don't like an answer, or your brand doesn't show up where you want it to, just ask a few more times.

Rand FishkinCo-founder, SparkToro

The second thing to say before you get anywhere near ethics is that the manufactured version decays, and there is a dated, measured example of it happening. Semrush tracked 230,000 prompts in weekly snapshots from July to October 2025 and watched ChatGPT's Reddit citation rate collapse from close to 60 percent of responses in early August to around 10 percent by mid-September. Wikipedia's ChatGPT citation rate fell in the same window, from roughly 55 percent to under 20 percent, while both held steady on Google AI Mode and Perplexity. Whatever happened, it happened inside one engine, deliberately.

I believe the main reason for the drop is an attempt to avoid over-citing on certain websites, to be less biased toward them, while generating answers. As a result, ChatGPT has become more resilient to manipulation attempts.

Sergei RogulinHead of Organic and AI Visibility, Semrush

That is not moralising. That is an engine operator's analyst saying that concentration in one source is a defect they actively correct. Any plan whose mechanism is saturating a single high-citation domain is buying an asset with a scheduled write-down already on the books.

The short answer

An earned AI citation comes from something another party chose to publish about you: a moderator left your comment up, an editor ran your data, a customer wrote a review nobody conditioned on sentiment. A manufactured one comes from something you paid to have appear. The usable field test is not intent, it is disclosure: if a tactic stops working the moment you label it accurately, it was manufactured. For the six most common tactic pairs, that difference is written into a specific clause of the FTC's review rule, Reddit's own policies, the Wikimedia Terms of Use, G2's guidelines, or Google's spam policies, and you can quote it back to the client instead of arguing about values.

84% to 93%

of AI citation weight sits on third-party sites, not the brand's own domain

The line lives off your own site, which is exactly why this got hard

Classic on-page SEO tempted you to lie about your own page. That is a small temptation with a small blast radius, and Google spent twenty years pricing it. AI citation moved the address. Aleyda Solis measured 15 SaaS brands across three US subverticals and found 84 to 93 percent of citation weight sitting on properties the brand does not own. Peec AI's read of 30 million cited sources puts Reddit first, then YouTube, LinkedIn and Wikipedia.

So the temptation moved with it. The new temptation is to lie about other people's pages, in other people's communities, using accounts that are not you. That is a categorically different act, and it is why the GEO discourse suddenly needs an ethics section when the SEO discourse mostly did not.

The share numbers are also more volatile than most posts admit, and the denominator does the work. Profound's 680 million citation analysis has Reddit at 2.2 percent of all Google AI Overview citations, 6.6 percent on Perplexity and 1.8 percent on ChatGPT, where Wikipedia leads at 7.8 percent. Semrush's ~60 percent figure counts responses containing a Reddit citation. Both are correct. If a vendor quotes you a Reddit share without naming the denominator, they do not know which number they are holding, which is worth knowing before you take their advice on which sources actually get cited.

84% to 93%
of AI citation weight sits on third-party sites
~60% to ~10%
collapse in ChatGPT's Reddit citation rate, Aug to Sep 2025
<1 in 100
chance two runs of one prompt return the same brand list

Six pairs of near identical twins, and the clause that separates each one

Each pair below sits at the same altitude. The earned version and the manufactured version produce the same artifact in the same place, and from the outside they can look identical. The difference is always a written rule, so I have quoted the rule rather than asserting a preference.

1. Answering in communities versus seeding threads

Earned: one named account, disclosed affiliation, answering questions in subreddits you would read anyway. Manufactured: three aged accounts whose entire history is recommending one company.

Reddit's spam policy defines spam as "repeated or unsolicited actions (whether automated or manual) that negatively affect redditors, communities, and/or Reddit itself" and names "Mass-posting repetitive content for the purpose of exposure or financial gain" as a violating example. Its guidance on staying clear is one sentence: "Post authentic content into communities where you have a personal interest."

Note what that clause does not say. It does not ban self-promotion, and it does not set a ratio. The 90/10 rule people still quote is folklore, not current policy. The actual test is whether you have a personal interest, which a real practitioner answering real questions passes trivially and a rented account cannot pass at all.

2. Upvotes you got versus upvotes you bought

Earned: you wrote something people voted for. Manufactured: you bought votes, or organised a group to cast them.

Reddit's Disrupting Communities policy prohibits "Vote cheating or manipulation, whether manual, programmatic, or otherwise," and spells out both delivery mechanisms: "Creating and employing multiple accounts, voting services, or any automation to manipulate vote counts," and "Engaging in coordinated voting with an organized group of people (or bots) to target a specific post."

There is a second, sharper clause. The FTC's review rule makes it a violation to "Purchase or procure fake indicators of social media influence that they knew or should have known to be fake and that materially misrepresent their influence or importance for a commercial purpose" (16 CFR 465.8). The rule defines those indicators as "any metrics used by the public to make assessments of an individual's or entity's social media influence, such as followers, friends, connections, subscribers, views, plays, likes, saves, shares, reposts, and comments."

Be honest about this one: upvotes are not in that list. The definition is open ended and an upvote count is obviously a metric the public uses to assess influence, so I read purchased upvotes as covered. No regulator has said so on the record, and I am not going to pretend otherwise. If that is the only thing standing between your client and the tactic, they are already too close to the line.

3. Asking every customer versus asking the happy ones

This is the pair agencies get wrong while believing they are clean, and it is the one with the most exact clause.

Buying sentiment is flatly prohibited: it is a violation to "provide compensation or other incentives in exchange for, or conditioned expressly or by implication on, the writing or creation of consumer reviews expressing a particular sentiment, whether positive or negative" (16 CFR 465.4). Everyone knows that one.

The clause nobody quotes is the safe harbour in 465.2(d)(1), which exempts "Reviews or testimonials that resulted from a business making generalized solicitations to purchasers to post reviews or testimonials about their experiences." Read those two together and the operational rule falls out with no ambiguity at all: send the review request to your whole customer list, not to the segment you expect to say nice things. Filtering the ask is the violation. The ask itself is protected.

G2 codifies the same line for software vendors and goes further, listing as prohibited "collecting reviews by any method that segments out potentially negative reviews or exclusively targets positive reviews" and, separately, "Fraudulent or Manipulative Review Activity," defined as "creating, soliciting, or submitting fake or otherwise inauthentic reviews that don't reflect a genuine service or buying experience."

One more clause with teeth, because employee reviews are the quiet default in small agencies. An officer or manager writing a review of their own business without "a clear and conspicuous disclosure of the officer's or manager's material relationship to the business" is a violation under 465.5(a). And the rule's own definition of clear and conspicuous is stricter than the disclosure most people ship: "A disclosure is not clear and conspicuous if a consumer must take any action, such as clicking on a hyperlink or hovering over an icon, to see it." A bio-page disclosure does not clear that bar.

4. Pitching a listicle versus buying a slot in one

The commercial pressure here is real and quantified, which is why it deserves a straight answer rather than a shrug. Peec AI analysed nearly 200,000 AI responses across eight engines and found that ranking first in a frequently cited third-party listicle was associated with a 16.5 percentage point visibility lift in B2B SaaS, and moved a brand's position within the answer 1.80 places earlier in US Finance. Placement in someone else's list is one of the most leveraged positions in AI search.

Which is exactly why slots in those lists are for sale. Google's spam policies name the transaction directly, listing as link spam "Advertorials or native advertising where payment is received for articles that include links that pass ranking credit, or links with optimized anchor text in articles, guest posts, or press releases distributed on other sites." The same page defines site reputation abuse as "a tactic where third-party content is published on a host site mainly because of that host's already-established ranking signals."

Here is the part most agencies miss, and it is the part that makes this workable: Google does not prohibit the payment. It prohibits the undisclosed ranking credit. The same document says buying and selling links is "a normal part of the economy of the web for advertising and sponsorship purposes" and is not a violation when the link carries rel="sponsored" or rel="nofollow". So a paid placement is available to you. It is available with an attribute on the link and the word sponsored on the page. If the value of the placement evaporates once you do that, you were never buying reach, you were buying ranking credit, and you knew it.

5. Fixing a Wikipedia error versus hiring an undisclosed editor

Wikipedia is ChatGPT's most-cited domain at 7.8 percent of all citations in Profound's dataset, so the incentive to buy a page is obvious. The Wikimedia Terms of Use handle it in one sentence: "You must disclose each and any employer, client, intended beneficiary and affiliation with respect to any contribution for which you receive, or expect to receive, compensation." The disclosure has to be on a user page, a talk page, or in the edit summary. And the reach of that clause surprises people: if you advertise paid Wikipedia editing anywhere off-platform, you must disclose every account you have used or will use, in the advertisement itself.

That is a clean, quotable answer for the client who wants a page. The honest addition is that I have found no primary evidence that a Wikidata entry or a Wikipedia page causally lifts AI citation for a specific brand. The correlation is easy to observe. The mechanism is not established, and buying an undisclosed edit is a policy violation in exchange for an unproven return.

6. Writing something quotable versus writing something for the retriever

The last pair is on your own page, and it is the one with actual published research on both sides.

On the earned side, the GEO paper accepted to KDD 2024 tested nine optimisation methods on a 10,000-query benchmark. Quotation Addition scored 27.2 on Position-Adjusted Word Count, Statistics Addition 25.2 and Cite Sources 24.6, against an unoptimised baseline of 19.3. Real quotes, real numbers, real citations. That is not a trick, it is just writing that is easier to lift.

On the manufactured side, Aounon Kumar and Himabindu Lakkaraju showed that adding a strategic text sequence to a product page substantially increases its chance of being the model's top recommendation, and Nestaas, Debenedetti and Tramer demonstrated Preference Manipulation Attacks against production Bing and Perplexity, concluding that they produce "a prisoner's dilemma, where all parties are incentivized to launch attacks, but the collective effect degrades the LLM's outputs for everyone."

That is the cleanest statement of the case against manufacturing I have found anywhere, and it comes from adversarial ML researchers rather than from marketers with a values page. The tactic works and it poisons the well it draws from.

Google's position on the automated version is already written: scaled content abuse covers "Using generative AI tools or other similar tools to generate many pages without adding value for users." Reddit's Manipulated Content policy allows AI-assisted content but prohibits content "that presents itself as human-generated." And it is worth remembering that Google's own AI documentation says there are "no additional requirements to appear in AI Overviews or AI Mode", which is the same reason llms.txt is not a lever and schema does not lift citations.

Comparison table of six earned versus manufactured AI citation tactics, each labelled with the platform policy clause that separates them
Every row on the right breaks a specific written rule. The rule, not the intent, is what you quote to the client.Sources: 16 CFR Part 465 (eCFR), Reddit Rules, Wikimedia Terms of Use, G2 Community Guidelines, Google Search spam policies.
Use this graphic on your site

Free to republish with a link back to this page. Copy the embed code:

<a href="https://josephtimpson.com/insights/how-to-get-cited-by-ai"><img src="https://josephtimpson.com/assets/infographics/how-to-get-cited-by-ai.svg" alt="Comparison table of six earned versus manufactured AI citation tactics, each labelled with the platform policy clause that separates them" width="1200" style="max-width:100%;height:auto"></a><p>Graphic by <a href="https://josephtimpson.com/insights/how-to-get-cited-by-ai">Joseph Timpson</a></p>

Three tests for the cases the six pairs do not cover

New tactics arrive faster than policy text does. When a pair is genuinely novel, I run these three in order and stop at the first failure.

The three tests, in order
  1. The disclosure test. Write the sentence that accurately labels what you did, in public, at the point of the artifact. If the tactic stops working, it was manufactured.
  2. The refusal test. Identify the party who could say no: the moderator, the editor, the customer, the reviewer. If nobody in the chain has a real ability to refuse, you are not earning anything.
  3. The volume test. Ask whether the tactic only pays at a scale no honest human could perform. If the economics require 40 accounts or 400 pages, the volume is the mechanism, and the volume is what every policy on this page is written to catch.

The disclosure test does most of the work, and it is the one to hand a client, because it converts a values argument into an operational one. Nobody has to agree with you about ethics. They have to decide whether they are willing to write the label. Note that the FTC's rule is built on exactly this logic: it does not prohibit employees having opinions, it prohibits undisclosed ones, and its definition of adequate disclosure requires the disclosure to be unavoidable rather than one click away.

The refusal test is the one I added most recently, and it catches things the other two miss. A guest post on a site that accepts every submission for a fee has an editor in name only. The refusal test flags it even when the payment is disclosed, because a gatekeeper who never gates is not conferring anything an engine should weight.

EARN is the fourth stage of the Cited Method, and it runs after ACCESS and MEASURE for a reason. Earning citations you cannot see is not a strategy.

See how the EARN stage works

What each lane actually costs

I am not going to publish price ranges for manufactured tactics, because I have not verified any and quoting a market rate is a form of advertising it. What I can lay out is the shape of each lane.

The two lanes, priced honestly
EarnedManufactured
Time to first signalSlow. Months, and most pitches are simply ignoredFast. That is the entire pitch
Who controls the outcomeA moderator, an editor, a customer, a reviewerYou, until the platform notices
What degrades itThe topic moving onThe engine actively de-weighting the source
What happens under disclosureNothing. It was always disclosedIt stops working
Downside if caughtA pitch goes unansweredAn FTC rule violation, a platform ban, or a Google manual action
What it leaves behindAn asset that keeps getting citedAn account graveyard and a rebuild

The first row is the honest cost, and pretending otherwise is how agencies lose these arguments. Earned placement is slow and most of it fails. Muck Rack's State of Journalism 2026 found 69 percent of journalists prefer pitches under 200 words, which tells you how thin the attention is at the other end.

Journalists, like all of us, are extremely overwhelmed. No response doesn't always mean no interest.

Michael KayeHead of E&E Brand and Communications, Match Group

The row that actually decides it is the last one. Manufactured citation share has to be maintained forever, because the maintenance is the mechanism. Earned citations sit there. Kevin Indig's study of more than 50,000 brands found that where a category already had a clear owner in ChatGPT answers, that brand held first place in 90.4 percent of month-over-month comparisons. Durability is the whole return, and it is the argument that survives contact with a CFO. It is also the reason I scope EARN work as a retainer line rather than a project.

What the earned lane has going for it, and where the evidence is thin

I would rather you disagree with me having seen the weak spots than agree with me having seen a highlight reel.

The strongest thing in the earned column is the GEO paper's negative result, not its positive one. Keyword stuffing scored 17.7 against a 19.3 unoptimised baseline, meaning the classic manipulation tactic measured worse than doing nothing at all.

While this technique has been widely used for Search Engine Optimization, we find such methods have little to no performance improvement on Generative Engine's responses.

Pranjal AggarwalLead author, GEO: Generative Engine Optimization, accepted to KDD 2024

The off-site case rests on Ahrefs' study of 75,000 brands, where branded web mentions correlated with AI Overview visibility at 0.664 against 0.218 for backlinks. I lean on that number often. It is a correlation, the authors say so themselves, and most posts repeating it delete that sentence. It does not prove that earning a mention causes a citation. It proves the two travel together, which is weaker and still useful. I unpack that gap in more detail in the piece on what brand mentions actually buy you.

The honest summary is that the earned lane has better evidence than the manufactured lane on durability and a comparable amount of evidence on short-term effect. That is the real trade, and it is worth stating plainly rather than dressing up as a moral victory. The manufactured lane works. It just works the way a payday loan works.

What to say when the client asks why the competitor is winning

Here is the script, and it is four sentences.

First: that screenshot is one sample, and two runs of the same prompt agree less than one percent of the time, so let us measure it properly before we react. Second: the specific tactic you are pointing at breaks a written rule, and here is the clause, and here is the URL. Third: it also decays, and here is a dated example of an engine cutting a single source's citation rate by roughly six times in six weeks. Fourth: here is the earned twin of that exact tactic, what it costs, and how long it takes.

That conversation does not require the client to share your values. It requires them to read four sentences and decide whether they want to write the disclosure. Most of them do not want to, and that is the answer.

The reason it works is that AI answers are ultimately borrowing other people's credibility, and the platforms know it.

In a world flooded with AI slop, people are seeking real community, lived experience, and trusted opinions. That's Reddit's differentiator.

Steve HuffmanCo-Founder and Chief Executive Officer, Reddit, Inc.

That is a CEO explaining, in a shareholder letter, exactly why the thing you would be manufacturing is the thing the platform exists to protect. The engines are downstream of that. Pew found that 88 percent of AI summaries cite three or more sources, which means you do not need to own the answer. You need to be one of several credible mentions, repeatedly, in places where somebody real chose to include you.

Start with whether the crawlers can reach your content at all, because none of this matters if they cannot. Then build the prompt set and the baseline so you can tell the difference between a real lift and a re-roll. Then earn. In that order, every time. The rest of the method is laid out in the Cited Method, and the full set of these teardowns lives in Insights.

Frequently asked questions

How do you get cited by AI without manufacturing citations?

Be one of several credible mentions in places somebody chose to include you. Answer in communities under a named account, pitch data to editors who can refuse it, ask every customer for a review rather than the happy segment, and publish quotable statistics with sources.

Is buying Reddit upvotes against the rules?

Yes. Reddit's Disrupting Communities policy prohibits vote cheating or manipulation "whether manual, programmatic, or otherwise," naming voting services and coordinated voting groups. The FTC's rule separately bans purchasing fake indicators of social media influence, though upvotes are not explicitly named in its list.

Can I pay for a spot in a listicle that AI engines cite?

You can pay for the placement. Google's spam policies prohibit paid articles carrying links that pass ranking credit, but the same page says paid links are fine when qualified with rel=sponsored or rel=nofollow. If the placement loses its value once disclosed, you were buying ranking credit.

What does the FTC rule actually prohibit about reviews?

16 CFR Part 465 prohibits fake reviews, incentives conditioned on sentiment, undisclosed insider reviews, company-controlled review sites presented as independent, review suppression, and buying fake social media influence indicators. It took effect on October 21, 2024 and is issued under 15 U.S.C. 57a.

Is asking customers for reviews allowed?

Yes, and the rule protects it explicitly. Section 465.2(d)(1) exempts reviews resulting from "generalized solicitations to purchasers." The violation is filtering the ask. Send the request to your whole list rather than to the customers you expect will say something positive.

Do Reddit citations actually help AI visibility?

Reddit is the most-cited domain in Peec AI's analysis of 30 million sources, but the share is platform-specific and volatile. Profound measured 6.6 percent on Perplexity and 1.8 percent on ChatGPT, and Semrush watched ChatGPT's rate fall from roughly 60 percent to 10 percent.

Can I hire someone to edit our Wikipedia page?

Only with disclosure. The Wikimedia Terms of Use require disclosing every employer, client and intended beneficiary for any compensated contribution, on a user page, talk page or in the edit summary. Off-platform advertisements for paid editing must list every account used.

How do I know if a new tactic crosses the line?

Run three tests in order. Disclosure: does it survive an accurate public label. Refusal: can the moderator, editor or customer genuinely say no. Volume: does it only pay at a scale no honest person could perform. Stop at the first failure.

Do manufactured AI citations work in the short term?

Often, yes, and pretending otherwise loses the argument. Two peer-reviewed adversarial studies show production engines can be manipulated. The case against is durability: engines actively de-weight over-cited sources, and the maintenance cost never ends because the maintenance is the mechanism.

Does schema markup or llms.txt help get cited by AI?

No published evidence supports either. Ahrefs' controlled study of 1,885 pages found no uplift from adding JSON-LD, SE Ranking found no citation relationship across 300,000 domains for llms.txt, and Google states there are no additional requirements to appear in AI Overviews.

Sources

  1. Federal Trade Commission (eCFR). Rule on the Use of Consumer Reviews and Testimonials, 16 CFR Part 465 (2024-08)
  2. Reddit Help. Spam (2026-05)
  3. Reddit Help. Disrupting Communities (2026-05)
  4. Reddit Help. Manipulated Content and Misleading Behavior (2026-05)
  5. Wikimedia Foundation. Terms of Use, Paid Contributions Without Disclosure (2026-07)
  6. G2. Community Guidelines (2026-07)
  7. Google Search Central. Spam policies for Google web search (2026-07)
  8. Google Search Central. AI features and your website (2026-07)
  9. Google Search Central Blog. Evolving nofollow, new ways to identify the nature of links (2019-09)
  10. Semrush. Most cited domains in AI search (2025-11)
  11. Profound. AI platform citation patterns, 680 million citations (2025-06)
  12. Peec AI. Top domains cited by AI search, analysis of 30M sources (2026-03)
  13. Peec AI. The listicle rank effect, nearly 200,000 AI responses across 8 engines (2026-05)
  14. Aleyda Solis. SaaS AI search optimization, 15 brands (2026-07)
  15. SparkToro with Gumshoe.ai. AIs are highly inconsistent when recommending brands or products (2026-01)
  16. Aggarwal, Murahari, Rajpurohit, Kalyan, Narasimhan, Deshpande. GEO: Generative Engine Optimization (KDD 2024) (2024-06)
  17. Aounon Kumar and Himabindu Lakkaraju (arXiv). Manipulating Large Language Models to Increase Product Visibility (2024-04)
  18. Nestaas, Debenedetti and Tramer (arXiv). Adversarial Search Engine Optimization for Large Language Models (2024-06)
  19. Ahrefs. AI Overview brand visibility correlation study, 75,000 brands (2025-05)
  20. Muck Rack. State of Journalism 2026 (2026-04)
  21. Pew Research Center. Google users are less likely to click on links when an AI summary appears (2025-07)
  22. Reddit, Inc.. Q4 2025 Letter to Shareholders (2026-02)
  23. Growth Memo (Kevin Indig). Does topical authority matter in AI search, 50,000 brands (2026-07)
  24. Ahrefs. Does schema markup help with AI citations, 1,885 pages (2026-05)
  25. SE Ranking. llms.txt adoption and citation impact across 300,000 domains (2025-11)
Joseph Timpson
Written by
Joseph Timpson

Joseph Timpson has worked in search since 2010 and runs Timpson Marketing out of St. George, Utah. He built The Cited Method, a five stage framework for earning and proving real citations in AI answers, and publishes what does not work alongside what does.

Want me to run this on your site and show you the before and after?

One call, no pitch deck. We look at what is actually blocking you and tell you the truth about whether we can help.

Book a free consultation