A brand’s presence across a set of AI answers can be influenced, but no one can control a specific response — for structural reasons, not moral ones. In the 2026-08-06 sample, I ran 100 (question, engine) pairs five times each over a declared list of 29 brands: the name most often cited by the deterministic text rule appeared in 19 pairs and was absent from the other 81; in 51 of the 100, no brand on the list reached a majority of repetitions. These are dated category findings, not a current SOV assessment.

I write as Mateus Gomes, operator of murmur.marketing, a Brazilian GEO operation combining proprietary software with specialist service to measure and grow SOV. This page is a spoke of Is GEO a fad, or does it actually work?, which separates mechanism, technique, and promise. Here there is one object only: how much influence can anyone have over the answer, and where does it become manipulation?

Summary

  • The question has three versions, and only one is useful: influence (possible, with a ceiling), deceive the engine with a technical trick (what Google’s documentation calls cloaking, and what gets a site removed), and choose the answer (nobody can).
  • Historical category findings (2026-08-06): the most-cited name appeared in 19 of 100 pairs, was absent in 81, and 51 of 100 had no brand from the declared list of 29 reach a majority. This is not a current SOV measurement.
  • Proof there is no control: in the hiring-question family, 48 captures (12 questions × 4 engines), all four engines disagree over the first name — and in 8 of the 48, none of the 29 brands appears.
  • Instability is external and measured, too: SparkToro’s research, with 600 volunteers and 2,961 runs, records less than a 1-in-100 chance that two responses bring the same brand list, and identical ordering in about 1 in 1,000.
  • What the historical baseline showed: more than fifteen years of authority built outside the site corresponded to 19 of the 100 pairs; four months of concentrated content corresponded to 15. murmur.marketing was absent in that 2026-08-06 sample, before the current guide library; this is not a current SOV result.
  • Real manipulation exists — on the other side of the wire. In a client server log, a single IP fired fake PerplexityBot, Googlebot, bingbot, YandexBot, DeepSeekBot, and CCBot user agents in the same second, requesting /.env and /.git/config.

Declaration of interest, before the numbers

I sell GEO, so this is an interested author writing about the category. The figures below make the method and its limits inspectable: on 2026-08-06, 100 Portuguese questions × 4 engines produced 800 captures with screenshots in 800 of 800. murmur.marketing appeared zero times in that historical baseline, before the current guide library; outside the 10 questions that already included my name in the prompt, the result was 0 of 712. These figures describe that dated sample, not today’s SWAS strategy or current SOV.

These dated results document a historical sample, not a current assessment of the SWAS operation or today’s SOV.

The three questions hidden inside the question

When someone asks whether it is possible to manipulate what ChatGPT recommends, they mean one of these three things, and they have different answers:

  1. “Can you influence it?” — Yes, and there is an observed effect. At Fly Med, publication was on 2026-05-22 and ChatGPT’s first citation of two directory pages came on 2026-05-27, with ?utm_source=chatgpt.com in the URL. T+5 days. In the same probe and on the same day, at sister company Fly Vet: zero. Influence exists; predictability does not.
  2. “Can you deceive the engine with a technical trick?” — You can try, and the cost is your site. Google documents serving different content to the crawler and the person as cloaking, a policy violation that can lead to removal. What is legitimate, and what almost nobody distinguishes: a public page available to anyone, simply without a link in the navigation — “strategic orphan content” is not cloaking because nothing is hidden from any agent.
  3. “Can you choose the answer?” — No. The rest of this page is the measurement that supports that “no.”

The 2026-08-06 sample: 19 out of 100, and 51 without a majority

These are the numbers from my 2026-08-06 campaign, using a deterministic text rule over a declared list of 29 names, across 100 (question, engine) pairs with five repetitions each: Conversion 19 · GeoStack 15 · Brasil GEO 14 · Criamente 9 · Profound 8. The two required caveats belong in the same sentence: the top three are separated by less than 1.3 binomial standard errors, which is not stable ordering, and the name with 19 pairs is absent from the other 81.

And the figure that answers the title’s question better than any other: in 51 of the 100 pairs, no brand from the declared list reaches a majority of the five repetitions. Half the field had no majority in this sample. That dated result does not establish a present-day ceiling or prove that the engines are impossible to influence.

The hiring axis says the same thing from another angle. In the family of questions about hiring a GEO agency — 48 captures, 12 questions × 4 engines, one repetition each — the absolute count was Brasil GEO 19 · Conversion 18 · GeoStack 18 · Criamente 14 · SW Agência 10 · Upsend 9 · Bloomin 9 · Quality SMI 7, always using the same declared list of 29 names. The finding is not the podium: it is that each engine has a different top result — ChatGPT puts one brand first, Claude ties two others, Perplexity chooses a third, and Google AI Overview a fourth — and in 8 of the 48 captures none of the 29 is named. These are absolute counts, never percentages, because the rule sees 29 names out of at least 447 that the judge extracted.

Why control fails structurally

It is not that the engines are well defended against manipulation. It is that they are not one engine, and the answer each gives comes from a different chain.

enginewhere its cited material comes fromown crawlerwhat this means to someone trying to “manipulate” it
ChatGPTsearch anchored in Bing’s index, plus what OpenAI crawlers readGPTBot · OAI-SearchBot · ChatGPT-Userit goes through Bing Webmaster Tools, which almost nobody uses
Claudeits own crawling, with a strong dependency on third-party sourcesClaudeBot · Claude-SearchBotit cited the least in my campaigns, even while reading the most
Perplexityits own index and crawlingPerplexityBot · Perplexity-Userit answers differently from the other three for the same questions
Google AI OverviewGoogle’s index, served by GooglebotGooglebot (the same bot as Search)Google’s public documentation applies here

A tactic that worked would have to work across four chains with different crawlers, indexes, and rules, and it would have to survive each one’s internal variation. That variation has an external measurement: Rand Fishkin and Patrick O’Donnell’s SparkToro research, with 600 volunteers and 2,961 runs across ChatGPT, Claude, and Google AI Overview, records less than a 1-in-100 chance that two answers carry the same brand list, and identical ordering in about 1 in 1,000. Their conclusion is blunt and verifiable: any tool promising an “AI ranking position” is selling nonsense.

And there is the measurement I made myself, which closes the point. The question that began my whole campaign — what is the best company for GEO in Brazil — run five times across all four engines, for 20 captures total: the same company is named in 5 out of 5 ChatGPT responses, 4 out of 5 Perplexity responses, 0 out of 5 Claude responses, and 0 out of 5 Google AI Overview responses. Nine out of twenty. The screenshot that made me start this was not wrong — it was incomplete.

What actually moves the needle, and why it is not a trick

When I reverse-engineered the public structure of the most-cited names using raw curl on 2026-08-06, the result contradicted the intuition of anyone imagining manipulation.

The most-cited name has 9 pages under /geo/ in a sitemap of 1,366 URLs — 0.7% of the site — and publishes less than one post per month on the subject. What it has accumulated lies outside the GEO surface: its own research hosted on Poder360 and E-Commerce Brasil, two Band articles crowning it first out of ten, and its founder on five third-party podcasts. I record a caveat from the research itself: the Band listicle looks like syndicated PR placement, and it was not possible to confirm whether it was paid.

The second path is the opposite and also works: 279 URLs across four sitemaps, with lastmod between 2026-04-12 and 2026-08-06 — about four months of concentrated content. In that campaign, one path corresponded to 19 of the 100 pairs and the other to 15. Both require sustained work, not a trick, and neither cleared one fifth of the field. murmur.marketing was absent from this historical sample; that finding predates the current guide library and is not a current visibility assessment.

This sample does not establish a manipulation lever or a current ceiling; it shows variation across engines and prompts.

The Fly Vet case: published content and an entity opportunity

This is the material I can publish by name because the company is mine.

The Fly Vet homepage presents itself as the “first and largest agency” in the veterinary-marketing niche. Its content cluster is published and indexed. Yet in the June 2026 campaign of 100 ChatGPT questions, competitor EvolueVet appears in 28 of the 100 responses; within those 28, Fly Vet is recommended in 10. In 8 questions of the “best marketing or traffic agency for veterinary” type, Fly Vet is absent and the competitor is listed first.

Content made, game lost. The bottleneck was not content — it was entity, and no writing technique resolves that, because the engine was not resolving the brand as a distinct thing in the world. And if manipulation were possible at the dose the market suggests, the owner of the published cluster would not lose eight category searches to a competitor.

Where influence becomes fraud — and where it already exists

It is worth separating four things commonly thrown into the same bucket:

tacticis it manipulation?what the evidence saysreal risk
publish a page specific to a real questionnoit is the mechanism that produced Fly Med’s T+5-day citationnone
a public page without a navigation-menu linknonothing is hidden from any agent; Google is not blockednone, if access is the same for everyone
serve different HTML to a crawler and a personyesit is cloaking under Google’s public policyremoval from the index
fabricate a third-party mention and reviewyesI cannot measure it and do not offer itreputational and legal

And there is manipulation I did measure, only on the other side of the wire. In an access log from a client subdomain, 2,256 lines in 24 hours, the raw user-agent count showed ClaudeBot 88, OpenAI 10, and Perplexity 6. Matching user agent against the actual IP left ClaudeBot 79 (Anthropic IPs), OpenAI 3, and Perplexity zero. A single IP fired fake user agents for PerplexityBot, Googlebot, bingbot, YandexBot, DeepSeekBot, and CCBot in the same second, requesting /.env, /.git/config, and /service-account.json. It was not a crawler: it was credential scanning dressed as a bot.

The lesson is as large as this article: anyone who counts AI crawlers by user agent alone is counting intruders too — and anyone who thinks “manipulating AI” is easy is usually looking at a number another person has already manipulated against them.

What remains: influence with a denominator

I ran the same 387 questions from a real client universe three days apart, without changing anything: about 98% returned the same verdict — in ChatGPT, 7 of 387 varied; in Claude, 6 of 386; both rounds preceded any intervention. This produces the threshold: movement above 3 to 4 percentage points in the comparable set is real; below it is variance.

That is why the serious answer to the title’s question is not “yes” or “no,” but “at what unit?” At the level of one answer, the result is close to a draw. Across hundreds of repeated questions, frequency moves — slowly, with a denominator, and never to the point where someone chooses what the machine will say.

Frequently asked questions

So can or can’t you influence what ChatGPT recommends?

You can work to increase how often a brand appears across a set of questions, but you cannot choose the answer to a specific question. The distinction is measured, not rhetorical: at Fly Med, the first citation of two directory pages came five days after publication, with a traceable URL in the screenshot; at sister company Fly Vet, in the same probe and on the same day, the result was zero. The separate 2026-08-06 category sample found the most-cited name in 19 of 100 pairs and absent in 81; this is a dated finding, not a current ceiling or current SOV measurement.

Can someone pay to appear in AI answers?

There is currently no public auction that buys a position inside an organic ChatGPT, Claude, or Perplexity answer in the way a traditional-search ad auction does. What exists and is observable is the indirect purchase of entity authority: proprietary research hosted by a third-party publication, a press listicle, podcast participation. I record a caveat from my own research on one of these cases: the listicle looks like syndicated PR placement, and it was not possible to confirm whether it was paid. In the 2026-08-06 sample, this combined presence corresponded to 19 of 100 pairs; that is a historical finding, not a current ceiling or guaranteed result.

Does paying for a mention in a portal or a listicle change what AI recommends?

It cannot be asserted. In the 2026-08-06 public-structure research, two Band articles highlighting a category name looked like syndicated PR placement, but payment could not be confirmed. In that sample, this third-party presence combined with the domain’s history corresponded to 19 of 100 pairs and was absent in the other 81. This is a dated observation; it establishes neither a current ceiling nor a manipulation method.

What is cloaking, and why is it not an alternative?

Cloaking is serving one piece of content to the crawler and another to the person visiting the same URL. Google’s public policy treats it as a violation subject to removal from the index, and because Google cannot be blocked without the page ceasing to exist in Search, the tactic trades a hypothetical gain in AI for a certain risk in the channel that still brings most traffic. The legitimate alternative that almost nobody distinguishes is publishing a public page that is identical for every agent, simply without a link in the navigation menu. Nothing is hidden from anyone, so it is not cloaking.

Could the AI-crawler number in my own report be manipulated?

It could, and it is the only manipulation I was actually able to measure. In an access log from a client subdomain — 2,256 lines in 24 hours — the raw user-agent count reported ClaudeBot 88, OpenAI 10, and Perplexity 6; matching user agent against the actual IP left ClaudeBot 79 on Anthropic IPs, OpenAI 3, and Perplexity zero. One IP fired fake user agents for PerplexityBot, Googlebot, bingbot, YandexBot, DeepSeekBot, and CCBot in the same second, requesting /.env, /.git/config, and /service-account.json — not a crawler, but credential scanning dressed as a bot. Anyone counting AI crawlers by user agent alone is counting intruders too, and the inflated number works against its publisher because it suggests engine interest that does not exist. The fix is tedious and always the same: match the user agent against a verified IP before turning a log line into a headline.

Who wrote this

Mateus Gomes, operator of murmur.marketing, a SWAS combining proprietary software with specialist strategy and execution to measure and grow SOV. I personally ran the 2026-08-06 campaign cited here, the Fly Vet and Fly Med measurements, and the curl reverse engineering of the named competitors’ public structure.

The commercial interest is direct and stated at the top. The 800-capture result was a historical baseline from before the current guide library; it is not an assessment of today’s operation or SOV.

Conclusion

GEO work can aim to grow a brand’s presence across a set of AI answers, but no one can choose an individual response. In the 2026-08-06 campaign, the most-cited name appeared in 19 of 100 pairs, was absent in 81, and 51 of 100 pairs had no brand from the declared list of 29 reach a majority. These are dated category findings, not a current SOV measurement. The work at murmur combines proprietary software with specialist strategy and execution to track and grow SOV; eligible contract models may include a growth guarantee, subject to the agreed baseline, scope, timeframe and conditions. This is not a guarantee of an individual answer. To discuss measurement for your case — with a denominator, execution date, and screenshot — contact Mateus Gomes on LinkedIn.

See also