Tag: AI

  • Is SEO Really Dead? Discover the Future of SEO in 2026

    Is SEO Really Dead? Discover the Future of SEO in 2026

    SEO isn’t dead—far from it. But let’s face it, AI is definitely changing the game in ways we never imagined. This got me thinking about how things are looking different for us, especially with the rise of zero-click searches and AI Overviews. In 2026, these are becoming more like the hand guiding our SEO strategies.

    With AI advancements, I’m seeing how crucial it is for all of us to adapt and build our SEO approaches around these innovations. Answer Engine Optimization (AEO) is making waves, and it’s fascinating to watch how it reshapes our tactics.

    If we want to stay ahead, integrating AI into our SEO strategies isn’t just optional—it’s essential. The landscape is evolving, and so should we.


    Inspired by this post on HiGoodie Blog.


    crushpress.ai community screenshot
  • AI Legal Risk for Business: A Practical Exposure Audit

    AI Legal Risk for Business: A Practical Exposure Audit

    Your AI legal risk probably isn’t sitting in an experimental lab. It’s in ordinary work: a marketer pastes customer information into a model, an editor publishes an unsupported product claim, or a team promises exclusive ownership of material that a machine largely produced.

    You can find much of that exposure before it becomes a dispute. The practical job is to map each AI workflow, identify what enters and leaves it, assign a human decision-maker, and retain enough evidence to explain what happened. This is an operational risk framework, not a legal opinion. If an AI use could affect contractual rights, regulatory duties, intellectual property, or an individual’s interests, have qualified counsel assess the specific facts and jurisdiction.

    Map the workflow, not just the AI tool

    An isometric office scene follows an AI-assisted task from a customer record through generation, editorial review, managerial approval, publication, and evidence storage.

    A list of approved tools is useful, but it isn’t an exposure audit. The same model might be used for harmless brainstorming, confidential document analysis, public product claims, or automated customer responses. Those uses don’t carry the same consequences.

    AI is accelerating familiar legal risks involving intellectual property, privacy, consumer protection, misinformation, and liability. That is good news for your first review: you don’t have to predict an entirely new field of law. You have to locate where AI touches obligations the business already has.

    Build the inventory around use cases. Give each recurring workflow its own row, even when several rows use the same vendor. Record:

    • The team and accountable owner.
    • The business purpose and any decision the output influences.
    • The data, documents, prompts, images, code, or other material sent to the system.
    • Whether inputs contain personal, confidential, licensed, or third-party material.
    • Where the output goes: private notes, an internal system, a client deliverable, a website, JSON-LD, an advertisement, or a customer-facing assistant.
    • The human review required before the output is used.
    • The provider, account type, model or feature used, and relevant retention or training settings.
    • The evidence retained, including sources, revisions, approvals, and important vendor terms.

    That last point matters because AI features change. Recording only the vendor name may not let you reconstruct a decision later. Capture the actual product or feature closely enough that the workflow owner can explain which system handled the information.

    AI workflowExposure to examineEvidence to retain
    Marketing copy, SEO content, and schema markupUnsupported claims, copied expression, unclear ownershipClaim sources, human revisions, reviewer approval
    Customer-facing chatbotIncorrect answers, misleading representations, personal-data handlingApproved answer set, test results, escalation rules, retention decision
    Internal document summarizationPersonal, confidential, or licensed material sent to a providerPermitted data class, access controls, provider settings, deletion terms
    Generated design, image, or codeThird-party rights, license restrictions, protectability, promised ownershipInput provenance, similarity or license checks, material human changes

    Flag a workflow for deeper review when it publishes externally, processes personal or confidential data, makes a consequential recommendation, creates something the business expects to own, or acts without a human approval step. These are screening signals, not legal conclusions. Their purpose is to keep a risky use from disappearing inside a generic label such as “content assistance.”

    Separate input rights, output risk, and ownership

    Teams often compress every intellectual-property question into “Can we use AI for this?” That question is too broad to answer. Break it into three decisions: whether you may submit the input, whether you may use the output, and whether anyone can claim enforceable ownership of the finished work.

    Check the material going into the model

    Permission to read or possess a file does not automatically settle whether it may be uploaded to an external system. A customer brief, licensed image library, unpublished manuscript, source-code repository, or partner document may be governed by a contract, confidentiality term, or access restriction.

    Before submission, identify who supplied the material, what rights the business received, whether the provider may retain or use it, and whether the workflow exposes it to anyone who was not already authorized. If the answer depends on contract language, stop and have counsel interpret that language. Guessing can compromise confidentiality or create a breach that cannot be fixed by deleting the eventual output.

    Inspect the output for third-party material

    A polished answer is not proof of clean provenance. AI output can unintentionally incorporate protected material, creating a practical infringement risk even when the user never requested a copy. Review distinctive text, images, code, characters, slogans, and other recognizable elements before release. For code, inspect dependencies and license implications rather than relying only on a general plagiarism check.

    Give the reviewer the prompt, known source material, and intended channel. Asking whether an output merely “looks original” is too subjective. Ask whether its important elements can be traced, whether suspicious passages require a targeted search, and whether the business could defend its permission to use them.

    Document the human contribution you expect to own

    The U.S. Copyright Office position reflected in the available guidance is that purely AI-generated work is not protected and human creativity must materially shape the work for protection to become possible. Typing a prompt and accepting the first result is therefore a weak foundation for an ownership promise.

    Preserve evidence of the human work that made the final result distinct: the original brief, independently created structure, source selection, rewritten sections, editorial judgments, discarded drafts, compositional decisions, and final approval. The aim isn’t to save meaningless activity. It is to show where a person exercised creative control.

    This distinction belongs in client and contractor workflows. Don’t promise that a customer will receive exclusive, fully protectable rights merely because your contract uses the word “deliverable.” Align the promise with the provider’s terms, third-party licenses, the human contribution, and counsel’s view of the governing law.

    Patent questions need separate treatment. Revised U.S. Patent and Trademark Office guidance has left practical questions about human-conceived inventions developed with AI. If AI materially contributed during invention or development, preserve the chronology and involve patent counsel before making inventorship or filing decisions.

    Treat every public claim as your company’s own statement

    A disclaimer that content was “AI assisted” does not make a false statement accurate. Once your business publishes an output, customers, regulators, partners, and search systems encounter it as a representation made under your brand.

    The dangerous errors are not limited to obvious nonsense. Generative systems can produce invented facts, fabricated citations, and reasoning that sounds coherent but does not support the conclusion. A fluent paragraph can therefore pass an ordinary copy edit while failing a factual review.

    Review claims rather than prose. Maintain a simple claim ledger for externally published material. For each substantive assertion, record:

    • The exact claim a customer will see or reasonably infer.
    • The evidence that supports it, with enough detail for another reviewer to locate that evidence.
    • The product, service, market, audience, and period to which it applies.
    • Important qualifiers that must remain attached to the claim.
    • The person who approved it and the event that should trigger re-review.

    This is especially important for comparisons, rankings, prices, performance statements, testimonials, guarantees, and claims about safety, health, money, or legal outcomes. Those claims warrant specialist review because an error can cause more than a correction or ranking loss.

    SEO and AEO teams should apply the same standard to structured data. A false or stale statement does not become safer because it appears in JSON-LD instead of visible copy. Confirm that product attributes, prices, availability, ratings, organizational facts, author information, and FAQ answers match the page and the underlying business records. If automation updates those fields, assign an owner to the feed and define what happens when the source system and published markup disagree.

    Use a release gate that is proportional to consequence:

    1. Extract each factual and implied claim from the draft.
    2. Verify it against evidence that actually supports the same scope and wording.
    3. Open every citation; don’t accept a plausible title, quotation, or URL without checking it.
    4. Restore necessary qualifiers, limitations, and effective dates that generation or editing removed.
    5. Confirm that the visible page, metadata, schema, advertisement, email, and chatbot answer do not make conflicting representations.
    6. Record the reviewer and approval before publication.

    Keep unverified material out of production. A visible internal status such as “UNVERIFIED – DO NOT PUBLISH” is more reliable than hoping a placeholder citation will be remembered during the final edit. If evidence cannot be found, remove or narrow the claim rather than polishing it.

    Keep personal data out until its handling is defensible

    Privacy exposure begins when information enters the workflow, not when the generated answer is published. Personal data may appear in prompts, uploaded documents, chat histories, feedback, retrieval indexes, output logs, analytics, or support transcripts.

    The regulatory landscape includes frameworks such as the GDPR in the European Union, PIPEDA in Canada, and the CCPA in California. Their requirements differ, so a generic global statement that “we comply with privacy law” is not an operational control. Determine which people, data, activities, and jurisdictions are involved. Have a privacy professional or qualified counsel decide the applicable legal basis and obligations.

    Before approving a workflow involving personal data, require clear answers to these questions:

    • What personal data is required, and can the task be completed with less data?
    • Why is the business using it, and is that use compatible with what the person was told?
    • Does the provider use prompts, files, outputs, or feedback to train or improve its systems?
    • How long are inputs, outputs, logs, backups, and derived data retained?
    • Where is the data processed, who can access it, and which other providers receive it?
    • Can the business locate, correct, export, restrict, or delete the data when required?
    • What security, incident-notification, deletion, and audit commitments appear in the contract?
    • Who owns the response when a customer or regulator asks how the data was handled?

    If the owner cannot answer those questions, don’t send the data yet. Use approved enterprise controls where available, remove unnecessary identifiers, or redesign the workflow around synthetic or non-personal material. Redaction is not automatically anonymization: remaining details may still make someone identifiable when combined. Ask the privacy lead to assess that risk when the data is sensitive or the context is distinctive.

    Separate privacy from confidentiality during the review. A document can contain no personal data and still expose trade secrets, contract-restricted information, security details, or a client’s confidential plans. Conversely, information may be publicly visible yet remain personal data governed by a specific use and jurisdiction. Give each category its own permission rule.

    Prepare a response path before an incident. The workflow owner should know how to pause the use, identify the account and provider involved, preserve necessary evidence without spreading the data further, contact privacy and security personnel, and route rights requests or regulator communications. Once a request or incident exists, don’t improvise deletion or send a casual explanation. Preservation, notification, and response duties can conflict, so counsel should direct the specific response.

    Build controls people can use at the moment of decision

    An employee pauses before entering customer information while a colleague verifies rights, accuracy, privacy, and release controls built into the workstation.

    A long AI policy won’t help if an employee cannot tell whether a customer file is allowed in a particular feature. Convert policy into a small operating system that answers the questions people face while working.

    • An AI use register with a named business owner for every recurring workflow.
    • An approved-tool matrix showing which accounts and features may handle public, internal, confidential, personal, and sensitive material.
    • A review matrix defining who approves public claims, intellectual-property-dependent work, personal-data uses, and consequential decisions.
    • A contract checklist covering provider data use, retention, deletion, security, intellectual property, notice of material changes, responsibility, and liability terms.
    • An evidence pack for each higher-exposure workflow containing the purpose, data decision, test results, human review, source records, and current approval.
    • A reporting route that lets staff pause questionable work without having to prove a legal violation first.

    Assign one accountable owner, but involve the functions that control the underlying risk. Marketing or SEO can own publishing accuracy; privacy can decide data handling; security can assess access and incident controls; procurement can preserve vendor commitments; and counsel can interpret rights, duties, and disputed contract language. “Legal owns AI” is not a workable substitute for operational ownership.

    Test the control with a real workflow. Ask a person unfamiliar with the project to locate the approved tool, permitted data class, required reviewer, evidence record, and stop condition. If those answers live in separate inboxes or depend on knowing whom to ask, the control is not ready for routine use.

    Key takeaways

    • Audit AI by business use, input, output, audience, and decision – not by vendor name alone.
    • For intellectual property, answer three separate questions: may you submit the input, may you use the output, and can you support the ownership being promised?
    • Verify every external claim and citation as a representation made by your company, including claims encoded in metadata and schema.
    • Do not process personal or confidential data until purpose, provider handling, retention, access, deletion, and response ownership are clear.
    • Keep evidence of meaningful human contribution, factual review, permissions, settings, and approval.
    • Escalate uncertain rights, high-consequence uses, incidents, and jurisdiction-specific questions to qualified counsel.

    Know when to stop the workflow

    Pause and obtain specialist advice when a workflow depends on unclear contract rights, sends sensitive or confidential information to an unapproved provider, appears to reproduce distinctive protected material, influences a high-consequence decision, or makes a claim that could materially affect someone’s health, safety, finances, legal position, employment, or access to a service.

    Stop routine handling immediately if you receive a demand letter, rights request, security alert, regulator inquiry, or credible complaint about harmful or misleading output. Don’t destroy records, admit liability, or continue publishing while the facts are unclear. Preserve the relevant evidence and let the appropriate legal, privacy, security, or compliance professional direct the response.

    Start with one live, public-facing AI workflow this week. Map its inputs, claims, data, reviewer, and evidence trail. Fix the first unresolved permission or approval gap before expanding the audit. That single completed workflow will give your team a control pattern it can repeat across the business.

    References

  • Unlock Local Visibility: Harness AI in Local Search Now

    Unlock Local Visibility: Harness AI in Local Search Now

    I recently discovered how AI is revolutionizing the way customers find local businesses. Tools like Google AI Overviews, Gemini, and Ask Maps are paving the way for more detailed, conversational searches.

    It’s clear to me that traditional search rankings are no longer the sole factor in gaining visibility. Ensuring your business details are complete and accurate—like your Google Business Profile, reviews, and local content—can make a big difference.

    I’m excited to join SOCi and Google for an exclusive webinar, Winning the Next Era of Local Visibility, on June 3. It’s a golden opportunity for anyone looking to stay ahead of the curve.

    During this webinar, I look forward to learning:

    • How AI is transforming local search dynamics.
    • The types of signals that AI considers for recommendations.
    • Strategies to boost visibility on Search, Maps, and Gemini.
    • The implications of Ask Maps for your brand.

    I’m convinced that AI is already shaping customer discovery, so it’s crucial to ensure your business isn’t left behind.

    Register now to secure your spot.


    Inspired by this post on Search Engine Land.


    crushpress.ai community screenshot
  • Google’s UCP Checkout Revolutionizes Search Shopping

    Google’s UCP Checkout Revolutionizes Search Shopping

    I find it fascinating that Google’s Universal Commerce Protocol (UCP), which was initially limited to AI Mode, is now expanding into regular search results. It’s not just a fleeting trend; some retailers have already begun integrating this technology into their listing pages, making our online shopping experience even more intuitive.

    Earlier this year, Google rolled out UCP for AI-agents to facilitate direct purchases from search results. It first launched exclusively within Google’s AI Mode but now, we’re seeing it implemented in Google’s main search results for retailers who support UCP.

    Discovering what the UCP checkout looks like was made easier thanks to a post by Brodie Clark. He shared a screenshot showing how Wayfair’s listings on Google Search now feature a UCP-powered ‘Buy’ button. This button is a game-changer because it allows purchases directly from Google’s interface without navigating to Wayfair’s website.

    The UCP protocol is paving the way for seamless transactions by establishing a common language for AI agents and commerce systems. No longer do we have to worry about bespoke integrations across different platforms.

    ```json
{
  "alt": "Google search results for striped bed sheet set, featuring various sheet options and prices.",
  "caption": "Exploring online options for striped bed sheet sets? Check out this search showcasing a variety of styles and prices to suit every bedroom decor.",
  "description": "This image shows a Google search result page for 'striped bed sheet set'. Various bed sheets including options from Wayfair, IKEA, and Eddie Bauer are displayed, with prices ranging from $15.99 to $239.00. A highlighted product is the 100% Cotton Sateen Striped Sheet Set from Wayfair in black. The image also features browser and interface elements like search tabs and filters, ideal for navigating online shopping efficiently. Keywords: striped bed sheets, Google search, online shopping, sheet set prices."
}
```

    Collaboratively developed with big names like Shopify, Etsy, Wayfair, and Target, UCP aligns with existing standards, such as Agent2Agent and Agent Payments Protocols, creating a more cohesive digital commerce space.

    What really excites me is the potential for profit growth for retailers who embrace this technology. Although Wayfair might miss out on direct site traffic for specific searches, their affiliation with Google through UCP can still result in conversions.

    While it’s clear that not everyone will bypass the traditional shopping journey, as many of us still prefer exploring products on the retailer’s site, the option to ‘Buy’ directly adds a layer of convenience. It’s definitely something worth monitoring as its prevalence in search results increases.


    Inspired by this post on Search Engine Land.


    crushpress.ai community screenshot
  • Stay Updated: AI Transforming Healthcare Innovations

    Stay Updated: AI Transforming Healthcare Innovations

    As someone passionate about the convergence of AI and healthcare, I’m thrilled to share monthly updates from the Goodie team. We dive into the latest breakthroughs and trends in artificial intelligence and the medical field. It’s all here, waiting for you to explore.


    Inspired by this post on HiGoodie Blog.


    crushpress.ai community screenshot
  • End of an Era: Ask.com Closes After 25 Years

    End of an Era: Ask.com Closes After 25 Years

    As someone who has been on the internet exploration journey for years, today’s news hits home. Ask.com, which many of us fondly remember as Ask Jeeves, officially closed down on May 1, 2026, after a remarkable 29 years of service. It launched on June 3, 1996, even before Google made its debut.

    Upon visiting the now-closed Ask.com, we are greeted with a heartfelt farewell message that feels like a trip down memory lane:

    Every great search must come to an end. As IAC continues to sharpen its focus, we have made the decision to discontinue our search business, which includes Ask.com. After 25 years of answering the world’s questions, Ask.com officially closed on May 1, 2026.

    I can’t help but feel gratitude as they graciously acknowledge, “To the millions who asked…”. They expressed appreciation for the brilliant engineers and loyal users who have been a crucial part of their journey. And yes, Jeeves’ spirit indeed lives on.

    ```json
{
  "alt": "Ask.com closure announcement stating closure on May 1, 2026, after 25 years.",
  "caption": "After 25 years of service, Ask.com bids farewell as it officially closes on May 1, 2026. A heartfelt thanks to users and contributors.",
  "description": "This image is an announcement of Ask.com's closure, effective May 1, 2026. The notice expresses gratitude to its users and contributors over the past 25 years. It highlights the decision to discontinue the search business as IAC refocuses its objectives. The statement is accompanied by an inscription about the enduring legacy of Jeeves and conveys appreciation for the community's curiosity and trust."
}
```

    For those of us who relied on this answer engine in its early days, Ask.com and the iconic Jeeves butler will always hold a special place. In a world now dominated by AI and competitive answer engines, it’s understandable why IAC, the parent company, decided to step back in such a challenging market.

    Ask.com has left a significant impact on the search marketing industry, and saying goodbye is indeed bittersweet. Until we meet again in some digital form, dear Jeeves.


    Inspired by this post on Search Engine Land.


    crushpress.ai community screenshot
  • Embracing AI in PPC: Ginny Marvin’s Evolution in Search

    Embracing AI in PPC: Ginny Marvin’s Evolution in Search

    I find it quite fascinating how the world of search has transformed over the years from manual PPC efforts to AI-driven systems. Reflecting on Ginny Marvin’s journey offers a glimpse into these dynamic changes and underscores the importance of staying curious and adaptable as marketers.

    My journey into PPC wasn’t fueled by a master plan but rather by a desire to reinvent myself professionally. Transitioning from print publishing and advertising sales, I found myself at a crossroads when the startup magazine I had helped establish ceased operations. That pivotal moment pushed me towards digital marketing, starting from entry level.

    Starting fresh meant embracing the unknown. As Marvin put it, she didn’t know what she was doing initially, which makes her story relatable for anyone starting anew. This fresh start paved her path into search marketing, eventually leading her to significant roles at Search Engine Land and Google as the Google Ads Liaison.

    During our interview, Marvin shared insights into the evolution of paid search, highlighting common misconceptions marketers still hold, and emphasized how the next era of search will value curiosity over control.

    Interestingly, PPC clicked for me faster than SEO. My initial foray into the industry was through SEO at a small agency, but I quickly discovered my passion when the paid search manager took a vacation, and I temporarily managed the campaigns. This experience showed me the power of PPC’s speed and measurability, especially coming from a print background where results were slow and uncertain.

    Marvin observed that Google’s clear focus and rapid iteration were key to outpacing competitors like Yahoo and Microsoft. Google’s relentless enhancement of its offerings to align with advertiser needs set it apart and solidified its leadership in the industry.

    I remember the early days of PPC being a manual slog full of exhaustive keyword lists and precision-targeted campaign strategies. We spent hours meticulously crafting keyword combinations, but today’s campaigns are more sophisticated and goal-oriented, aligning more naturally with business objectives rather than conforming to platform constraints.

    When Search Engine Land was in its infancy, Marvin was also establishing her footprint in the search field. The platform quickly became essential for industry news, insights, and expert analyses, fostering professional growth by making information accessible.

    One standout characteristic of the search community, as Marvin noted, is its openness to sharing and collaboration. People have always been generous about sharing their experiments, successes, and failures, recognizing that ongoing learning benefits everyone. This spirit of community has been a cornerstone in my own career development.

    Regarding AI, Marvin asserts that it’s not as novel as many perceive. Although the rapid advancements fueled by large language models seem sudden, machine learning has been embedded in systems like Google Ads for years, refining aspects like Smart Bidding and close variants.

    The real shift lies in consumer behavior, where search patterns have become increasingly complex and diverse. With people using images, voice, and multimodal inputs, modern search engines understand intent beyond simple keywords, necessitating a comprehensive view of the customer journey.

    Despite all these changes, the essence of search success remains tied to business results. What’s different now is the enhanced ability to accurately measure outcomes and align campaign activities with strategic business goals, highlighting the critical role of data and first-party signals.

    Looking ahead, Marvin champions curiosity as the trait that will define successful marketers over the next two decades. Adaptability, understanding customer behavior, and proactively learning new technologies like AI will keep marketers ahead of the curve.

    Marvin candidly remarks that while PPC marketers often claim to embrace change, they can be resistant when major shifts occur. Her advice is to adopt a long-term perspective because seemingly abrupt changes often have deep-seated, gradual developments.

    Experimentation is key, according to Marvin. Even if a new feature doesn’t yield immediate success, dismissing it entirely could be shortsighted. As platforms and capabilities evolve rapidly, what didn’t work before might succeed now, and clinging to outdated methods could hinder progress in the evolving search landscape.

    Reflecting on her career, Marvin expressed pride in the resilient and collaborative nature of the search community. Her contributions at Search Engine Land and Google have always been geared towards fostering an informed and empowered marketing community. To her, “by marketers, for marketers” is more than a motto; it’s a driving mission.


    Inspired by this post on Search Engine Land.


    crushpress.ai community screenshot
  • Discover How OpenAI is Revolutionizing Ads with ChatGPT CPC

    Discover How OpenAI is Revolutionizing Ads with ChatGPT CPC

    Have you heard the news that OpenAI has introduced CPC ads to ChatGPT? This strategic shift has transformed it into a performance-driven channel, offering advertisers new avenues for engaging intent-driven audiences and tracking ROI.

    OpenAI is moving away from a focus purely on impressions in ChatGPT to prioritize performance. This change places OpenAI in direct competition with giants like Google by adopting cost-per-click (CPC) ads, allowing advertisers to pay only when users click on their ads.

    What’s happening? OpenAI has started testing CPC ads within ChatGPT, where advertisers only pay when their ads receive clicks. Initial reports highlight that these clicks are priced between $3 to $5. They’re rolling out this feature through a limited ads manager, alongside their existing CPM-based model.

    Why now? The main catalyst seems to be pricing pressure. Since its launch, ChatGPT’s CPMs have significantly decreased from around $60 to approximately $25. Switching to CPC helps mitigate this decline by connecting revenue to tangible outcomes rather than mere impressions.

    Why do we care? With its evolution into a performance channel, ChatGPT is now not just a branding space. The CPC pricing model makes it easier for us to connect budgets directly to measurable actions, test ROI, and compare these results with channels like Google Search.

    I’m excited about the opportunity for advertisers to access what could be a high-intent audience in a new format. This presents a first-mover advantage before competition—and the associated costs—escalate.

    The bigger picture: This isn’t just a pricing change; it’s a strategic pivot. By embracing CPC advertising, OpenAI challenges Google’s dominance in the market, thereby positioning ChatGPT as a contender for performance marketing budgets.

    Reading between the lines: A major challenge lies in proving user intent. While search advertising is effective because it captures users actively searching for something, ChatGPT’s conversational context needs to generate clicks with equal value. Advertisers will likely compare these results directly with Google, setting a high standard for quality and conversion.

    Zoom out: Advertising is becoming integral to OpenAI’s long-term revenue plan, supported by investments in ad infrastructure, measurement tools, and a wider self-serve platform.

    Bottom line: By implementing CPC ads, OpenAI is vying for the performance-driven ad dollars that have long supported traditional search platforms.


    Inspired by this post on Search Engine Land.


    crushpress.ai community screenshot
  • Best-of-N AI Jailbreaking: Risks and Defensive Controls

    Best-of-N AI Jailbreaking: Risks and Defensive Controls

    You may have watched your AI assistant reject an unsafe request and concluded that its safeguards worked. If you tested only once, you answered the wrong question. An attacker does not need every prompt to succeed. They need one useful failure after enough retries.

    Best-of-N jailbreaking turns that model variability into a search process. To manage the risk, you need to evaluate the whole campaign, enforce permissions outside the model, and control every additional chance created by retries, fallback models, tools, and automated agents.

    The dangerous unit is the campaign, not the prompt

    A Best-of-N attack creates or collects multiple versions of a prohibited request, submits them to an AI system, and selects the response that comes closest to the intended outcome. The essential move is to send many variations and keep the most successful result. The value of N is not fixed, and the selection can be performed by a person, a script, or another model.

    This changes the security question. A per-request review asks, “Did this prompt get blocked?” A campaign-level review asks, “Did any related attempt produce a prohibited result?” The second question reflects the attacker’s objective.

    The probability principle is straightforward. If each attempt has a nonzero chance of crossing a boundary, repeated opportunities can raise the chance that at least one attempt succeeds. Under the simplified assumption that attempts are independent and have the same success probability p, the probability of any success after N attempts is 1 – (1 – p)^N. Real prompt variants are often correlated, so you should not use that formula as a production risk estimate. Measure complete campaigns against your actual system instead.

    Three distinctions prevent confusion during threat modeling:

    • A normal retry is usually an attempt to clarify a legitimate request after an incomplete or incorrect answer. Repetition alone does not establish malicious intent.
    • A jailbreak tries to bypass behavioral restrictions placed on a model.
    • Prompt injection supplies untrusted instructions that compete with the system’s intended instructions, often through user input or retrieved content. Best-of-N is a search strategy that can amplify jailbreaks, prompt injection, or other policy-evasion techniques.

    Treat Best-of-N as a threat multiplier, not as the root vulnerability. It finds inconsistent decisions and weak handoffs. It cannot grant a caller a permission that your application enforces deterministically outside the model. That is why authorization architecture matters more than clever safety wording.

    Where repeated attempts find extra chances

    An isometric AI network branches into retry loops, fallback nodes, tools, memory, and agent pathways carrying repeated request signals.

    Your model is only one part of the attack surface. A typical AI workflow also has an identity layer, input filters, a router, one or more models, output checks, retrieval, tools, and application code. Every component that makes a fresh probabilistic decision can give a campaign another route to success.

    LayerMisleading green lightCampaign signal to inspectStronger control
    Prompt policyOne prohibited request was refusedRelated requests are repeatedly rephrased after denialsAggregate policy events by actor, session, intent cluster, and protected resource
    Input moderationEach prompt remains below an individual alert thresholdSmall wording, format, language, or encoding changes accumulate around the same objectiveAnalyze normalized forms and sequences while retaining the raw input for investigation
    Model routingThe primary model refusedA fallback model, alternate endpoint, or retry path returned a different decisionApply one canonical policy before routing and a final gate after generation
    Tools and agentsThe assistant’s visible text looks harmlessA tool call requests a broader scope, sensitive record, or irreversible actionEnforce authorization, parameter validation, and action limits in application code
    Traffic controlsEach IP address or API key stays within its local limitRelated attempts move across sessions, keys, endpoints, or modelsCorrelate only the identifiers justified by your threat model, privacy obligations, and retention policy
    LoggingEvery prompt was stored somewhereNo record connects attempts, decisions, tool calls, and final outcomesAssign campaign and event identifiers so an investigation can reconstruct the sequence

    For an SEO, AEO, or GEO workflow, the highest-consequence result may not be a bad chat response. It may be an unauthorized CMS publication, a destructive edit, exposure of an unpublished campaign, or a tool call made with the application’s credentials. If a model generates page copy or JSON-LD, syntactic validation is necessary but insufficient. Valid structured data can still contain false, disallowed, or unapproved claims. Check the output against business rules and publishing permissions before it reaches a live page.

    Build controls that survive repeated attempts

    A request signal passes through layered security gates before reaching an AI core and protected tool mechanisms.

    No safety prompt can carry this responsibility alone. Prompts influence model behavior, but they are not security boundaries. Use several controls with different failure modes, and place deterministic checks wherever failure could expose data, spend money, alter content, or trigger an external action.

    1. Put authorization outside the model. Resolve the authenticated principal in application code, grant the least privilege needed for the workflow, and verify permission again when a tool executes. Never let generated text decide whether the caller may read, publish, delete, or export something.
    2. Separate read and write capabilities. An assistant that only needs to draft content should not inherit publishing or deletion rights. When write access is required, constrain the allowed resource, action, fields, and destination.
    3. Normalize for analysis without overwriting evidence. Retain the original request, then create a canonical representation for similarity detection. Normalization can help reveal superficial changes in spacing, character representation, formatting, or casing, but it must not silently change the content executed by downstream systems.
    4. Maintain campaign state. Record the actor or service identity, session, endpoint, model route, normalized intent cluster, policy decision, tool request, and outcome. Look for repeated denials, rapid reformulations, alternate-route probing, and requests that converge on the same protected capability.
    5. Add adaptive friction. As campaign risk rises, reduce retry opportunities, disable expensive fallback routes, introduce a cooldown, require stronger authentication, or move the request to human review. Apply the strongest friction to workflows with data access or irreversible effects rather than imposing the same response on harmless drafting tasks.
    6. Gate outputs and tool calls separately. Check generated content against the output policy, validate structured fields, reject unexpected tool names or parameters, and limit the records or resources returned. A harmless-looking explanation must not conceal a disallowed action request.
    7. Define safe failure behavior. If moderation, identity resolution, authorization, or final validation is unavailable, return a controlled error for protected operations. Do not route around a failed safeguard to preserve a smooth user experience.
    8. Protect the control plane. Restrict who can change system prompts, policy rules, model routes, tool definitions, and safety thresholds. Log those changes and make rollbacks possible, because a campaign can exploit configuration drift as readily as model variability.

    There is no universal safe retry count. A blanket limit low enough for a sensitive data-export agent may be needlessly hostile in a public brainstorming tool. Set budgets by consequence, then examine legitimate retry behavior before choosing enforcement thresholds. Track false positives alongside security outcomes so that users who are clarifying ambiguous, multilingual, or accessibility-related requests are not treated automatically as attackers.

    Be careful with model-based safety judges as well. A second model can add useful evidence, but it may share blind spots with the model it evaluates. Use deterministic authorization and validation for hard boundaries, with model judgments contributing to risk scoring rather than granting privileged access on their own.

    Test the full campaign without publishing an exploit kit

    A single-prompt red-team check will miss the defining behavior of Best-of-N. Your evaluation runner should group related attempts, preserve production routing logic, and score whether any attempt reaches a prohibited outcome. Keep testing authorized, isolated, and away from live customer data or publishing systems.

    1. Define the breach before generating tests. Describe prohibited outcomes in observable terms, such as returning a protected field, invoking a disallowed tool, publishing without approval, or producing content that violates a named policy. A vague label such as “unsafe response” produces inconsistent scoring.
    2. Build campaign families. Group sanitized test cases by underlying objective, then vary the permitted dimensions relevant to your system, such as phrasing, format, language, model route, and retry sequence. Keep actionable attack strings in an access-controlled security repository rather than general documentation or analytics dashboards.
    3. Reproduce the production topology. Include the actual order of input checks, retrieval, routing, fallback behavior, output gates, tools, and error handling. Testing the base model alone does not test the application your users can reach.
    4. Run attempts as connected sequences. Carry session and risk state between related requests. Also test whether switching endpoints or invoking an automated agent incorrectly resets that state.
    5. Score outcomes at two levels. Retain per-request decisions for diagnosis, but make campaign-level success the headline measure. A system can have an impressive individual refusal rate while still allowing too many campaigns to obtain one useful failure.
    6. Review the most consequential path first. A policy-breaching paragraph matters, but a tool call that exposes private data or changes a live site demands tighter controls and faster remediation.
    7. Version the evaluation and rerun it after changes. A new model, system prompt, router, retrieval source, guardrail, tool definition, or fallback rule can alter campaign behavior even when the visible feature appears unchanged.

    Your evaluation dashboard should include the campaign any-success rate, attempts to the first breach, breach severity, detection and containment outcomes, tool or data-boundary violations, and false-positive friction for legitimate users. Do not collapse these into one average. A small number of severe authorization failures should remain visible rather than being diluted by many harmless refusals.

    Stop a test immediately if it begins interacting with real user records, external recipients, paid services, or live publishing. Move the scenario into an isolated environment with synthetic data and inert tools. The purpose of the exercise is to verify containment, not to prove that production damage is possible.

    Key takeaways for AI product owners

    • One successful refusal does not establish safety; measure whether any attempt in a related campaign succeeds.
    • Best-of-N exploits repeated opportunities and inconsistent decisions, so retries, fallback models, alternate endpoints, and agents all belong in the threat model.
    • System prompts and model-based judges can support safety, but they cannot replace deterministic authentication, authorization, validation, and tool restrictions.
    • Aggregate related attempts without assuming every retry is malicious; calibrate friction to the consequence of the requested capability.
    • Test the production workflow as a sequence, then report campaign-level success and breach severity alongside per-request refusal metrics.
    • Keep security payloads controlled, use synthetic data and inert tools, and never red-team an external or production system without authorization.

    Before your next release, choose the AI workflow with the greatest access to data, tools, or publishing. Trace every place where a rejected request can receive another model call or another route. Then add campaign-level telemetry and a deterministic gate at the highest-consequence handoff.

    That review will not eliminate model variability. It will prevent variability from becoming permission.

    References


  • Evading AI’s ‘Bland Tax’: How to Maintain Brand Visibility

    Evading AI’s ‘Bland Tax’: How to Maintain Brand Visibility

    When I think about brand visibility today, it’s clear that being chosen by AI systems is crucial. Authority, unique insights, and consistent signals now determine if my brand makes the cut.

    I’ve realized that AI isn’t just reshaping search; it’s deciding which brands are seen and which are ignored.

    I learned from Andrew Warden, CMO of Semrush, at the Adobe Summit that visibility is evolving fundamentally, and our brands risk being systematically filtered out by AI systems.

    “The idea of standing out is no longer optional. There’s a real risk of sameness,” he pointed out.

    With AI systems deciding what to highlight and what to ignore, I know I must compete more fiercely for visibility in AI-generated answers.

    AI is Changing How Discovery Works

    The change is evident in the data: 60% of Google searches now end without a click to a website. People are still seeking information but aren’t always visiting websites. They’re getting their answers directly from AI systems like Google AI Overviews and ChatGPT.

    These AI systems have become, as Warden described, the “new gatekeepers.”

    This shift ushers us into the agentic era, where AI systems act as intermediaries, guiding users from inquiry to decision in one seamless interface.

    Meanwhile, user behavior is evolving. People engage more in conversational environments, posing follow-up questions, refining queries, and surveying options within the interface, all resulting in fewer clicks but often attracting higher-intent users.

    Warden noted that consumers using LLMs convert at least four times higher than those relying solely on search.

    SEO is the Foundation

    Despite some claims that AI could replace search, Warden reassured us that SEO is not dead.

    SEO has become more foundational than ever. It’s essential to ensure my brand exists in the data layer AI systems rely on.

    Warden emphasized, “SEO isn’t just for humans anymore. This is a training manual for AI right now.”

    This involves ensuring:

    • Crawlability
    • Indexability
    • Structured data
    • Authority signals

    Without these, my brand won’t appear at all.

    Research backs this up: 94% of Google AI Overviews cite at least one top organic result, reaffirming that traditional search signals still support AI outcomes.

    The Rise of the ‘Bland Tax’

    One striking concept from the session was what Warden dubbed the “bland tax.”

    AI conditions itself to overlook blandness, causing generic or repetitive content to vanish.

    If I’m generic, Warden warned I’m perceived as average, and if I’m bland, I’m effectively invisible.

    AI systems don’t reward sameness. Rather than highlighting my brand, they often condense similar content into a single, attribution-lacking response.

    “This is an invisible penalty,” Warden noted.

    The consequences manifest in several ways:

    • My brand identity gets erased in AI-generated summaries
    • My content is filtered out as low-value
    • My work becomes training data for AI without offering visibility to my brand

    “You also become a free training ground for LLMs,” he said.

    What Visibility Depends On

    Warden redefined brand visibility as a blend of:

    • Discoverability: Can LLMs easily find me?
    • Authority: Do they trust my brand enough to include it?

    “You absolutely need both,” Warden asserted.

    SEO ensures I’m discoverable. Authority determines whether my brand shows up in AI-generated responses.

    Without authority, I risk turning into a “commodity that isn’t worth being mentioned.”

    How to Win: Three Key Signals

    Warden outlined three crucial areas determining whether my brand appears or gets filtered out:

    1. Entity Authority

    AI systems map entities and relationships, and they must recognize my brand as an authority on a topic.

    One key signal is brand demand. If people aren’t seeking out my brand, neither will AI.

    Strong brands emphasize their authority across various platforms—owned content, media exposure, and community discussions—demonstrating their niche.

    2. Information Density and Originality

    AI systems prioritize content that offers new insights. It’s vital to not just publish content but contribute something meaningful.

    They emphasize new facts with proprietary data, original research, unique perspectives, and expert insights.

    According to Warden, original insights can enhance visibility by 30 to 40%.

    3. Signal Alignment

    AI evaluates not just what I convey but also what others say about my brand.

    This includes reviews, discussions on platforms like Reddit and YouTube, media mentions, and customer conversations.

    Warden warned that conflicting signals could prompt AI to flag my brand as unreliable.

    Consistency across these channels creates what he called a “consensus signal” that AI systems can trust.

    Why Most Organizations Aren’t Ready

    One of our biggest challenges is organizational, as visibility isn’t just a channel issue; it’s an organizational one.

    Currently, responsibilities are fragmented. SEO teams focus solely on rankings, PR and brand teams manage messaging, and growth teams conduct experiments. This leaves no one clearly owning AI visibility.

    This fragmentation leads to inconsistent signals and missed opportunities for us.

    To truly compete, we need alignment across teams, working on a shared strategy about how my brand appears wherever LLMs gather data.

    The Measurement Problem

    Meanwhile, traditional performance metrics are unraveling.

    Many marketers, including myself, notice a gap where rankings hold steady, but traffic declines. Meanwhile, leads might increase, yet attribution remains murky.

    Warden explained that demand remains, but traffic no longer serves as its proxy. Our content is utilized, but not in ways directing users back to us.

    This creates a growing disparity between impact and the ability to measure that impact accurately.

    From Rankings to Relevance

    The nature of competition has evolved. I’m no longer vying for a mere position; instead, I’m competing to be featured in a synthesized AI answer.

    Authority, once easier to influence, now hinges on external validation—emphasizing what others say over what I publish.

    Algorithms have shifted from being my allies to arbiters of meaning, marking a significant change in search dynamics since Google itself emerged.

    The New Rules of Brand Visibility

    AI has not altered what makes a brand strong but has transformed how that strength is measured and rewarded. The brands that win today will build real authority in a focused niche, publish original and high-value content, and ensure consistent messaging across every platform.

    The need for consistent third-party validation across an ecosystem is paramount.

    As Warden urged, I must make it impossible for LLMs to ignore my brand.


    Inspired by this post on Search Engine Land.


    crushpress.ai community screenshot