This year’s 3·15 Consumer Rights Gala deployed a deceptively straightforward experiment to expose one of the more unsettling realities of the AI era: a wholly fabricated smart wristband, produced at a cost of a few hundred yuan and seeded into the information ecosystem over the course of a few hours, was able to climb to the top of recommendation lists across multiple mainstream large-model AI platforms. As consumers increasingly turn to AI for health advice and product guidance, the ostensibly objective answers they receive may have been carefully pre-positioned well in advance. From invented specifications such as “quantum entanglement sensing” to fully fictitious cosmetic-medicine clinics conjured from nothing, a gray industry chain built around Generative Engine Optimization — known as GEO — is quietly contaminating AI’s information supply at scale. When an AI’s authoritative-sounding answer can be openly purchased, the tension between convenience and truth becomes impossible to ignore.
The “Rise” of a Fabricated Product: A Manipulation Experiment Costing a Few Hundred Yuan
When the words “Large AI models are being poisoned” appeared on screen at this year’s CCTV 3·15 Gala, the initial reaction among many viewers was confusion. Unlike familiar consumer traps — adulterated chicken feet, fraudulent height-increase supplements — “AI poisoning” sounds like a remote technical abstraction. The demonstration that followed, however, sent a chill through both the technology industry and the broader viewing public. A smart wristband that did not exist anywhere in the physical world, seeded with fabricated information at a cost of a few hundred yuan (roughly tens of U.S. dollars) over just a few hours, climbed to the top of mainstream large-model AI recommendation lists and became what those platforms presented as a trusted answer.
The live demonstration laid bare the mechanics of AI recommendation manipulation in near-absurd detail. Industry insiders purchased a piece of software called the Liqing GEO Optimization System from an e-commerce platform and used it to construct a fictitious smart wristband named “Apollo-9,” complete with invented specifications carrying no scientific basis whatsoever — “quantum entanglement sensing” and “black-hole-grade battery life” among them. The software then executed what amounted to one-click fraud: it automatically generated more than a dozen richly illustrated advertorial articles styled as professional reviews, user feedback, and industry rankings. Pre-prepared media accounts distributed the content in batches across the internet. Two hours later, when a reporter queried a mainstream large-model AI about the Apollo-9 wristband, the model not only reproduced the fabricated marketing language verbatim but recommended the product in earnest, describing it as suitable for middle-aged and elderly users as well as health and wellness enthusiasts. Over the following three days, as additional angle-specific fake advertorials continued to be fed into the system, the non-existent product ranked near the top of “smart health wristband recommendations” on two further AI platforms.
This was not an isolated incident. Subsequent investigations by industry media demonstrated how readily the model scales. One reporter spent just RMB 100 (approximately USD 13.89) to fabricate a cosmetic-medicine clinic with no qualifications, no registered address, and no actual staff, supplying invented credentials including a “22-year local legacy” and “Level-4 surgery qualifications.” Within half a day, the clinic appeared at the top of a mainstream model’s recommendations for reliable cosmetic-medicine providers in Liangxi District, Wuxi. A fabricated health supplement brand similarly outcompeted established names such as By-Health and Swisse within hours, appearing in AI recommendations as the more cost-effective alternative.
These experiments demonstrate that the ostensibly objective outputs of current large models can be systematically overwhelmed by a coordinated flood of false information. The question is no longer whether AI can be misled — it plainly can — but that it is being misled at scale, in a structured and deliberate manner, across multiple platforms simultaneously.
The “Black-Hat GEO” Industry Chain Surfaces: From Content Optimization to Data Poisoning
The disorder is underwritten by an emerging industry built around GEO — Generative Engine Optimization. The concept originated as a legitimate extension of digital marketing: by optimizing content to align with the retrieval logic of generative AI models, brands could increase the likelihood of being cited in AI-generated responses. In practice, however, GEO has followed the same trajectory as SEO before it. Just as search engine optimization was progressively colonized by black-hat tactics exploiting technical loopholes, GEO has rapidly developed a shadow branch dedicated to data contamination rather than content quality.
The industry chain is already operating with considerable maturity. At the front end, GEO service providers solicit clients openly on e-commerce platforms and social networks, offering packages ranging from one-time trials to monthly retainers and annual plans priced at tens of thousands of yuan. A GEO operator associated with a firm called Lisi Culture Media told reporters candidly that the appeal of GEO services lies precisely in their dual capacity: they can amplify a client’s own promotional claims while simultaneously degrading competitors’ standing in AI results. Between some major brands, he disclosed, parties spend several million yuan (equivalent to hundreds of thousands of U.S. dollars) using GEO offensively against one another, in competition for the limited recommendation slots available within AI-generated responses.
At the technical midstream, service providers deploy tools such as the Liqing GEO system in combination with AI writing platforms to mass-produce advertorials tailored to client specifications. These articles are produced across multiple formats — expert reviews, industry leaderboards, user testimonials — with sufficient detail to appear credible on casual inspection. Distribution is automated: the software registers accounts, logs in, and publishes across platforms on a continuous 7×24 basis. One GEO provider in Jiangsu reported closing deals with 20 to 30 brands per day on average, publishing roughly ten articles per client daily to maintain keyword rankings across major AI platforms.
At the downstream end, a network of self-media accounts and general-purpose websites serves as the distribution infrastructure for poisoning operations. Specialist publishing platforms have emerged to meet demand, some capable of publishing hundreds of articles per day at a fee of tens of yuan per article (equivalent to several U.S. dollars), forming an indispensable link in the broader contamination chain. The affected sectors span cosmetic medicine, health supplements, consumer electronics, and education — effectively the full breadth of consumer-facing industries.
Using Models to Fight Models: Technical Countermeasures and a Legal Gray Zone
AI platforms are not passive in the face of this escalating challenge. GEO service providers themselves acknowledge that some platforms have begun adjusting their content inclusion logic in response — in particular, downgrading or ceasing to cite leaderboard-style content generated in bulk by automated systems without traceable data sources. The dynamic between AI platforms and the GEO black-market industry has the character of a continuous and evolving contest rather than a settled outcome.
The technical difficulty is inherent to the problem. GEO operators are working against systems of hundreds of billions of parameters that iterate continuously, making manual testing an inadequate response mechanism. The industry’s technical trajectory is consequently moving toward what practitioners describe as “using algorithms to understand algorithms, using models to fight models” — analyzing large models’ retrieval preferences through technical means and adapting to platform countermeasures as they emerge. Platform responses are treated as a given; the offense-defense dynamic is understood as a force that drives both sides to advance rather than a contest with a foreseeable endpoint.
The legal and regulatory framework, however, remains significantly underdeveloped relative to the scale of the problem. Legal researchers note that using GEO to fabricate false rankings is potentially in breach of the Anti-Unfair Competition Law, the Advertising Law, and the Law on the Protection of Consumer Rights and Interests, constituting false advertising and infringement of consumers’ right to know. Shanghai Shenlun Law Firm attorney Xia Hailong observes that current cases predominantly involve exaggeration and false publicity; where specific parties suffer concrete harm, existing law provides avenues for redress. However, judicial precedents specifically addressing GEO-related conduct are virtually nonexistent at present. The more fundamental question is whether existing regulatory frameworks, designed for traditional advertising contexts, are adequate for a form of “cognitive intervention” in which manipulated content is delivered through the seemingly neutral and authoritative voice of a third-party AI system — a mode of influence with considerably greater concealment and reach than conventional advertising.
Immediate Reactions: Platforms, Merchants, and Consumers After the Exposure
The broadcast on the night of March 15 produced rapid chain reactions across the market. Reporters checking e-commerce platforms after the program ended found stores still listing services under names such as “GEO optimization source” and “Qingmu Electronics Digital Technology,” with customer service representatives quoting annual fees of RMB 15,000 to RMB 20,000 (approximately USD 2,083 to USD 2,778). Within minutes of those checks, the stores delisted all GEO-related offerings and customer service communication ceased. The speed and completeness of that disappearance confirmed the industry’s awareness of its own fragility when exposed to public scrutiny.
The broadcast also constituted an impromptu stress test for the AI platforms themselves. Following the program, multiple media organizations queried mainstream large-model AIs with the same question used in the original demonstration — “How is the Apollo-9 smart wristband?” — to assess how platforms had responded. The results were varied. Some AI models identified the wristband as the fabricated product exposed by the 3·15 Gala. Others flagged mixed information and low credibility. Some declined to answer at all. One model that had been misled in the original demonstration, however, treated the product as a potentially emerging brand or a channel-specific item — a result that underscored two significant points: that removing already-embedded false data is technically difficult even after public exposure, and that platforms vary considerably in the robustness of their detection and remediation capabilities.
For ordinary consumers, the exposure functioned as a significant cognitive recalibration. Much of the trust that users place in AI recommendations derives from a presumption of objectivity — a belief that AI, unlike an advertising banner or a commissioned review, has no commercial stake in the answer it provides. The revelation that this presumption is exploitable, and is being exploited systematically, represents a meaningful shift in how consumers will need to engage with AI-generated information, particularly in high-stakes categories such as health products and medical services.
Toward “Trustworthy GEO”: A Market at a Crossroads
The scale of the underlying market ensures that GEO will not simply disappear as a commercial practice. Forecasts from relevant research institutions project that China’s GEO industry could reach RMB 24.0 billion (approximately USD 3.33 billion) by 2030. At that scale, the question of how to channel development toward legitimate uses is a shared challenge for regulators, AI platforms, compliant service providers, and consumers alike.
Regulatory signals have been encouraging. The State Administration for Market Regulation’s Key Points of National Advertising Regulation Work for 2026 explicitly identifies AI-generated advertising as a priority area for concentrated rectification. Industry self-regulation has also accelerated: at the end of 2025, 14 companies jointly initiated the China GEO Industry Development Initiative under the guidance of the China Business Advertising Association. In February 2026, the Artificial Intelligence Industry Development Alliance organized ten companies to sign the Artificial Intelligence Safety Commitment on Generative Engine Optimization, and published a technical specification — Basic Requirements for Trustworthy Generative Engine Optimization Services — setting out standards across dimensions including material review and the integrity of optimization methods. The China Academy of Information and Communications Technology has launched an initial round of related evaluation work.
For AI platforms, experts have proposed that in high-risk verticals, platforms should restrict reliance on open internet corpora and instead connect to curated official whitelist databases. Where AI-generated content has been influenced by commercial payments or anomalous data inputs, prominent disclosure — labeling such outputs as “AI commercial synthesis” — has been suggested as a means of preserving users’ right to informed decision-making.
For consumers, the most dependable defense remains critical engagement. When an AI recommendation sounds implausibly positive, or when an unfamiliar brand appears with an implausible degree of consistency across AI responses, a minute spent on independent verification is well spent: Are the sources cited by the AI traceable and credible? Can key claims be confirmed through official channels or established third-party platforms? Marketing language built around phrases such as “quantum entanglement” and “black-hole-grade” warrants automatic skepticism. In an information environment where the underlying data supply may be contaminated, maintaining that skepticism is the most reliable form of protection available to individual users.
The contest around AI recommendation integrity has only begun. It tests not only the pace of technical countermeasure development, but also the adequacy of regulatory frameworks, the integrity of commercial actors, and the critical awareness of users — the capacity to enjoy the genuine convenience that AI offers while retaining the judgment to know when that convenience is being turned against them.

[Disclaimer]: The above content reflects analysis of publicly available information, expert insights, and BCC research. It does not constitute investment advice. BCC is not responsible for any losses resulting from reliance on the views expressed herein. Investors should exercise caution.
