Tag: Compliance

  • Healthcare AI Search Visibility: A Practical AEO Plan

    Healthcare AI Search Visibility: A Practical AEO Plan

    Your health system may rank well for a service and still be absent when a prospective patient asks an AI assistant where to go, who provides the service or what happens next. Adding another FAQ block does not, by itself, close that gap. Your pages must be easy to retrieve, unambiguous about people and places, and safe enough to reuse in a health-related answer.

    The practical goal is to make accurate passages and verified organizational facts available at the moment an AI system needs them. That is how you work toward earning AI citations and patient recommendations without turning medical content into promotional copy.

    Key takeaways

    • Organize the work around patient questions and decisions, not a list of high-volume keywords.
    • Give each important fact one authoritative home, then keep supporting pages and external profiles consistent with it.
    • Write answer-ready passages that preserve clinical qualifiers, geographic limits, eligibility rules and clear next steps.
    • Use structured data to clarify entities and relationships, not to repeat keywords or make claims that visitors cannot see.
    • Measure citations, factual accuracy and entity matching with a fixed prompt set; referral traffic alone cannot show whether an AI answer represented you correctly.

    Start with the patient decision, not the keyword

    A keyword list tells you what people type. It does not tell you which decision they are trying to make or which fact an AI answer must retrieve. Start with a specific service line and map the questions that affect discovery, access and preparation.

    Your question inventory should include the language a patient or caregiver would actually use. Useful patterns include:

    • Does this organization provide the service I need?
    • Which location provides it?
    • Which department or type of specialist handles it?
    • Is a referral or prior step required?
    • Who is eligible, and what important exceptions apply?
    • How do I prepare for an appointment or procedure?
    • What should I expect afterward?
    • How do I schedule, call or find the correct location?
    • Which concerns require advice from a clinician or urgent assistance?

    Do not answer these from the search team’s memory. Turn the inventory into a working sheet with one row per question and fields for the responsible department, approved answer, canonical page, geographic scope, clinical reviewer, review trigger, risk level and intended next action. A blank field is a useful finding: it shows that the organization has not yet established an answer that a person or machine can reliably use.

    Then assign each question one authoritative destination. If referral requirements appear differently on a physician profile, a service page and a location page, polishing all three versions creates three polished conflicts. Decide which page owns the fact. Supporting pages should summarize it consistently and link to the canonical explanation.

    Prioritize gaps by consequence. A missing parking detail is inconvenient. An outdated location, an incorrect eligibility statement or ambiguous urgent-care language can interfere with access or safety. Fix the facts with the greatest patient impact before expanding into broader educational coverage.

    Make each answer quotable without making it unsafe

    A clinician and content specialist review an abstract answer card alongside source and safety verification symbols.

    An answer-ready passage is not merely short. It is self-contained enough to survive extraction from the surrounding page. A reader should still know who the answer concerns, where it applies, what the limits are and what to do next.

    Use this test on every passage that answers an important patient question:

    • Does the first sentence answer the question directly?
    • Does it name the facility, department, service or population instead of relying on vague words such as “we,” “here” or “this treatment”?
    • Does it retain eligibility conditions, geographic limits and meaningful exceptions?
    • Does it distinguish general education from advice for an individual patient?
    • Does it identify a safe next action, such as contacting the relevant department or consulting an appropriate licensed professional?
    • Can an editor identify who approved the claim and what event should trigger a new review?

    Compare “We offer this treatment at several locations” with a more usable template: “The [named department] provides [named service] for [defined population] at [named locations], subject to [referral, eligibility or scheduling conditions].” The second version carries its context with it. Populate that template only with verified facts from the responsible operational and clinical owners.

    Do not remove a medical qualifier to make a sentence sound more decisive. Content about symptoms, diagnosis, medication, procedure eligibility, recovery or emergency thresholds needs clinical review. If a general page cannot safely resolve an individual situation, say that plainly and direct the person to the appropriate type of licensed professional or emergency resource. Search visibility is not a substitute for medical assessment.

    Separate three content layers that are often mixed together:

    • Stable organizational facts: official names, locations, departments, contact routes and service relationships.
    • Operational facts: availability, referral processes, scheduling instructions and other details that may change when workflows change.
    • Clinical information: benefits, limitations, eligibility, preparation, recovery and safety information that requires clinical ownership.

    Give each layer an appropriate review trigger. A clinician leaving, a location closing, a service moving or a referral process changing should prompt an update even if the page has not reached its routine review date. The date displayed on a page is not evidence of freshness unless someone is accountable for the facts behind it.

    Build an entity layer that removes avoidable ambiguity

    An isometric healthcare campus network connects a hospital with clinics, clinicians, services and locations.

    A health system is not one entity. It may contain a parent organization, hospitals, clinics, departments, physicians, service lines and locations with similar names. Your site should make those relationships explicit so that a machine does not have to infer whether two pages describe the same facility or two different ones.

    Create a canonical entity record for every organization, location, department and clinician you publish. At minimum, settle the official name, approved alternate names, canonical URL, organizational parent, physical location, contact route and the services or roles genuinely associated with that entity. Use the same record to inform page copy, navigation, internal links, directories and structured data.

    For JSON-LD, choose the most specific valid Schema.org type supported by the visible page, such as Hospital, MedicalClinic, MedicalOrganization or Physician. Give each entity a stable identifier, reuse that identifier wherever the same entity appears, and connect related entities instead of creating isolated markup fragments.

    • A physician page should identify the person and connect that person to the correct organization, department or location where the relationship is supported.
    • A location page should describe that location, not silently inherit every service offered anywhere in the health system.
    • A service page should name the organization and locations that actually provide the service.
    • Structured data should match visible, current content. Do not add claims, ratings, specialties or service availability that a visitor cannot verify on the page.
    • Validate both the JSON-LD syntax and the rendered page after publishing. A valid block in a content-management field is not useful if a template, script or deployment process removes it from the delivered page.

    Structured data can reduce ambiguity; it cannot guarantee an AI citation or turn a weak claim into reliable evidence. Treat it as an entity-control layer that supports clear content, not as a separate ranking campaign.

    Check the external records you can correct as well. Compare your canonical entity data with map listings, professional profiles, major directories and other trusted surfaces relevant to the organization. Record discrepancies by field rather than writing “listing inconsistent” in an audit. “Old phone number on profile X” gives someone a concrete correction to make.

    Measure retrieval, citation and accuracy separately

    Analytics can show visits that reach your site. They cannot show every answer in which your organization was omitted, confused with another provider or described inaccurately. You need a controlled prompt set in addition to web analytics.

    Build that set from the question inventory. Include discovery questions, location questions, access questions and questions about the service itself. Keep the wording stable enough to compare runs. For every test, record the exact prompt, AI product or model, date, relevant location or account context, response, cited URLs and screenshots or saved output where permitted.

    Classify each result before choosing a fix:

    • Not retrieved: your organization and pages do not appear in the answer or citations.
    • Wrong entity: the response blends two locations, clinicians or organizations.
    • Retrieved but not selected: your page appears relevant to the question, but the final answer relies on another source.
    • Cited but inaccurate: the response cites your domain while stating a fact incorrectly or without a necessary qualifier.
    • Accurate but incomplete: the response gets the core fact right but omits the information required to act safely.
    • Actionable and supported: the response is accurate, preserves essential limits, points to an appropriate next step and cites a relevant page.

    These labels stop the team from prescribing the same remedy for every failure. A wrong-entity result calls for clearer naming, relationships and identifiers. An accurate but incomplete answer calls for a better passage. A citation to an outdated page calls for consolidation, correction or deprecation of the stale URL.

    Track a small group of interpretable measures:

    • Citation coverage: tracked prompts that cite an approved page divided by eligible prompts tested.
    • Accurate-answer rate: reviewed responses that pass your factual checklist divided by all reviewed responses.
    • Entity-match rate: responses that connect the correct organization, location and clinician or department divided by responses where those relationships matter.
    • Owned-source rate: answers citing a controlled organizational domain divided by answers containing any citations.
    • Correction latency: the time between finding a material error and correcting the responsible page or data record.

    Define the checklist before reviewing results. Otherwise, the standard tends to move when a prominent brand mention looks encouraging. A mention is not a success if the location is wrong, the service is unavailable there or the wording drops a clinically important limitation.

    Turn the audit into a controlled publishing workflow

    Do not begin with a sitewide rewrite. Choose one service line where the facts can be verified and where an inaccurate answer would have a meaningful patient or operational consequence. Then move through the work in a fixed order:

    1. List the real patient questions and assign each one an accountable answer owner.
    2. Run a baseline prompt set and save the responses, citations and entity errors.
    3. Resolve conflicts in names, locations, service availability, access requirements and contact routes.
    4. Give each important answer a canonical page and rewrite its key passage so it remains accurate when extracted.
    5. Connect people, facilities, departments and services through navigation, internal links and valid structured data.
    6. Complete clinical, operational and compliance review according to the risk of the claim.
    7. Publish the changes with a change log that identifies what changed, where and why.
    8. Run the same prompts again under comparable conditions and classify the results with the same checklist.
    9. Move the verified facts and reusable patterns into the next service line only after the workflow itself is working.

    Assign four forms of ownership even if one person fills more than one role: a content owner for the page, a clinical or operational owner for the claim, an entity-data owner for names and relationships, and a measurement owner for the prompt set. Without named ownership, a visibility problem can sit between SEO, clinical, compliance and web teams while each group assumes another one is handling it.

    Do not claim causation from one changed response. AI outputs can vary, and multiple web changes may occur between tests. Keep the prompt and review criteria stable, log every material site change, and look for repeated improvement before treating an intervention as proven.

    Start with one service line, one verified entity record and the questions that most affect a patient’s next step. When those answers are accurate, extractable and properly connected, you have a repeatable operating model for healthcare AI visibility rather than a collection of speculative optimizations.

    References


  • YouTube Masthead Access for Online Gambling Advertisers

    YouTube Masthead Access for Online Gambling Advertisers

    Your gambling licence alone does not unlock YouTube’s most prominent advertising placement. Starting October 21, 2026, Google will extend YouTube Masthead eligibility to more certified online gambling advertisers, but access will still depend on the product, jurisdiction, registration rules, certification scope, and campaign controls.

    If you’re planning a Masthead campaign, qualify the exact product-market combination before you commit the budget or build the creative. The policy change creates an opportunity, not an automatic approval.

    The change opens one premium placement, not the whole platform

    YouTube’s Masthead requirements already permit sports betting advertising. The October change expands eligibility to additional forms of online gambling advertising, provided the advertiser holds the relevant Google Ads certification and satisfies the applicable legal restrictions.

    That distinction matters. Masthead eligibility, Google Ads certification, and campaign approval are related, but they aren’t interchangeable:

    • Eligibility means your type of gambling business may be considered for the placement.
    • Certification means Google has approved you to advertise the relevant gambling category in the jurisdictions covered by that certification.
    • Campaign approval means the specific account, targeting, creative, destination, and other campaign elements satisfy Google’s applicable policies.

    Passing one stage does not guarantee the next. A certified advertiser can still submit a campaign that falls outside its approved geography, reaches an impermissible age group, or conflicts with another Google advertising policy.

    Use this four-gate test before treating your brand as eligible

    An advertiser passes through four gates symbolizing licensing, jurisdiction, registration, and campaign controls on the way to a premium video screen.

    Run each proposed product and target market through four gates. If any answer is unknown, treat the campaign as pending rather than eligible.

    1. Does mandatory state or national registration apply? The exception is easy to misread: online gambling advertisers not subject to mandatory state or national gambling registration remain excluded from the expanded eligibility. Operating in a category without a registration requirement is not a shortcut into the Masthead.
    2. Are you legally permitted to offer the product in the target jurisdiction? Confirm the relevant registration and licensing position for the product and location. If the answer depends on an interpretation of local law, use qualified legal counsel rather than inferring eligibility from a competitor’s campaign.
    3. Do you hold the matching Google Ads certification? Certification is not a universal gambling credential. Approval depends on the gambling category, local rules, licensing requirements, and jurisdictions you intend to target.
    4. Can the campaign enforce every geographic and age restriction? The campaign must stay inside the approved markets and comply with all applicable age limits. A broad audience setup can invalidate an otherwise eligible plan.

    The third gate deserves particular attention. A government licence or registration addresses your legal status. Google Ads certification addresses your permission to advertise through Google’s systems. Keep both records in your campaign approval file; neither should be treated as a substitute for the other.

    Map eligibility by product and jurisdiction

    A compliance team reviews connections between different gambling products and selected regions on an unlabeled tabletop map.

    Don’t label the entire company “approved” because one product is certified in one market. Build a simple eligibility matrix with one row for every product-jurisdiction combination you want to advertise.

    • Product or gambling category
    • Target country, state, or other applicable jurisdiction
    • Whether mandatory gambling registration applies
    • Registration and licensing status
    • Google Ads certification status and scope
    • Required geographic exclusions
    • Applicable age restrictions
    • Overall status: eligible, pending, or blocked

    This matrix prevents a common planning error: allowing a valid approval in one market to become an assumption about another. It also gives media, legal, compliance, and creative teams the same definition of what can launch.

    Be strict about the status labels. “Pending” should mean that a required decision, certification, or legal confirmation is still outstanding. It should not be converted to “eligible” because the campaign deadline is approaching. “Blocked” should identify the failing gate so the team knows whether the constraint is the product, jurisdiction, registration rule, certification, or targeting requirement.

    Sequence the campaign so compliance is not the final dependency

    The expensive mistake is to complete the media plan and creative first, then discover that the certification doesn’t cover the proposed product or market. Use this order instead:

    1. Define the exact gambling product being promoted.
    2. List every jurisdiction the campaign would reach.
    3. Confirm whether mandatory registration applies in each product-market combination.
    4. Verify the relevant registration, licensing, and legal permissions.
    5. Obtain or confirm Google Ads certification for the applicable category and jurisdictions.
    6. Configure geographic targeting, geographic exclusions, and age controls around the narrowest permitted scope.
    7. Review the creative, destination, account, and campaign against Google’s broader advertising policies.
    8. Commit the Masthead budget and launch date only after the required approvals are confirmed.

    For the initial rollout, narrow scope is easier to govern. A campaign covering one confirmed product-market combination has fewer ways to drift beyond its permissions than a launch that combines several products and jurisdictions. Expansion can follow as additional rows in the eligibility matrix become confirmed.

    October 21 is an eligibility start date, not a guaranteed campaign launch date. Account review, certification, legal clearance, and campaign approval still determine whether your specific campaign can run. Keep an alternative media plan until those dependencies are settled, particularly when the Masthead date is tied to a fixed promotion.

    Key questions about YouTube gambling ad access

    Can every online gambling operator buy a YouTube Masthead from October 21?

    No. The expansion applies to eligible, certified advertisers that satisfy the relevant legal, registration, licensing, geographic, and age requirements. It is not blanket permission for online gambling advertising.

    Does a gambling licence replace Google Ads certification?

    No. A licence or registration establishes a legal status under the applicable jurisdiction. Google Ads certification is a separate platform requirement for advertising the covered gambling category and market.

    Does one Google certification cover every jurisdiction?

    You should not assume that it does. Certification requirements depend on the category, jurisdiction, local regulation, and applicable licensing rules. Verify the scope against every market in the campaign.

    Are sports betting advertisers newly eligible?

    No. YouTube’s existing Masthead policy already permits sports betting advertising. The change extends potential access to more certified online gambling advertisers.

    Your next move is concrete: write down the exact product and jurisdiction you want to promote, then clear all four gates before briefing the campaign. If registration, licensing, certification, geography, or age controls remain unresolved, the Masthead plan is not ready for budget approval.

    References


  • How to Choose a Specialized SEO Agency for Healthcare or Deep Tech

    How to Choose a Specialized SEO Agency for Healthcare or Deep Tech

    You can hire an agency that understands SEO and still spend months correcting inaccurate copy, arguing about lead quality, or repairing a site structure that cannot represent your locations, services, products, and use cases. In healthcare and deep tech, generic SEO competence often fails at the layer that determines whether visibility becomes revenue: subject-matter accuracy, approval workflow, conversion design, and attribution.

    Your decision should not hinge on which agency uses the most current terminology. It should hinge on whether the team can model how your buyers or patients search, publish material your experts will approve, and connect search visibility to an outcome your organization values. The tests below will help you find out before you sign a long engagement.

    Key takeaways before you build a shortlist

    • Vertical specialization is an operating capability, not a collection of client logos. Look for specialist writers, expert-review gates, vertical-specific site architecture, and relevant conversion reporting.
    • For healthcare, the central test is whether the agency can connect local and organic visibility to patient acquisition without creating clinical, privacy, or compliance risk.
    • For deep tech, the central test is whether the agency can produce technically defensible content and measure its contribution across a long, multi-stakeholder sales cycle.
    • GEO and AEO are useful extensions of search strategy only when the agency can explain the pages, entities, evidence, third-party authority, and technical foundations that support AI visibility.
    • Choose your measurement rules before reviewing forecasts. If you do not define a qualified patient action or sales opportunity, traffic and ranking gains can conceal a commercially weak campaign.

    Real specialization appears in the delivery system

    An isometric team of specialists works at connected stations around a circular content review and approval process.

    A relevant client list is helpful, but it is only evidence of access. It does not prove that the people assigned to your account understand your field. Ask who will perform the keyword research, write the content, review technical claims, resolve stakeholder comments, and interpret conversion data. Those are the people whose expertise matters.

    Healthcare and deep tech share a need for accuracy, but they do not share the same search journey. A healthcare program commonly has to route a patient or caregiver from a condition, service, clinician, or location query to an appropriate next step. A deep-tech program may need to help a technical evaluator, business sponsor, and procurement stakeholder understand the same product from different angles before an opportunity exists.

    Decision pointHealthcare SEODeep-tech SEO
    Primary search journeyNeed, service, specialist, and location leading toward careTechnical problem, product capability, industry, and use case leading toward evaluation
    Highest content riskMisleading, unsupported, or clinically inappropriate health informationIncorrect technical claims, overstated capabilities, or loss of credibility with experts
    Core site relationshipsServices, specialties, providers, facilities, and geographic coverageProducts, platforms, industries, applications, technical resources, and evidence
    Meaningful conversionQualified call, form submission, appointment request, booking, or completed visitQualified inquiry, technical consultation, demo, sales opportunity, or attributable pipeline
    Essential approval gateClinical, privacy, legal, and operational review where applicableProduct, engineering, scientific, legal, and sales review where applicable
    Reporting requirementResults segmented by service and location, with an agreed patient-acquisition definitionLeading search indicators connected to CRM opportunities and a long sales cycle

    A specialized agency should be able to describe these differences without prompting. More importantly, it should show how the differences alter research, page architecture, editorial review, conversion tracking, and reporting. If the proposed workflow would be unchanged for a hospital network, a robotics company, and a local retailer, the specialization is probably superficial.

    For healthcare, test local acquisition, clinical accuracy, and data boundaries

    Healthcare leaders are right to push the conversation beyond rankings. Among 87 providers from multi-location practices who completed a survey, patient acquisition and ROI accounted for 24.5% of their must-have selections, the largest weighted criterion in that evaluation. That is not a universal benchmark, but it is a useful instruction for your RFP: define the patient action before asking how much traffic an agency can generate.

    Ask for a location-and-service operating plan

    Multi-location healthcare SEO is not solved by copying a service page and changing the city name. Each page needs a clear purpose, accurate local information, and enough unique value to deserve its place in search. The agency also needs a system for keeping location data, provider relationships, service availability, and Google Business Profile information aligned.

    Give each finalist a real service line and a representative set of locations. Ask for these artifacts:

    • A map showing which service, specialty, provider, and location intents deserve separate pages, and which should be consolidated.
    • A Google Business Profile inventory plan that identifies ownership, duplicate-risk checks, required fields, review responsibilities, and the source of truth for operational data.
    • A location-page brief showing which facts must be unique, who supplies them, and how unavailable services or provider changes are corrected.
    • An internal-linking plan that lets patients move between educational information, relevant services, appropriate locations, and the next operational step.
    • A reporting example segmented by location and service rather than a single sitewide visibility total.

    Local rankings and profile activity are diagnostic measures. They become business measures only when you can see whether the resulting calls, forms, or bookings were appropriate for that location and service. Make the agency explain that connection in the proposal.

    Put medical accuracy inside the production workflow

    Healthcare content faces heightened trust expectations, including the scrutiny associated with Your Money or Your Life topics. Strong healthcare programs therefore combine medical subject-matter writing with technical, local, and conversion work. The writer’s fluency matters, but the approval process matters just as much.

    Ask who has written for your exact specialty, not merely for healthcare in general. Then inspect the review workflow. It should identify who checks clinical meaning, who approves claims, how evidence is recorded, what triggers an update, and how a correction is deployed across related pages. A fluent page that is medically misleading can harm patients and expose the organization to regulatory, reputational, or legal consequences. The agency can operate the workflow, but it should not replace your authorized clinical and legal reviewers.

    A useful content trial is deliberately difficult. Supply a page with ambiguous terminology, an outdated service detail, and comments from more than one internal stakeholder. See whether the agency resolves the contradictions, asks precise questions, and maintains a traceable list of claims requiring approval. A polished first draft is less revealing than a disciplined revision.

    Draw the privacy boundary before connecting systems

    Outcome reporting may involve call tracking, forms, scheduling systems, a CRM, or EHR data. That can improve the connection between marketing activity and patient outcomes, but it also raises the stakes. Before granting access, require a data-flow diagram showing what is collected, where it goes, who can access it, how long it is retained, and which vendors receive it.

    Do not accept the phrase HIPAA-compliant as a complete explanation. If U.S. HIPAA obligations apply, your privacy, security, compliance, and legal owners should approve the contractual and technical design. Keep protected or identifying health information out of marketing tools unless the organization has explicitly determined that the proposed use, vendor relationship, access controls, and retention rules are permitted.

    You can still build useful reporting within a strict boundary. Agree on permitted events such as qualified calls, appointment requests, bookings, or aggregated completed visits. Document the event definition, exclusions, attribution window, source system, and owner. That prevents a dashboard from quietly treating spam, existing-patient activity, recruitment inquiries, and new-patient demand as the same result.

    For deep tech, test technical precision and sales-cycle fluency

    An evaluator compares evidence from a secure local healthcare setting and a technical laboratory with a long buyer journey.

    Deep tech is broad. In this context it includes fields such as advanced computing, biotechnology, aerospace, semiconductors, robotics, and clean energy. Experience in one field does not automatically transfer to another. A team that understands climate technology may still need substantial onboarding before it can write credibly about semiconductor design or a scientific platform.

    Technical accuracy deserves explicit weight in the selection process. Across 43 agencies with documented deep-tech experience, technical-content precision received a 20% weighting, compared with 10% for sales-cycle fluency and 10% for GEO/AEO specialization. Those weights are not a formula you must adopt. They do illustrate a sound ordering: an agency should not earn extra credit for AI-search terminology if its core technical content cannot survive expert review.

    Run a paid technical audition

    A portfolio can show that an agency worked for a technical company. It cannot show how much the client’s engineers had to rewrite. The clearest test is a small paid assignment using your terminology, a real search opportunity, and the same experts who would review live work.

    Ask the candidate to deliver a search-intent rationale, page outline, sample section, claim inventory, open-question list, and internal-linking recommendation. Have your subject-matter expert evaluate factual accuracy, missing qualifications, misuse of terminology, strength of evidence, audience level, and revision quality. Also record how much expert time the assignment consumes. Content that becomes accurate only after your engineering team rewrites it is not an outsourced content capability.

    Do not expect an outside writer to know undisclosed product details. Do expect the agency to distinguish established facts from assumptions, notice where evidence is missing, and ask questions that a technically literate person would ask. Intellectual restraint is part of precision.

    Make the agency model your market, not just your keywords

    A deep-tech site often needs to explain one capability through several market lenses. Prospects may search by product category, underlying problem, industry, application, technical method, or comparison. Strong domain strategies therefore account for products, services, industries, and use cases instead of relying on a flat list of high-volume keywords.

    Ask for a market-to-site map. It should connect each meaningful intent to an existing page, a planned page, or a deliberate decision not to create one. The last option matters. Publishing a near-duplicate page for every possible industry and use-case combination creates maintenance debt and thin content. Separate pages are justified when the search intent, technical evidence, buyer problem, or conversion path is materially different.

    The map should also show how educational content supports commercial pages. A technical explanation can earn attention, links, and citations, but it should give the right reader a clear path to the applicable capability, evidence, and next step. If the agency cannot explain that path, it is planning a publishing calendar rather than a demand system.

    Use reporting that can survive a long sales cycle

    Deep-tech search performance and revenue rarely move in lockstep. A technically strong page may attract evaluators early, assist an opportunity later, and never receive last-click credit. That does not justify vague attribution. It means search and CRM data need a shared measurement model.

    Separate leading indicators from commercial outcomes. Leading indicators can include indexation, non-branded visibility, qualified organic entrances, engagement from target accounts, technical-resource use, and relevant conversion events. Commercial outcomes can include accepted inquiries, opportunities, influenced pipeline, and closed business. The exact set depends on your systems and sales process, but every metric should have an owner and a definition.

    Ask sales to define disqualifying conditions as well as desirable ones. A contact may be technically interested but commercially irrelevant because of geography, application, scale, purchasing authority, or timing. If the agency reports every form completion as a lead, it will optimize for volume while your team absorbs the qualification cost.

    Use the same evidence test for every finalist

    Agency comparisons become unreliable when each finalist receives a different brief and chooses its own success metric. Give every candidate the same business problem, access constraints, audience definition, conversion definition, and approval requirements. Then use a consistent selection sequence.

    1. Disqualify unsafe operating models. Remove any candidate that cannot explain medical or technical review, access control, data handling, correction procedures, or claim approval where those controls apply.
    2. Inspect working artifacts. Request sanitized examples of research briefs, page maps, editorial comments, technical audits, local reporting, and conversion definitions. A slide describing a process is weaker evidence than the documents the process produces.
    3. Verify outcomes in context. Ask what improved, over what campaign period, from which baseline, for which location or product, and under which attribution rule. Clarify what the client supplied, including brand demand, paid media, development resources, and internal experts.
    4. Run the relevant audition. Healthcare finalists should solve a location, service, clinical-review, or measurement problem. Deep-tech finalists should complete a technical content and market-architecture exercise.
    5. Assess account fit. Confirm who will actually work on the account, how often specialists participate, how requests are prioritized, what is excluded, and how the agency responds when results or assumptions change.
    6. Choose the right scope. A search specialist can be the better fit when your internal team already owns brand, web development, PR, and paid media. An integrated agency can be useful when those programs must move together, provided the SEO and GEO expertise remains visible in the staffing and deliverables.

    Several warning signs should end or sharply downgrade the conversation:

    • Vertical expertise is supported only by logos, with no relevant work samples or named workflow roles.
    • The agency forecasts traffic without defining a qualified patient action, inquiry, opportunity, or pipeline event.
    • Healthcare location pages are treated as interchangeable templates with no plan for unique services, providers, operations, or local information.
    • Deep-tech content is delegated to generalist writers without a technical briefing and expert-review process.
    • The agency guarantees placement or citations in AI-generated answers.
    • GEO or AEO reporting relies on a proprietary visibility score but does not expose the monitored prompts, observed citations, cited pages, competitors, or resulting actions.
    • The phrase HIPAA-compliant replaces a concrete explanation of data flows, permissions, vendors, security controls, and contractual responsibilities.
    • Case results are presented without the baseline, duration, attribution method, campaign scope, or client contribution needed to interpret them.

    GEO and AEO deserve evaluation, but they should remain connected to the same evidence system. Ask which answer environments and query themes the agency will monitor, how it will record mentions and citations, which on-site or off-site changes it expects to influence them, and how it will separate visibility from business impact. AI-search activity that cannot be inspected or tied to a useful audience action is not yet a performance strategy.

    Your next step is to write a one-page selection brief before contacting more agencies. Name the priority service or product, target geography or market, qualified conversion, prohibited data, approval owner, available systems, and business outcome. Give that same brief to every finalist, commission the relevant audition, and choose the team whose work needs the least translation from your experts.

    References


  • Microsoft Automotive Ad Pricing Rules: A Dealer Checklist

    Microsoft Automotive Ad Pricing Rules: A Dealer Checklist

    A vehicle price can be correct in your inventory system and still become misleading by the time it reaches an ad. A conditional discount may lose its qualifier, a feed may retain yesterday’s amount, or the landing page may show a different offer.

    If you manage U.S. dealer campaigns, treat Microsoft Advertising’s updated automotive pricing policy as a reason to audit the entire path from inventory record to landing page. The central test is simple: does the price a shopper sees accurately represent the offer that shopper can obtain?

    Key takeaways for U.S. automotive advertisers

    • The revised pricing requirements apply to automotive dealers advertising in the United States through Microsoft Advertising.
    • Accuracy depends on more than the number in a feed. Review source data, feed transformations, discounts, ad rendering and landing pages together.
    • A discount that depends on eligibility, timing or another condition should not appear to be universally available.
    • Quarantine ambiguous or mismatched inventory records instead of allowing questionable prices to keep serving.
    • Keep evidence showing what the offer, feed, ad and landing page displayed when each pricing review was completed.

    Start with the requirement you can prove

    The revised requirements govern how vehicle prices are represented, including the treatment of prices, discounts and related pricing information across Microsoft Advertising formats. Microsoft has framed the change as a way to make compliance easier while keeping advertised prices faithful to the available offer.

    That principle is useful, but it isn’t a substitute for the current policy language. Before changing templates or feed logic, retrieve the active Microsoft Advertising policy and its change log from your account or policy library. Save the version your team reviewed. Then convert each requirement into a control that can be tested.

    Your requirements matrix should record:

    • Scope: the campaigns, formats, accounts and inventory covered by the requirement.
    • Price element: the feed field, discount, qualifier or rendered text that must be checked.
    • Expected behavior: what the feed, ad and destination must show for the record to pass.
    • Evidence: the feed export, ad preview, landing-page capture and approval record that demonstrate compliance.
    • Owner: the person or team responsible for correcting a failure.

    This prevents a familiar operational mistake: translating a policy change into a vague instruction such as “check the prices.” A requirement without a named field, pass condition and owner is unlikely to survive the next inventory refresh.

    Audit the price as a chain, not a field

    An isometric audit chain links a vehicle inventory record, feed pipeline, online ad, and mobile landing page with connected price and discount tags.

    The shopper sees the output of several systems. Your audit should therefore follow the same route as the price.

    1. Confirm the underlying offer. For each sampled vehicle, record the stock identifier, selling price, included discounts, eligibility conditions, availability and relevant offer timing. This is the truth the rest of the chain must preserve.
    2. Inspect the feed transformation. Compare the inventory-system values with the exported values. Look for field mapping, rounding, fallback values, promotional overrides or other logic that can change the amount.
    3. Check the rendered ad. Use the actual ad preview or delivered-ad evidence where available. Do not rely only on the feed file; templates can omit qualifiers or place values in the wrong pricing field.
    4. Open the destination. Confirm that the click resolves to the same vehicle and that the visible price and conditions agree with the advertised offer. A correct feed does not repair a contradictory landing page.
    5. Test the handoff. A staff member who was not involved in creating the promotion should be able to identify who qualifies, which discounts are included and how the displayed amount is obtained.

    Keep the evidence together under the same stock identifier. If a campaign is questioned later, separate screenshots and exports are far less useful when nobody can tell whether they describe the same vehicle or the same version of the offer.

    Review discounts more aggressively than base prices

    Base prices are usually direct values. Discounts often contain business logic: a buyer must qualify, offers may or may not combine, inventory may be restricted, and a promotion may end while an old feed remains active. That makes discounts the natural place for a technically valid number to become an inaccurate promise.

    For every advertised discount, answer these questions before the record is eligible to serve:

    • Can the intended audience actually receive the discount on the advertised vehicle?
    • Does eligibility depend on a fact that the ad or destination fails to communicate clearly?
    • If several discounts produce the displayed price, can those discounts genuinely be combined?
    • Does the promotion apply to this specific inventory record rather than merely to a related model or trim?
    • What removes or replaces the promotional amount when the underlying offer changes?
    • Will the landing page explain the offer in a way that agrees with the ad rather than quietly narrowing it?

    Use a practical reproduction test: give the rendered ad and its destination to the person responsible for the offer, then ask that person to reconstruct the advertised amount. If the total depends on an undisclosed assumption, the price chain needs correction before the ad runs.

    Platform compliance is not a legal opinion. Automotive price disclosures can also create legal exposure outside Microsoft Advertising, so route uncertain wording, fee treatment and eligibility disclosures to qualified counsel or your compliance team before publication.

    Build controls that can handle a large vehicle feed

    Manual review is valuable for interpreting an offer, but it does not scale well across a changing inventory. Use automated checks to find records that deserve human attention.

    Block records with objective failures

    • A required price or stock identifier is missing or cannot be parsed.
    • The destination resolves to a different vehicle, a removed listing or an error page.
    • The feed amount and the landing-page amount do not match under the same stated conditions.
    • A discount is present without the data your process requires to validate eligibility and offer status.
    • A source update fails, but the campaign would otherwise continue serving the previous promotional value.

    Send these records to quarantine. Do not let a failed validation silently fall back to a stale or lower amount merely to preserve inventory coverage.

    Queue ambiguous records for human review

    • A new discount or pricing override appears.
    • The size of a discount changes unexpectedly.
    • Several incentives contribute to one advertised amount.
    • The ad copy implies broad availability while the underlying offer contains narrow eligibility conditions.
    • The visible landing-page explanation makes the price harder to understand than the ad itself.

    Prioritize the lowest advertised prices, the largest discounts, recently changed offers and records produced by fallback logic. This is risk-based review: it directs attention to the entries most likely to create a material gap between the advertised number and the obtainable offer.

    Keep each record in an explicit state such as eligible, quarantined or approved exception. An exception should contain its reason, approver and supporting evidence. Otherwise, a temporary workaround can become permanent feed behavior without anyone consciously accepting the risk.

    Handle a pricing violation as a data incident

    A dealership advertising team investigates an amber-highlighted pricing mismatch across inventory, ad, and landing-page systems.

    A pricing problem is rarely fixed by editing one headline. Policy violations can create compliance problems and potentially disrupt campaigns, so preserve the evidence and repair the system that produced the bad value.

    1. Contain the issue. Pause or exclude affected records without unnecessarily disabling inventory that has passed validation.
    2. Preserve the observed state. Save the source record, exported feed row, rendered ad, destination page and applicable policy version.
    3. Locate the first divergence. Determine whether the error began in merchandising data, discount logic, feed mapping, ad templates, the landing page or update timing.
    4. Correct the origin. A manual edit downstream may conceal the symptom while the next refresh recreates it.
    5. Revalidate the path. Confirm both the corrected record and comparable records that use the same rule or template.
    6. Document the prevention. Add a validation rule, ownership change or release check so the same failure cannot pass unnoticed.

    Do not assume every rejected vehicle has the same cause. One campaign may contain a stale-price problem, an eligibility problem and a destination mismatch at the same time. Classifying each failure before applying a bulk fix reduces the chance of introducing a second pricing error.

    Give one person authority over the final price path

    Pricing accuracy crosses several teams: merchandising defines the offer, feed operations map the data, paid media controls the ad, web teams publish the destination, and compliance interprets disclosure risk. Shared work still needs a final owner who can prevent a record from serving when those components disagree.

    Before your next feed publication, choose a discounted vehicle and trace it from the underlying offer through the rendered ad to the landing page. Record every transformation and assign an owner to every failure point. Once that path is reliable, apply the same control to the rest of the high-risk inventory before releasing broader campaign changes.

    References


  • Google Ad-Tech Antitrust Litigation: A Publisher’s Playbook

    Google Ad-Tech Antitrust Litigation: A Publisher’s Playbook

    If you depend on programmatic advertising revenue, the Google ad-tech litigation creates a planning problem before it creates a financial opportunity. The wrong response is to put a recovery into your forecast or make a rushed platform change. The useful response is to determine whether your business touches the surviving claims and whether you can still explain, with records, how money moved through your ad stack.

    Major claims remain alive, but that is not the same as a finding that every publisher was harmed. Your immediate job is to separate what the court has established, what the publishers still must prove, and what evidence your own legal and finance teams would need to evaluate any potential exposure or recovery.

    The ruling preserved a path, not a payout

    On Sept. 30, U.S. District Judge P. Kevin Castel issued an 88-page opinion denying Google’s requests for summary judgment on the publishers’ principal ad-tech claims. He also declined to exclude important expert testimony supporting their damages cases.

    Summary judgment is a pretrial mechanism for resolving claims that do not require a trial to decide. Denying it means Google did not persuade the court to dispose of the principal claims on the pretrial record. It does not mean the publishers have won a damages award, that every expert assumption has been accepted, or that every remaining dispute will necessarily reach trial.

    What the decision didWhat it did not do
    Kept the publishers’ principal ad-tech claims in the litigationDecide how much, if anything, Google owes
    Allowed key damages testimony to remain in the caseAdopt the experts’ estimates as proven losses
    Preserved claims involving the AdX publisher class and Mikula Web SolutionsPreserve every claim brought by every plaintiff
    Prevented Google from relitigating certain findings from the separate Virginia caseEstablish injury and damages for each publisher automatically

    The mixed outcome matters. Castel ruled for Google on the New York General Business Law claims brought by Gannett and Daily Mail, on claims brought by The Progressive, and on Inform’s federal antitrust claims. Claims involving the AdX publisher class and Mikula Web Solutions were allowed to continue. A headline saying publishers cleared a major hurdle is accurate, but it is too broad to answer whether a particular company, legal theory, or alleged loss remains in play.

    When you brief executives, use a claim matrix rather than a win-or-loss label. Give each claimant and legal theory its own row, then record whether the claim survived, which issues are already established, which issues remain disputed, and what procedural event comes next. That prevents a partial ruling from turning into an inaccurate company-wide assumption.

    The economic dispute sits between inventory and demand

    An abstract publisher page and advertiser nodes connected through a layered auction system carrying metallic tokens.

    A publisher ad server manages advertising inventory and helps decide which demand source can fill an opportunity. An exchange provides a marketplace in which demand can compete for that inventory. When one company controls important infrastructure on both sides of that handoff, the rules connecting the products can affect which demand participates, how an auction operates, what fees are charged, and what reaches the publisher.

    That connection is central here. The publishers allege that Google’s control over its publisher ad server and the AdX exchange, combined with practices governing ad auctions, reduced publisher revenue or produced excessive fees. Google contests those allegations. The disputed question is therefore not simply whether publishers used Google technology; it is whether challenged conduct caused a measurable economic injury.

    The litigation also draws on the federal government’s separate ad-tech case in Virginia. Castel had already determined that Google could not relitigate certain findings from that proceeding, including the finding that Google unlawfully tied its publisher ad server to AdX. That gives the publisher plaintiffs an important established point, but it does not calculate the consequences for a particular publisher. Injury, causation, and damages still have to be connected to the conduct at issue.

    For your business, the practical unit of analysis is an ad-monetization dependency map. It should show:

    • The legal entities, sites, applications, and business units that sold digital inventory.
    • The publisher ad server and exchanges used during each relevant period, including migrations and material configuration changes.
    • Which demand paths were direct, exchange-based, mediated, or otherwise dependent on the publisher ad server.
    • The contracts, amendments, fee schedules, invoices, and reporting accounts associated with each path.
    • The identifiers that connect domains, properties, accounts, reports, and payment records across systems.
    • The employees or vendors who understood auction configuration, yield management, billing, and reporting definitions at the time.

    This map does not establish that you belong to a class or have a claim. It gives counsel the facts needed to assess those questions without relying on institutional memory. It also reveals whether a change in revenue coincided with traffic, inventory, auction, fee, or platform changes instead of treating every decline as one undifferentiated problem.

    Do not mistake the damages estimates for recoverable amounts

    The public figures are large because they are damages estimates prepared by experts retained by the plaintiffs. They are not court-awarded compensation:

    Claimant or groupPlaintiffs’ expert estimate
    GannettRoughly $901 million
    Daily Mail$600 million
    Publisher class$1.72 billion through March 31, 2024

    The plaintiffs claim additional class damages after March 31, 2024, but no additional amount was provided. Do not extend the $1.72 billion estimate beyond that date, apply it as a percentage of industry revenue, or use it to derive a hypothetical recovery for your company. None of those calculations is supported by the disclosed figures.

    An expert’s testimony can remain admissible while its assumptions, method, causal reasoning, and conclusions remain disputed. The publishers still need to prove that the challenged conduct injured them and that the requested damages are attributable to that conduct. Google can continue contesting those points.

    Your finance team should therefore treat the amounts as allegations supported by the plaintiffs’ models, not as receivables or operating income. If you need an internal scenario, build it in layers:

    1. Use zero recovery as the operating baseline unless legal and accounting advisers determine otherwise.
    2. Ask counsel whether the relevant legal entity, products, time periods, and transactions could fall within a surviving claim or class.
    3. Identify which revenue, fee, and auction records could support or contradict economic injury.
    4. Document every assumption in any contingent scenario, including eligibility, time boundaries, allocation method, legal costs, and uncertainty.
    5. Keep the scenario outside normal performance targets so an unresolved lawsuit does not distort hiring, content, or technology decisions.

    The same restraint applies to vendor decisions. A surviving antitrust claim is not proof that your current contract is invalid, that a migration will improve yield, or that another stack will produce a particular result. Evaluate a change using your own fees, demand access, reporting quality, operational cost, and measured auction outcomes.

    Build a counsel-led evidence pack while the systems are identifiable

    An overhead view of storage drives, blank records, archive envelopes, and a magnifying glass arranged as an evidence pack.

    This is an operational preparation checklist, not a determination that your company is part of the litigation or subject to a legal-hold obligation. If the surviving claims may be relevant to your business, ask qualified antitrust or litigation counsel to assess eligibility and preservation duties. Do that before changing retention policies or launching a broad data collection.

    1. Create a system inventory. Record each ad server, exchange, reporting interface, billing system, data warehouse, and archive, along with its owner and available date range.
    2. Preserve the commercial record. Locate contracts, order forms, amendments, invoices, payment statements, fee disclosures, account notices, and documents explaining platform migrations or material configuration changes.
    3. Preserve the operational record. Identify ordinary-course auction reports, revenue reports, configuration histories, demand-partner lists, account identifiers, and metric definitions. Record where a field was renamed or calculated differently over time.
    4. Build a dated chronology. Align platform changes with shifts in impressions, fill, auction participation, reported fees, and net publisher revenue. A chronology makes alternative explanations visible instead of assuming every movement came from the challenged conduct.
    5. Reconcile money to activity. Where the data permits, connect inventory and auction records to invoices and net payments. Record unexplained gaps rather than backfilling them with estimates.
    6. Document limitations. Note missing periods, expired logs, acquired properties, changed account IDs, inconsistent currencies, and reports that cannot be reproduced. A known limitation is more useful than false precision.
    7. Control access. Keep the working set limited to the people who need it, and follow counsel’s directions for preservation, privilege, privacy, security, and collection scope.

    Do not delete, rewrite, or normalize potentially relevant originals after counsel identifies a preservation obligation. At the same time, do not collect extra user-level information merely because it might be available. An indiscriminate collection can create privacy and security exposure without helping establish publisher-level fees or revenue. Preserve what is relevant, document what each field means, and let counsel define the defensible scope.

    SEO, content, and audience teams also have a role. Keep acquisition performance separate from monetization performance in your reporting:

    • Acquisition: visits or sessions from organic search, AI-search referrals, direct traffic, social platforms, and other channels.
    • Inventory: ad opportunities, eligible impressions, ad load, and fill-related measures available in your systems.
    • Monetization: auction outcomes, disclosed fees, and net publisher revenue, with the governing metric definitions attached.

    Traffic can improve while monetization weakens, or monetization can improve while traffic falls. A single blended revenue-per-session figure hides that distinction. Separating the layers helps you evaluate content performance accurately now and gives legal and financial reviewers a cleaner record if they later need to isolate alleged ad-tech harm.

    Key takeaways for publisher teams

    • The Sept. 30 decision kept principal Google ad-tech claims alive and preserved key expert testimony; it did not award damages.
    • Google cannot relitigate certain findings from the separate Virginia case, including unlawful tying of its publisher ad server to AdX, but publisher-specific injury and damages still require proof.
    • The estimates of roughly $901 million for Gannett, $600 million for Daily Mail, and $1.72 billion for the publisher class are plaintiffs’ expert estimates, not payouts.
    • The result varies by claimant and legal theory. Several claims were resolved for Google, while claims involving the AdX publisher class and Mikula Web Solutions continue.
    • Your defensible next step is a counsel-led review of eligibility, systems, contracts, fees, and retained data—not an assumed recovery or an emergency platform migration.

    Within your next reporting cycle, produce a one-page ad-stack dependency map and assign owners for the supporting contracts, reports, and payment records. Have counsel decide whether a deeper eligibility or preservation review is warranted. That gives you a decision-ready file without pretending the litigation has already produced money for publishers.

    References


  • Web Data Access Mandates: A Playbook for Site Owners

    Web Data Access Mandates: A Playbook for Site Owners

    You want search engines and AI systems to discover your work, but you also need to know who is copying it, why they want it, and whether your access rules mean anything. At the other end of the market, opening a dominant platform’s data may improve competition while moving sensitive search histories beyond the systems that originally protected them.

    The useful question is not whether web data should be open or closed. It is whether each access decision has a verified actor, a defined purpose, a proportionate data scope, an enforceable control, and an accountable owner. That is the operating model site owners, SEO teams, AI platforms, and data recipients need as transparency mandates develop.

    Key takeaways

    • Crawler transparency and platform data sharing are different obligations. The first identifies who is requesting access; the second governs data that is transferred to another party.
    • A User-Agent is a claim, not proof of identity. Give special access only after the crawler has been verified through evidence controlled by its operator.
    • Use robots.txt to communicate preferences to cooperative crawlers, but enforce important restrictions through edge controls, authentication, scoped credentials, or restricted endpoints.
    • Separate discoverability from permission. Allowing a crawler does not guarantee citations or AI visibility, while blocking one can reduce its ability to retrieve current content.
    • Anonymization is not a label applied to an export. Sensitive search data needs minimization, re-identification testing, access controls, retention limits, audit logs, and incident procedures.

    Two transparency mandates solve different problems

    One policy track concerns traffic arriving at your site. The proposed federal Stealth Bot Prohibition Act would require automated crawlers to identify themselves and disclose their purpose. It targets tactics such as posing as a human visitor, routing requests through residential proxies, or using scraping services to get around website controls. A similar New York measure applies to news publishers, while the federal proposal would extend more broadly across websites and digital platforms.

    The other policy track concerns data leaving a large platform. The European Commission has required Google to share with competitors in the European Union the same search data it uses to improve its own search services, subject to anonymization. The reported deadline for search-data sharing is January 2027. Google has appealed the decision, arguing that the required anonymization is insufficient and that moving query data outside its infrastructure creates additional security exposure.

    Those positions are not opposites. A crawler can disclose its identity without receiving unrestricted access. A platform can be required to provide access without publishing raw data to the world. Transparency identifies the actor and the rules; it does not eliminate access controls.

    Operational questionCrawler transparencyPlatform data sharing
    Who must act?The automated requesterThe platform holding the required dataset
    What must become clear?Identity, purpose, and compliance with the site’s policyDataset scope, recipient, purpose, safeguards, and permitted use
    Does data have to leave the holder?Not necessarily; disclosure can precede an allow-or-block decisionYes, to the extent required by the applicable mandate
    Main control failureA false identity defeats crawler-specific rulesWeak minimization, anonymization, or recipient security exposes sensitive data
    First question to answerCan you prove which operator sent this request?Can you prove why each transferred field is necessary and protected?

    Keep these workstreams separate in your compliance register. The owner of bot verification may sit in infrastructure or security, while the owner of a mandated data transfer may span legal, privacy, security, and product teams. Combining them into a generic transparency project makes it easy to miss the control that actually matters.

    The legal stakes also differ from an ordinary integration project. Under the Digital Markets Act’s general penalty regime, non-compliance can expose a company to fines of up to 10% of annual global revenue, up to 20% for repeated infringements, and periodic payments of up to 5% of average daily sales. These are statutory maximums, not a prediction about any particular dispute. If your organization may be in scope, have qualified EU competition and privacy counsel confirm the current deadlines, the effect of any appeal, and the technical form of compliance.

    Make crawler identity verifiable, not merely declared

    A crawler presents a digital key at a network checkpoint while unverified crawler devices remain outside the gate.

    A crawler can place a recognizable name in its User-Agent header. That makes the name useful for classification, but it does not make the claim true. A hidden crawler can imitate browser traffic, borrow another bot’s label, or use residential addresses that do not resemble data-center infrastructure. This is why an identity mandate matters: rules addressed to a named bot are ineffective when the requester can lie about being that bot.

    Build your crawler register around five records:

    1. Declared operator and product. Record the organization claiming responsibility, the crawler name, an official contact path, and the date you checked the information.
    2. Declared purpose. Distinguish functions such as search indexing, live answer retrieval, model training, monitoring, and commercial content reuse. A label such as AI bot is too vague to support a meaningful decision.
    3. Verification method. Prefer evidence controlled by the operator, such as an official verification endpoint, safely validated published network ranges, or authenticated or signed requests when the operator supports them. Do not grant allow-list privileges from a User-Agent alone.
    4. Policy outcome. Map the verified identity and purpose to a specific action for each content class: allow, rate-limit, block, challenge, or route to an authenticated licensing channel.
    5. Observed evidence. Log the time, host and path, request method, response status, claimed User-Agent, relevant network information, verification result, policy matched, action taken, and response volume. Set retention around operational and legal need rather than keeping the data indefinitely.

    Be careful with URL logging. Query strings and path segments can contain account identifiers, search terms, or other personal information. Redact unnecessary values, restrict access to raw logs, and involve your privacy team before expanding retention merely because a bot dispute is possible.

    robots.txt still has a useful role. It gives cooperative crawlers a machine-readable statement of your preferences, and crawler-specific groups can express different choices for identified agents. It is not authentication and cannot stop a requester that ignores the file or hides behind another identity. Put consequential enforcement at the CDN, web application firewall, application, API gateway, or authenticated delivery layer.

    The same distinction applies to SEO infrastructure. A sitemap helps systems discover URLs. Structured data and JSON-LD help them interpret eligible page content after retrieval. Neither verifies the requester or grants unrestricted reuse rights. Keep discovery configuration, crawler authorization, and content licensing as three separate controls.

    If content access is licensed, use credentials or a dedicated delivery route. Define the permitted purpose, content scope, request volume, attribution terms, retention, onward use, reporting, suspension conditions, and termination process. A crawler-identification mandate can make negotiation and enforcement more practical, but it does not by itself create a right to payment, attribution, or a licensing agreement.

    Build an access policy without giving up AI visibility

    Automated traffic is too large to manage as an occasional exception. Cloudflare Radar estimates bots account for 64% of internet traffic. On the publisher sites it monitors, TollBit reported more than 22 billion AI-bot scrapes during the first half of 2026. Its observed ratio of AI-bot visits to human visits moved from roughly one per 200 in the first quarter of 2025 to one per 31 in the fourth quarter. Those vendor-specific figures do not tell you the composition of your traffic. They tell you why your own server and edge logs should, rather than assumptions.

    Use this sequence to turn that telemetry into an enforceable policy:

    1. Inventory content surfaces. Separate public HTML pages, media files, feeds, APIs, downloadable archives, licensed material, account areas, and private content. Anything genuinely private should sit behind access control rather than a crawler instruction.
    2. Write a decision matrix. For each content class, decide what happens when the requester is a verified desired crawler, a verified crawler with an unapproved purpose, a claimed but unverified bot, an authenticated licensee, or unknown automation. Give unverified claims no special allow-list privilege.
    3. Enforce in layers. Publish crawler preferences, apply rate and resource controls at the edge, require credentials for restricted delivery, and keep application-level authorization in place. Roll out aggressive rules carefully so false positives do not lock out people or the search services you depend on.
    4. Measure the consequence. Before changing a rule, record verified crawler requests, pages served, bandwidth or compute cost, response errors, identifiable referrals, and the AI citations or mentions you monitor for priority queries. Compare equivalent periods after the change and alter one major policy variable at a time where practical.
    5. Prepare an incident path. Define who preserves logs, verifies the claimant, changes the edge rule, contacts the operator, assesses privacy exposure, and involves counsel. Record why the final allow, throttle, or block decision was made.

    Do not collapse this into a single allow AI or block AI switch. A public documentation page intended to win citations has a different job from a licensed report, a subscriber archive, or an account dashboard. Apply access decisions at the smallest content class your stack can reliably enforce.

    Be equally precise about visibility. Allowing retrieval creates an opportunity for a system to process current content; it does not guarantee ranking, citation, attribution, model training, or referral traffic. Blocking a specific crawler may reduce visibility in the service that relies on it, but it does not prove that all copies disappear or that other systems will stop finding the page. Decide from observed outcomes and your content rights, not from the crawler’s brand name.

    If you cannot verify a requester, fall back to a documented rule based on content sensitivity, infrastructure cost, request behavior, and your visibility objective. That is more defensible than guessing which company is behind an address and quietly granting it privileged access.

    Treat shared search data as a security product

    An analyst monitors a secure vault as search data is minimized, encrypted, and transferred through a controlled access port.

    The European dispute exposes a hard design problem. Search data can help competing search and AI services improve, which supports the Commission’s competition objective. Query histories can also reveal unusually sensitive interests, and transferring them creates another environment that can be attacked or misconfigured. Google’s security argument is a litigant’s position, not a final finding that the mandate is unsafe. The responsible response is to make the privacy and security claims testable.

    Anonymization must be evaluated against re-identification risk, not treated as the removal of obvious account fields. Rare queries, repeated sequences, timestamps, locations, and combinations of attributes may distinguish a person even when a direct identifier is absent. The appropriate transformation depends on the dataset, the recipient’s other information, the allowed use, and the governing mandate. Privacy and security specialists should test that risk before release and after a material change in fields or granularity.

    If you hold the data

    • Create a field-level inventory that names the business purpose, sensitivity, granularity, update frequency, and recipient for every element proposed for transfer.
    • Start with the least detailed representation that can satisfy the authorized purpose, then have counsel confirm whether the mandate requires additional parity with the data used internally.
    • Document the anonymization threat model, including rare records, sequence linkage, external-data linkage, and the conditions under which a recipient could regain access to more detailed information.
    • Deliver data through a segregated, authenticated environment with least-privilege access, encryption, audit logging, and a defined process for credential revocation. Avoid unmanaged bulk copies.
    • Set enforceable rules for retention, deletion, onward sharing, subcontractors, security incidents, and purpose changes. Verify compliance rather than relying only on contractual promises.
    • Publish a plain-language transparency record describing what is shared, with whom, for what purpose, and under which safeguards, while withholding details that would weaken security.

    If you receive the data

    • Accept only fields tied to a documented product or research need. Receiving extra sensitive data creates risk without guaranteeing a better service.
    • Separate raw access from derived outputs. Keep the smallest possible group able to reach detailed records and use aggregated outputs for broader product work where feasible.
    • Test whether the data produces the intended improvement. Access to a dominant platform’s dataset does not automatically change user habits or produce a competitive product.
    • Maintain lineage from the received field through each transformation and output so you can investigate misuse, honor deletion requirements, and explain how the data influenced a result.
    • Prepare a containment and notification procedure before ingestion. It should identify who can stop processing, revoke access, preserve evidence, assess affected data, and contact the provider.

    Your first deliverable should be one accountable register. Put inbound crawler identities and purposes on one side, outbound or received datasets and purposes on the other, and assign a named operational owner to every decision. Then test two scenarios: an unverified crawler requesting high-value content, and a sensitive export appearing outside its approved environment. Any missing owner, log, revocation path, or policy rule is your next fix.

    That register will remain useful even if a bill changes or an appeal succeeds. It gives you something legislation alone cannot: a repeatable way to prove who accessed data, why access was allowed, what left your systems, and how you limited the resulting risk.

    References


  • Google September 2026 Spam Update: An Action Plan

    Google September 2026 Spam Update: An Action Plan

    If your organic visibility moved sharply in September, your first job is not to rewrite the site. It is to determine whether the change is real, whether it is concentrated in search, and whether the timing actually fits Google’s spam update.

    The rollout window makes fast conclusions especially risky. Use the process below to separate an update-related pattern from tracking noise, seasonality, technical mistakes, and unrelated site changes. Then fix the smallest defensible set of problems instead of turning one traffic decline into several.

    Key takeaways

    • Google’s September 2026 spam update applies globally and to every language. A multilingual site should therefore be analyzed by country and language, not judged only by its English pages.
    • The rollout may take up to two weeks. Movement inside that window is useful evidence, but it is not a stable final result.
    • Google named no particular tactic, content format, industry, or production method as the target. Do not diagnose the loss from a theory circulating in the SEO community.
    • A credible diagnosis needs several signals to align: timing, an organic-search decline, a coherent group of affected pages or queries, and no stronger technical or business explanation.
    • Do not delete or rewrite hundreds of URLs at once. Preserve your baseline, stop expanding any clearly questionable pattern, and repair one coherent page group at a time.

    What Google confirmed, and what it did not

    Google released the September 2026 spam update to roll out globally, across all languages, for as long as two weeks. This is the fourth announced Google spam update of 2026, following another announced spam update in August.

    Those facts define the scope and timing. They do not identify a targeted tactic. Google did not specify that this release focuses on AI-generated text, affiliate pages, links, structured data, programmatic SEO, expired domains, or any particular industry. Treat confident claims about a single target as hypotheses until your own data supports them.

    Global scope also does not mean every market or section of your site must move in the same way. It means you cannot dismiss a loss merely because it occurred outside the United States or on non-English pages. For an international site, split the analysis by language, country, directory, hostname, and template. An unaffected English section is not a valid control for a declining Spanish, French, or Japanese section when all languages are in scope.

    The two-week window changes how you should interpret daily charts. A fall followed by a partial rebound may be rollout movement rather than recovery. A section that looks unaffected early in the window may move later. Keep monitoring, but reserve your strongest conclusion until the rollout has had time to finish and the data has begun to settle.

    Diagnose the loss before changing the site

    Four visual evidence streams, including a search pulse, loose cable, seasonal cycle, and broken site component, converge beneath a magnifying lens.

    A decline that overlaps the rollout is correlated with the update; it is not automatically caused by it. Build a short incident record that another person could review without relying on your interpretation.

    1. Mark the monitoring window. Record the update announcement as the start of a provisional window lasting up to two weeks. Do not manufacture an exact completion date before Google confirms one.
    2. Confirm the channel. Separate organic Google traffic from direct, referral, paid, social, email, and other search engines. A fall in total sessions is not evidence of a Google spam-update impact if organic Google performance is stable.
    3. Check more than clicks. Review impressions, average position, landing-page traffic, conversions, and revenue or leads where available. Fewer clicks with stable visibility tells a different story from a broad loss of impressions and rankings.
    4. Segment until a pattern appears. Break results down by branded versus non-branded queries, page type, template, topic, language, country, device, and publishing cohort. Sitewide totals can hide a damaged directory or make one shrinking section look like a domain-wide event.
    5. Find the breakpoint. Identify when the change first becomes visible and whether it is abrupt, gradual, or intermittent. Compare comparable weekdays and established business cycles rather than treating the previous day as a complete baseline.
    6. Inspect competing explanations. Check the deployment log, analytics configuration, consent changes, robots directives, canonical tags, redirects, server availability, indexing controls, migrations, and major campaign changes. A technical release on the same date can imitate an algorithmic loss.
    7. Assign a confidence level. Label the update as likely, possible, or unsupported. Use likely only when timing, channel, affected cohort, and the absence of a stronger alternative explanation all line up.

    Do not let one rank tracker make the diagnosis

    A rank tracker can reveal where to investigate, but a single keyword set may overrepresent one template, location, device, or search intent. Confirm the pattern with first-party search and business data. If tracked rankings fall while impressions, landing-page traffic, and conversions remain normal, you do not yet have evidence for a damaging sitewide hit.

    Likewise, a visibility chart from a third-party platform cannot tell you why movement occurred. Use it to locate affected query groups, then inspect the corresponding URLs and their actual performance.

    Audit the recurring pattern behind affected pages

    Spam-related risk is rarely diagnosed well by staring at the homepage. Start with the cohort that lost visibility. Export its URLs, classify them by template and purpose, and compare them with a genuinely similar cohort that remained stable. The useful question is not whether every declining page is imperfect. It is what the declining pages repeatedly do that the stable pages do not.

    Test purpose, substance, and consistency

    • Purpose: Does each URL satisfy a distinct user need, or do many pages exist mainly to capture slight variations of the same query?
    • Substance: Does the page provide an answer, evidence, comparison, tool, process, or decision support that is specific to its topic? A long template is not automatically substantial.
    • Differentiation: If you remove the product name, city, profession, or keyword from several pages, is most of the remaining material identical?
    • Claim support: Can a reader tell where important claims, numbers, quotations, and recommendations came from? Correct unsupported assertions instead of decorating them with more optimization.
    • Page promise: Does the visible content deliver what the title and main heading promise, or does it delay the answer and redirect the reader toward another page?
    • Editorial reality: Do bylines, review dates, author credentials, and update labels reflect a real process? Do not use trust signals as ornamental fields.
    • Markup consistency: Does structured data accurately describe what a visitor can see? Repair contradictions between schema and the page, but do not expect markup to compensate for weak or duplicative content.
    • Destination value: Does the page stand on its own, or is it mainly a search landing page that funnels visitors elsewhere without resolving the stated need?

    These questions are diagnostic checks, not a claim that September’s update targeted any one of them. Look for concentration. If a questionable characteristic appears equally across stable and declining pages, it is a weaker explanation than a characteristic heavily concentrated in the losing group.

    Do not confuse AI assistance with a diagnosis

    Google did not identify AI-generated content as the target of this update. That means an AI label, by itself, cannot explain a decline. Do not mass-delete content merely because software helped produce it.

    Audit the output instead. Check whether it is accurate, specific, internally consistent, properly supported, and useful for the query. Look for repeated structures that produced shallow pages at scale, but apply the same test to human-written and AI-assisted material. The operational risk is publishing weak patterns repeatedly, not the name of the drafting tool.

    The same restraint applies to AEO, GEO, and schema work. Correct markup that overstates or misrepresents the visible page. Preserve markup that accurately describes strong content. Replacing valid JSON-LD, adding more entities, or expanding FAQ markup is not a sensible first response when the evidence points to duplicative landing pages or unsupported claims.

    Make changes in an order you can evaluate

    Three separated workstations show duplicate page cards being consolidated, one page being repaired, and the result being monitored before further changes.

    Your remediation plan should reduce risk without erasing the evidence. Bulk edits during a moving rollout can make the site impossible to diagnose, and bulk deletion can remove pages that still attract qualified visitors or conversions.

    1. Preserve the baseline. Save the affected URL set, query groups, language and country segments, key metrics, and relevant deployment history. Record the date and owner of every subsequent change.
    2. Stop expanding a suspect pattern. Pause new publication from a clearly questionable template while you investigate. This limits exposure without requiring an immediate sitewide deletion.
    3. Fix the clearest cohort first. Choose one logically related group, such as near-duplicate location pages or unsupported comparison pages. Give each URL a defensible purpose: improve it substantially, consolidate genuine overlap, or remove it when it serves no user need.
    4. Protect technical integrity. Before consolidating or removing URLs, map internal links, redirects, canonicals, indexability, and sitemap entries. Content remediation that creates redirect chains, broken links, accidental noindex directives, or contradictory canonicals adds a second problem.
    5. Review visible content and structured data together. Facts, authorship, dates, products, FAQs, ratings, and organization details should agree across the page and its markup. Correct the underlying page first when both are wrong.
    6. Separate completed work from observed outcomes. Maintain a change log with the affected template, URLs, reason, and date. Do not call an immediate fluctuation a recovery simply because it followed an edit.
    7. Evaluate the same segments again. After the rollout window, compare the affected cohort with its previous baseline and with a similar stable cohort. Watch search visibility and business outcomes; improvement in one vanity metric is not enough.

    If you already know that the site relies on deceptive or manipulative tactics, stop those tactics rather than waiting for perfect attribution. For ambiguous quality problems, work in coherent batches. A controlled repair produces cleaner evidence than rewriting every title, paragraph, internal link, and schema object at once.

    Your next move should be a one-page incident record: the provisional rollout window, affected segments, alternative causes checked, suspected recurring pattern, immediate containment action, and the first page cohort to review. By the time the rollout settles, you will have a decision trail and a repair plan instead of a folder of screenshots and competing theories.

    References


  • Google Ads Controls and Measurement: An Audit Framework

    Google Ads Controls and Measurement: An Audit Framework

    You can hit your cost target and still have a control problem. A campaign average will not show whether a claim is valid in every target country, whether AI matched the right query to the right message, or whether advertising on the destination made the page harder to use.

    To manage Google advertising properly, you need one evidence trail spanning pre-launch permission, automated decisions, and post-click experience. The framework below turns those separate concerns into an audit process you can use before expanding a campaign or increasing its budget.

    Separate controls from observations

    A control determines what should happen. Measurement tells you what did happen. Confusing the two creates familiar mistakes: treating ad approval as proof of legal compliance, treating an AI instruction as a guaranteed constraint, or treating a satisfactory conversion rate as proof that every customer journey was appropriate.

    Build your operating model around four layers. Each layer answers a different question and needs its own evidence.

    LayerQuestion to answerEvidence to retainSuggested owner
    Market permissionWhat may this business claim, promote, and target in this location?Applicable Google policy, law, regulation, local code, review decision, and approval dateCompliance or market approver
    Automation instructionsWhat business, audience, and message context did AI Max receive?Versioned brief, campaign scope, approved claims, and destination mapPaid search owner
    Delivered journeyWhich search term, creative assets, and landing page came together?Observable query-to-creative-to-page combinations and their outcomesChannel analyst
    On-page ad experienceHow much advertising did real users encounter on the site?CrUX ad count, density, CPU weight, and network weightSite experience or monetization owner

    One person can own several layers in a small team. The important part is that no layer disappears into an aggregate dashboard. Cost, conversion volume, and return can tell you whether a campaign is commercially productive. They cannot answer whether a local claim was permitted or explain why a particular search led to a particular page.

    Gate each country before you copy the campaign

    Campaign modules pass through separate country checkpoints where documents, consent, and policy controls are reviewed.

    Geographic expansion is not merely a targeting change. The business may be based in one country while its ads create obligations in every country they reach. Copying a successful campaign into another market can therefore change which claims, disclosures, products, and promotional language require review.

    On September 22, 2026, Google expanded its reference list of advertising and marketing codes for Argentina, Australia, Chile, Colombia, Paraguay, and South Africa. That change matters if you advertise in those markets, but it does not turn Google’s list into a complete statement of local law.

    You remain responsible for the full rule stack: Google Ads policies, applicable laws and regulations, and relevant industry or advertising self-regulatory codes. Google’s local-code references do not replace its existing policies and are not an exhaustive explanation of local requirements.

    Use a launch gate for every country-and-offer combination:

    1. Create a target matrix. Record the country, campaign, offer, audience, domain, landing-page version, and planned launch state. Do not hide several countries inside one approval row.
    2. Inventory the claims. Include headlines, descriptions, asset text, prices, eligibility statements, comparisons, guarantees, testimonials, disclosures, and the claims repeated on the landing page.
    3. Check every applicable layer. Log the Google Ads policy reviewed, the local legal or regulatory question, and any relevant self-regulatory code. A blank field should mean not reviewed, not silently assumed irrelevant.
    4. Attach the decision. Record who approved the claim, what evidence supported the decision, which market it covers, and what conditions or required qualifiers apply.
    5. Define review triggers. Reopen the row when you add a country, change the offer or audience, introduce a new claim, replace a destination, or materially revise the creative.

    Do not treat an accepted ad as legal clearance. Platform eligibility and legal compliance answer different questions. This distinction is especially important in regulated industries, where a small change in wording or audience can change the risk. If the decision depends on interpreting local law, have qualified counsel for that market make it before you launch; a policy reference cannot substitute for jurisdiction-specific legal advice.

    Audit AI Max at the query-creative-page level

    AI-driven search advertising changes the unit you need to inspect. It is no longer enough to review a keyword list, approve a fixed ad, and assume one destination. The useful unit is the complete journey: the search term that expressed intent, the assets the person saw, and the landing page that received the click.

    AI Brief gives AI Max written context about your business, intended audience, and key messaging. Its closed beta has expanded to Dutch, French, German, Italian, Japanese, Portuguese, and Spanish. If the feature is available in your account, the additional languages can help you express market context more directly, but a translated brief does not remove the need for local claim review.

    Build a working brief with five components:

    • Business truth: a precise description of what you sell, who provides it, and what the offer does not include.
    • Audience boundary: the customer need and level of intent the campaign is meant to serve.
    • Message priority: the benefit or differentiator that should lead, supported by approved language.
    • Claim restrictions: statements that are prohibited, conditional, or require a qualifier in each market.
    • Destination map: the approved page for each offer, language, audience, and country.

    Put the business, audience, and messaging context into AI Brief where supported. Keep claim restrictions and destination approvals in your external control register as well. AI Brief supplies context for optimization; it is not evidence that every generated or selected combination passed your legal review.

    Version the brief instead of continually overwriting it. Retain a version identifier, effective date, campaign scope, approving owner, supported languages, and the landing-page map that was current at the time. When performance changes, that record lets you distinguish an automation change from a change in the instructions you supplied.

    Google is also developing a unified reporting view connecting the triggering search term, the creative assets shown, and the landing page reached. No specific launch date has been announced; additional availability details are expected later in 2026. Treat that as planned visibility, not a feature you can assume is already present in every account.

    When the connected view is available, review each journey in this order:

    1. Search term: Does the term express an intent the campaign should serve, and is that intent appropriate for the targeted market?
    2. Creative: Do the shown assets answer that intent without adding an unsupported promise or dropping a required qualifier?
    3. Landing page: Does the destination fulfill the same promise, use the correct market version, and make the next step clear?
    4. Outcome: Did the combination produce the business result you intended, rather than merely generating a click?
    5. Intervention: Should you revise the brief, query control, asset, destination, or market approval before the combination appears again?

    Until unified reporting arrives in your account, reconstruct a sample from the separate data the account exposes. Start with high-spend terms, regulated offers, new markets, and combinations producing weak or surprising outcomes. Record unavailable fields as measurement gaps. Do not infer which asset a user saw merely because that asset currently exists in the library.

    This journey-level review protects you from a misleading average. Strong aggregate performance can coexist with irrelevant queries, mismatched promises, incorrect destinations, or a small number of high-risk combinations. The aggregate tells you where to look; the connected journey tells you what to change.

    Use CrUX to measure the ad load users actually experience

    Two phones show a stable page beside a page whose late-loading ad blocks shift content near a user's hand.

    The click is not the end of advertising measurement. If your landing pages or content pages carry advertising, the site’s own ad stack can consume processing power, transfer data, and occupy the viewport after the visitor arrives.

    Chrome’s public User Experience Report now includes four experimental advertising metrics based on real Chrome user experiences. They measure a different layer from Google Ads reporting:

    CrUX metricWhat it measuresUnit or formOperational question
    Ad Weight – CPUProcessing resources consumed by adsMillisecondsDid the advertising stack create a larger computational burden?
    Ad CountAverage number of ads visible in the viewportAverage countDid the layout expose users to more ads at once?
    Ad DensityAverage share of the viewport occupied by adsPercentageDid commercial inventory crowd out the page’s primary task?
    Ad Weight – NetworkData consumed by advertisingBytesDid ad delivery become heavier for real users?

    Use these metrics as diagnostics, not as a made-up pass-or-fail score. Google added them to its page-experience resources to help site owners evaluate ad experiences, while also cautioning that not every available experience metric is a direct search ranking factor. A movement in an experimental metric does not, by itself, prove why rankings, conversions, or engagement changed.

    A practical review looks like this:

    1. Identify paid-traffic destinations that also display on-site ads. If a page has no advertising, mark this layer not applicable instead of forcing the metrics into its scorecard.
    2. Capture the four metrics at the CrUX scope available to you and establish an internal baseline. Compare like with like inside your own site rather than inventing an unsupported universal threshold.
    3. Annotate ad-stack releases, placement changes, template revisions, and monetization experiments so a later movement has a plausible change record.
    4. Read the metrics together. Rising count or density points you toward quantity and placement; rising CPU or network weight points you toward the technical burden of delivery.
    5. Pair the diagnosis with the business outcome you already trust. The aim is to improve the user experience without pretending that one metric explains every performance change.

    Keep the scope distinction clear. CrUX ad metrics describe advertising experienced on your site. They do not reveal how Google Ads selected a search term, assembled creative, or chose a destination. That is why the journey audit and the on-page experience review belong beside each other rather than being collapsed into one score.

    Key takeaways

    • Separate market permission, automation instructions, delivered journeys, and on-page ad experience. Each layer needs different evidence.
    • Open a new compliance row for every country-and-offer combination. Google’s local-code list is helpful, but it is neither exhaustive nor a replacement for Google Ads policies and applicable law.
    • Treat AI Brief as versioned steering context, not as legal approval or proof that every automated output complied with your restrictions.
    • Evaluate AI Max through the complete search-term, creative, landing-page, and outcome chain. Campaign averages can conceal strategically poor combinations.
    • Use the four experimental CrUX ad metrics to diagnose advertising on your own pages, not to manufacture a ranking score or judge the Google Ads auction.

    Before your next market expansion or material budget increase, create one control-register row for the country and offer in question. Fill in the approved claims, brief version, destination map, observable journey evidence, and CrUX measurements where they apply. If a field has no owner or evidence, resolve that gap before you ask automation to scale it.

    References