All resources
Blog

Anthropic's New Claude Rules Ban Fake Source Networks Built to Sway AI Answers

Anthropic's updated Usage Policy, effective November 12, 2026, bans using Claude to seed search engines and AI answer sources with content that misrepresents its origin. Here's what changed and which GEO tactics stay safe.

ANNOUNCEMENT

Anthropic has updated the rules for how people can use Claude, its AI model. The new Usage Policy was announced on October 8, 2026, and takes effect on November 12, 2026.1 One new line matters a lot for anyone working on AI search visibility. It bans using Claude to plant misleading content in the places that search engines and AI tools pull their answers from.2

The rule sits in a brand-new section called "Do Not Engage in Deceptive Campaigns or Artificial Activity." Search Engine Journal reported on the search clause on October 9.3 Here's what changed and what it means for GEO (generative engine optimization, meaning work to get a brand mentioned or cited in AI answers).

What the new rule says, word for word

Here is the exact bullet from the updated policy:

"Manipulate the sources from which search engines or AI systems draw answers by seeding them with content that misrepresents its origin, authorship, or independence (e.g., networks of sites posing as unaffiliated sources corroborating the same claims)"

Source: Anthropic Usage Policy, effective November 12, 2026.2

In plain words, content breaks the rule if it lies about:

  • Origin: where it really came from.
  • Authorship: who really wrote it.
  • Independence: whether it really comes from a separate, unconnected source.

The example in brackets is the key one. It describes websites that look like they're run by different people but are really run by one group. If they all repeat the same claim, an AI tool might treat that as several sources agreeing. That's the trick the rule targets.

The rest of the new section

The search clause is one of six bullets. CONFIRMED, by Anthropic's Usage Policy directly: the section also bans using Claude to:2

  1. Run fake identities. Create or operate fake personas, accounts, media outlets or organizations, or pretend to be real ones, to mislead people. The policy's own examples include sockpuppets, astroturfing (fake grassroots support), fake reviews, and bots that claim to be human.
  2. Hide who paid for a message. Hide or misstate the sponsorship of content meant to influence public opinion, officials or other decision-makers.
  3. Hide a common source. Spread content through "fake or ostensibly independent outlets, websites, or accounts" so that nobody can tell it all comes from one place.
  4. Seed AI answer sources. The search clause quoted above.
  5. Build the tools. Build, improve or maintain tools or systems designed to run deceptive campaigns, such as fake account creation or coordinated inauthentic behavior.
  6. Sell it. Market, sell or raise money for any of the above as a product or service.

Anthropic's announcement explains why the section exists. It says the old policy already banned this kind of activity, but the rules were "scattered across our elections, fraud, privacy, and disinformation sections." The new section pulls them together and applies to deceptive activity "whether political or commercial."1

A point the coverage can blur: Anthropic's announcement post does not mention search engines or AI answers. The search clause appears only in the full policy text.12 So coverage framing this as an AI-answers announcement is reading the policy, not the blog post.

Old policy vs new policy

The previous version of the policy took effect on September 15, 2025.4 Here's how the relevant points compare.

TopicOld policy (September 15, 2025)New policy (November 12, 2026)
Search engines and AI answersNot mentionedExplicit ban on seeding answer sources with content that misrepresents origin, authorship or independence
Fake personasBanned under the misinformation section, when used to falsely attribute contentBanned in the new deceptive campaigns section, with sockpuppets and bots named
Fake reviewsBanned under fraud ("fake reviews, comments, or media")Still banned, now listed as an example of fake identities
Fake media outlets and site networksNo dedicated rule; covered loosely across sectionsNamed directly: fake outlets, and networks of "ostensibly independent" sites
Tools for deceptive campaignsNo dedicated ruleBanned
Selling deception as a serviceNo dedicated ruleBanned
Automated publishingListed as high-risk ("Media or professional journalistic content")Removed from the high-risk list

Sources: archived 2025 policy4 and current policy.2

The quieter change: automated publishing is no longer "high-risk"

The old policy had a "high-risk" list. High-risk uses needed extra safeguards, such as human review and telling people that AI was involved. One item on that list was "Media or professional journalistic content." It covered using Claude to automatically generate content and publish it for outside readers.4

The new policy lists 11 high-risk areas, such as legal, medical, finance, credit, insurance, housing and employment. Publishing is not on the list.2 Anthropic's announcement does not explain why it was removed.13

This means using Claude to publish content no longer triggers the high-risk extra steps on its own. It does not mean anything goes. Deceptive publishing is now covered by the new section instead.

The case behind the rule: 70 fake local news sites

Anthropic links the new section to its September 2026 threat intelligence report.1 That report describes a network of about 70 fabricated news websites set up to look like independent local newsrooms. Anthropic traced it to LKM Company, a France-based digital advertising agency.5

CONFIRMED, by Anthropic's threat report directly:5

DetailWhat the report says
Fake news sitesAbout 70
Articles publishedAt least 8,913
LanguagesAbout 20
Article formatFixed structure, formatted HTML, exact character limits, three to four internal links per article
Stated goal of the articlesTo boost the sites' "authority rankings on search engines"
Real audience reachMost content got "little observable engagement from real audiences"
Anthropic's responseBanned the account and the linked organization, and built new detection methods

Notice what the report does not say. It does not say whether these sites actually ranked better. It also does not say whether they showed up in AI answers.53 So it shows an operation built to game search, caught early. It does not prove the trick worked.

Google already treats this as spam

Google's spam policies define spam as techniques used to deceive users or manipulate Search systems. Its examples include "attempting to manipulate generative AI responses in Google Search."6 On May 15, 2026, Google added a note to its documentation log: it "Clarified that our spam policies also apply to generative AI responses in Google Search."7

Google also says sites that break these policies "may rank lower in results or not appear in results at all."6 Two other Google policies are close to the fake-network problem:

  • Scaled content abuse: making many pages mainly to manipulate rankings, including "Using generative AI tools or other similar tools to generate many pages without adding value for users."6
  • Link spam: creating links "primarily for the purpose of manipulating search rankings."6

The two companies enforce differently. Google can push a site down or remove it from results. Anthropic can limit or cut off a person's or company's access to Claude.3 A brand caught running a fake-source network could face both.

We've covered Google's related guidance before, including its stance on fake author profiles and its advice to fact-check AI content before publishing.

Timeline

DateWhat happened
September 11, 2025The LKM network's sites publish nearly identical articles within three minutes of each other, an example of coordinated behavior described in Anthropic's report5
September 15, 2025Previous Anthropic Usage Policy takes effect4
May 15, 2026Google clarifies its spam policies apply to generative AI responses in Search7
September 2026Anthropic publishes its threat intelligence report describing the fake local news network5
October 8, 2026Anthropic announces its 2026 Usage Policy update1
October 9, 2026Search Engine Journal reports on the search-source clause3
November 12, 2026The new policy takes effect2

What this means for brands and agencies doing GEO

Most GEO work is not affected. The new rule targets lying about where content came from. It does not target trying to be cited by AI tools.

AI tools tend to cite sources that seem trustworthy and independent. Legitimate GEO earns that trust. The prohibited kind fakes it.

Still fine, and still the work that holds up:

  • Original research. Publishing your own data, surveys or tests under your own name.
  • Earned third-party coverage. Real journalists, analysts or customers choosing to write about you.
  • Clear authorship. Content that says who wrote it and who it's from.
  • Using Claude to draft your own content. Publishing under your real brand is allowed, as long as it doesn't misstate who's behind it.

Now named as prohibited when done with Claude:

  • Networks of "independent" review or news sites secretly run by one company.
  • Fake reviewers, fake experts or fake journalists.
  • Unlabeled paid placements made to look like neutral opinion.
  • Building or selling tools or services that do any of the above.

Is this tactic safe? A practical checklist

This table is Ripplix's practitioner reading of the two policies. It is guidance, not legal advice. Edge cases depend on details, so check the policy text and your own counsel for anything close to the line.

GEO tacticAnthropic's new ruleGoogle spam policyOur read
Publishing original research on your own siteNo conflictNo conflictSafe
Pitching journalists and earning real coverageNo conflictNo conflictSafe
Using Claude to draft articles published under your real brand and author namesNo conflict; no longer a high-risk use on its ownFine if pages add value; risky if mass-produced without valueSafe, with review
Clearly labeled sponsored posts on other sitesNo conflict if sponsorship is disclosedWatch link rules and site reputation policyUsually safe
Guest posts that say who the author works forNo conflictRisky if done mainly for links (link spam)Depends on intent
Running several of your own brand sites, openly linked to your companyNo conflict if ownership is clearRisky if they exist mainly to manipulate rankingsUse caution
Paying for reviews or posts without disclosureConflicts (concealed sponsorship)Link spam if links are traded for contentAvoid
Fake customer reviews or fake expert personasConflicts (fake personas, fake reviews)Not named directly, but fits the general definition of deceiving usersAvoid
A network of "independent" sites that all praise your productConflicts (named example in the rule)Likely spam (scaled content, link spam, AI response manipulation)Avoid
Selling any of the above to clientsConflicts (selling as a service)Client sites carry the spam riskAvoid

A quick test for anything not on the list: if a reader learned who was really behind the content, would they feel misled? If yes, the tactic is probably on the wrong side of both policies.

Open questions

  • How will Anthropic detect it? The policy says what's banned. It doesn't explain how Anthropic will spot search-seeding use beyond the detection work described in the threat report.5
  • Why drop publishing from high-risk? Anthropic hasn't said.3

See which sources AI answers actually cite for your brand

Ripplix shows which websites AI answers cite when they talk about your brand and your competitors. That tells you whether your visibility rests on real, independent sources.

Get your free AI Visibility Report →

Sources:

  1. Anthropic: 2026 Usage Policy update (October 8, 2026)
  2. Anthropic: Usage Policy (effective November 12, 2026)
  3. Search Engine Journal: Claude's New Rules Target Fake Sources Built To Sway AI Answers (October 9, 2026)
  4. Anthropic: Usage Policy, archived version (effective September 15, 2025)
  5. Anthropic: Threat Intelligence Report (September 2026)
  6. Google Search Central: Spam policies for Google web search (last updated August 28, 2026)
  7. Google Search Central: Latest documentation updates (May 15, 2026 entry)