A March 2026 CCTV 3·15 consumer rights gala showed a black hat GEO (generative engine optimization) attack make a Chinese AI assistant serve a fabricated product as a "standard answer" in two hours.
Two hours of bulk soft content, and an AI assistant invents a product that does not exist. That was the demo that aired on China Central Television's annual 3·15 consumer-rights gala on March 15, 2026: a black-hat GEO provider fed fabricated posts into the open web, and a major Chinese large-model assistant began serving the fake product as a "standard answer" to ordinary questions within two hours (QbitAI on the 3·15 GEO poisoning segment). GEO, or generative-engine optimization, is the practice of shaping what large models say about a brand.
The rest of 2026 turned that segment into a compliance regime. Read together, three 2026 events moved generative-engine optimization from a marketing channel onto a regulated surface: the 3·15 broadcast; the China Academy of Information and Communications Technology's (CAICT) March release of a GEO credible-service standard, 《生成式引擎优化(GEO)服务可信基本要求》; and the Cyberspace Administration of China's (CAC) April 30 "Qinglang" special action, the first time AI data poisoning was named inside a national rectification scope (QbitAI on the CAICT standard and CAC Qinglang action). The cost question is no longer whether to buy GEO but who pays for keeping a brand's AI citation clean.
The KPI shift is the part brand-side buyers have not yet been asked to audit. The traditional Chinese brand-marketing dashboard measured 发稿量 (pieces published). The new dashboard measures 提及率 (mention rate), 引用率 (citation rate), and 语义正向性 (semantic positivity), which are the share of large-model answers in which a brand is named, cited as a source, and described in favorable terms. These are useful questions, and they are also the questions that GEO vendors themselves defined and the ones the industry is now asked to optimize against. The Hanzhi Group, a Guangdong-headquartered enterprise-services firm founded in 2004, markets its GEO product around a GEO-Mix strategy engine, a GEO-Trace traceability engine, and a GEO-R3 efficacy engine, plus a 30-day continuous-monitoring acceptance window (QbitAI on Hanzhi's GEO architecture). The 30-day window is the vendor's commitment, not an audited industry standard.
Volcano Engine, the cloud unit of ByteDance, has published developer documentation positioning GEO as a built-in content-and-distribution workflow for its Doubao AI assistant and search surfaces (Volcano Engine GEO documentation). IT Home's GEO market write-up tracks the same crowding, with both established SEO agencies and content studios re-tooling for AI-answer surfaces (IT Home GEO market coverage). The vendor category now spans three operationally different bets: an enterprise-services firm selling acceptance-based delivery with traceability codes; a cloud vendor turning GEO into a workflow product on its own distribution surface; and a long tail of agencies migrating SEO playbooks into AI-answer monitoring. Each of those bets carries a different compliance risk for a brand buyer.
Three falsifiers should be on every brand-side RFP in 2026. First, AI-native KPIs are vendor-defined. Mention rate, citation rate, and semantic positivity are not yet standardized by CAICT or by any independent measurement body, so the numbers in a vendor dashboard are the same numbers the vendor is selling. Second, the "7-to-14 day core-reasoning iteration cycle and 14-to-30 day source-authority weight adjustment cycle" cited as industry consensus in vendor and sponsored coverage is not attributed to any specific AI platform, CAICT paper, or independent researcher. A 30-day acceptance window in a contract is a vendor commitment to chase a moving target it does not fully control. Third, "30-day continuous monitoring" is a service-level claim, not a compliance audit. The CAICT credible-service standard names traceability and acceptance as properties of a credible service; it doesn't specify what counts as a passing trace, a passing acceptance, or a passing dispute.
The China Internet Network Information Center (CNNIC) counted 6.02亿 (≈602 million) generative-AI users in China by December 2025, up 141.7% from a year earlier (CNNIC figures cited in QbitAI). Mobile-analytics firm QuestMobile counted 4.46亿 (≈446 million) domestic AI-native app users by March 2026. Hundreds of millions of queries per month in China now pass through assistants that can be poisoned in two hours and reweighted in two weeks, and the regulatory surface that just landed is the first time those numbers sit under a state-defined credible-service standard.
The next test is whether CAICT's GEO credible-service pilot and the Qinglang action produce a public list of named compliant providers, an audited KPI standard, or both. Brand-side buyers are now signing GEO contracts against a compliance regime that defines the surface but has not yet defined the measurement.