Three Google spam updates in one year: what the 2026 pattern reveals about thin content—and AI citability

March, June, August. Three confirmed rollouts, one content floor. And it’s the same floor the LLMs use to decide what to cite.

Google confirmed three spam updates in 2026: March, June, and August. The August rollout finished on the 21st, ten days ago. That’s long enough for the dust to settle and short enough to still read the pattern instead of the panic. And the pattern is the story here—not any single update.

Before I go further, one correction, because it matters and it’s the kind of thing that gets a post-mortem laughed out of the room. If you saw the dates written up as February, May, and August somewhere, that’s wrong on two of three. February 2026 was a Discover core update, not a spam update. May 15 was a revision to the spam policy documentation, not an algorithm rollout. The three confirmed spam updates ran March 24–25, June 24–26, and August 18–21. I checked each one against Google’s own status dashboard, and you should too before you build a recovery plan on a date that never happened.

What each update actually hit

The March update launched on March 24 at 12:18 p.m. PDT and completed the next morning at 7:39 a.m.—a run of roughly 19 hours and 21 minutes. Multiple SEO commentators called it the fastest confirmed spam rollout on record. That speed is not a footnote. As one analysis put it, where spam updates used to take days or weeks, Google now cracks down across the board in hours. A sub-20-hour completion reads as high classifier confidence, not a slow manual sweep. The machine already knew what it was looking for.

June, running the 24th through the 26th, named its targets more explicitly. Coverage of the rollout listed scaled content abuse—publishing high volumes of low-value pages with minimal human input—and expired-domain abuse, where someone buys an old domain for its residual authority and fills it with unrelated content. It also flagged attempts to game AI Overviews with fake citations. Notably, the update explicitly did not target link spam or site-reputation abuse. It was aimed at the content itself.

August began at 9:27 a.m. Pacific on the 18th and completed at 1:49 a.m. PDT on the 21st: 2 days and 16 hours. Google published no companion blog post and announced no new policy categories. Its own line was that this is a normal spam update rolling out for all languages and locations. Read that plainly: the rules didn’t change. The enforcement did. The existing spam policies were already the standard—August just applied them again, with the same confidence the March timing implied.

The false signals that made August feel worse than it was

Here’s what actually caused most of the client panic I fielded in August, and almost none of it was the spam update. Four things overlapped in a two-week window, and only one of them touched rankings.

  • August 1–3 volatility. A cluster of ranking-tracking tools—Sistrix, Mozcast, SEMRush, Mangools, and a dozen others—flagged elevated SERP movement. There was no matching incident on Google’s status dashboard and no confirmed cause. Real churn, unconfirmed origin. Treat it as weather, not climate.
  • An August 4 Ad Manager disruption with co-occurring, reported GA4 anomalies. I couldn’t pin a named, confirmed GA4 data bug to a primary source, so I’ll call it what it is: reported anomalies during a known ad-serving outage. Enough to make a dashboard look broken. Not enough to conclude anything about organic.
  • The GSC Generative AI Impressions logging error, August 13–17. This one is confirmed and it’s the trap. Google’s own help documentation states a logging error decreased impressions in the Generative AI performance report for those five days, and that the issue affects data logging only. John Mueller said it directly: a logging issue, not representative of visibility changes in Search.

Stack those together and you get a client staring at a graph that dips right before a confirmed spam update, convinced they were hit. In several cases the drop was a reporting artifact sitting on top of ad-outage noise sitting on top of unconfirmed volatility—with the actual spam update arriving after the scary part of the chart. The AI-impressions dip in particular fell squarely in the pre-update window, which is exactly how a logging bug gets mistaken for a penalty.

The single thread running through all three

Look at the confirmed casualty profiles across March, June, and August and one trait shows up every time. Not “AI content.” The classifier does not care whether a human or a model typed the words—Google’s own scaled-content policy says so, in the phrase “no matter how it’s created.” What the confirmed casualties share is narrower and more useful to know:

  • No named author. Nobody’s name, reputation, or face attached to the claim.
  • No first-hand signal. No original data, no test result, no “we ran this and here’s what happened.”
  • Structured around a keyword, not a question. The page targets a string, not a thing a person actually wants answered.

That’s the whole profile. Google’s canonical definition of scaled content abuse is content generated “for the primary purpose of manipulating search rankings and not helping users”—unoriginal, low-value, however produced. Expired-domain abuse is the same idea wearing a borrowed domain’s authority. The common denominator is content that could only have been produced by pattern-matching. It restates what’s already out there. It has no reason to exist except to rank.

The bridge nobody else is running: this is also why the LLMs skip you

Now the part that makes this more than another update recap. The site profiles that triggered spam penalties in 2026 are structurally identical to the pages large language models skip when they choose what to cite. I want to be honest about the evidence here, because this is where careless writers overclaim. Perplexity, ChatGPT’s retrieval layer, and Google AI Overviews do not publish citation-selection criteria. Anyone who tells you they know the exact weights is guessing. So I’ll say it the way the evidence supports it.

Practitioners who have mapped citation behavior consistently report the same tendencies: engines lean toward pages with a named, credible author, toward specific verifiable claims over vague summary, and toward content that fully resolves the question it raises. Observed pattern, not platform-documented fact—but a remarkably stable one across tools. And it lines up, almost trait for trait, with the casualty profile above. No author, no first-hand data, keyword-shaped instead of question-shaped: that page loses in the spam classifier and it loses in citation selection, for the same underlying reason. There’s nothing there worth pointing at.

Google made the convergence semi-official this year, too. The spam policy now lists “attempting to manipulate generative AI responses in Google Search” as spam, in the same sentence as manipulating rankings. AI-answer gaming and old-school rank manipulation are now one enforcement scope. The floor is unified from Google’s side. The citation engines just got there independently.

Five site profiles at structural risk

If your site fits one of these, you’re exposed on both fronts. For each, the recovery path is the same shape: add the signal that’s missing, or stop pretending the page needs to exist.

  1. AI content farms—high word count, zero first-hand signal. Long, fluent, and empty. Recovery: rewrite the survivors around genuine original input (a test, a dataset, a client result) and noindex the rest. Word count was never the asset.
  2. Expired-domain redirectors with thin topical authority. An old domain propped up by borrowed history. Recovery: there usually isn’t a graceful one—consolidate anything genuinely useful onto your real domain and let the rest go.
  3. Comparison and affiliate pages with templated pros-cons blocks. The same five bullets every competitor has. Recovery: add first-hand testing, real pricing you verified, and a named reviewer who actually used the products.
  4. Programmatic location pages with interchangeable body copy. “Plumber in [City]” times 400, one paragraph swapped. Recovery: consolidate to the locations you actually serve and make each page specific enough that it couldn’t describe the next town over.
  5. “Answer” pages that restate the query without resolving it. The title asks the question; the body circles it. Recovery: answer it in the first two sentences, then earn the rest of the page with specifics.

An eight-step recovery audit

Ordered, because the sequence matters. Skipping to reconsideration before you’ve confirmed a manual action is how people waste a month.

  1. Identify affected URL clusters by comparing GSC segments pre and post each rollout window (March 24–25, June 24–26, August 18–21). Look for step changes aligned to those dates, not to the August 1–3 noise.
  2. Isolate manual-action URLs from algorithmic drops. Check the Manual Actions report first. Algorithmic and manual recoveries are different work on different timelines—don’t conflate them.
  3. Triage every affected URL into one of three buckets: rewrite, consolidate, or noindex. Most content-farm pages are noindex candidates, not rewrites.
  4. Add dateModified to your JSON-LD with accurate timestamps. Accurate—faking a fresh date is its own manipulation signal.
  5. Layer in real E-E-A-T: a named author byline, a stated methodology, and at least one verifiable external source per major claim. This is the exact layer the citation engines reward, so you’re fixing both problems at once.
  6. Resubmit for reconsideration only if a manual action is actually confirmed. For algorithmic drops, there’s nothing to submit—you wait for reprocessing.
  7. Monitor the GSC Generative AI report only after Google has restored clean logging. Anything you read from the August 13–17 window is corrupted and will mislead you. A dedicated tracker like Cited is useful here too, since it watches how ChatGPT, Perplexity, Gemini, and AI Overviews actually describe you—independent of whichever GSC report happens to be buggy that week.
  8. Set a 90-day re-evaluation milestone. Spam recovery is slow. Judging it at two weeks is how you talk yourself into a second, unnecessary rewrite.

Writing for the 2026 floor means writing for citation, full stop

Put the two checklists side by side—Google spam recovery and AEO readiness—and they overlap by roughly 80 percent. Specificity. Attribution. Verifiable data. Named authorship. A structure that answers the question instead of restating it. Those five appear on both lists. The remaining 20 percent is plumbing: schema markup, crawlability, the technical hygiene that differs slightly between a ranking system and a retrieval system.

Which means teams running Google recovery and AEO readiness as separate projects, with separate owners and separate budgets, are paying twice for one outcome. Fix the content floor once and both problems move. That’s not a slogan—it’s just what happens when a spam classifier and a citation engine independently decide that the same page isn’t worth surfacing.

What to do this week

Pull one report. Take your ten highest-traffic pages and score each on the three-trait test: named author, first-hand signal, question-shaped structure. Any page scoring zero out of three is exposed—to the next spam update and to every citation engine at once. That’s your rewrite queue, in priority order, and you built it in an afternoon.

If you’d rather have that queue built for you against both standards in one pass, that’s exactly what our AI Visibility Audit does—it surfaces ranking-recovery gaps and citation-readiness gaps together, because in 2026 they’re the same gaps. Flat rate, no retainer. If you want to talk through your specific situation first, get in touch.