Securitylab•August 21, 2026•🇷🇺Translated from Russian

Google Issues Clear 2026 Guidance: No Separate SEO for AI Overviews or AI Mode

Generative search has spawned a new SEO industry faster than search engines could explain the rules. Site owners are being advised to create llms.txt files, rewrite articles for neural networks, split text into special blocks, publish hundreds of pages targeting long questions, and buy brand mentions on forums. Some recommendations are harmless, others useless, while certain tactics risk pushing sites into the same territory Google has spent years trying to clear of doorway pages and mass low-quality content.

By August 2026 Google’s position became much clearer. The company released separate guidance on optimization for generative search functions and explicitly stated that no dedicated SEO for AI Overviews and AI Mode exists. From Google’s perspective, visibility work in generative search remains ordinary search optimization. A page must be reachable by the crawler, enter the index, match user intent, and contain information Google considers useful and sufficiently trustworthy.

Yet the conclusion “nothing has changed” would also be incorrect. Classic search mainly selected documents and showed them to the user. Generative search first selects documents, then extracts facts, compares information, and assembles its own answer. A site now competes at several stages simultaneously: it must be found, chosen among candidates, used as a source, and ideally receive a link the user actually clicks.

How Google Collects AI Answers and Why This Changes SEO

AI Overviews and AI Mode rely on Google’s search index and core ranking systems. The generative system receives relevant pages from search, extracts information, and uses the material when constructing responses. Consequently, no separate “AI index” exists that site owners can target with special techniques.

A second key mechanism Google calls query fan-out. The model can take one complex question and run multiple additional searches in parallel. A user asking which backup system a small company should choose after a ransomware attack may trigger separate searches on recovery speed, copy isolation, cost, cloud storage, compatibility, and protection of administrative accounts.

The old notion that “one query equals one SEO page” begins to break down. Site owners cannot and should not guess every additional question the model will formulate behind the scenes. It is far more effective to build a thematic content system where the search engine can reliably find good answers to different parts of the user’s task.

Do Not Turn Query Fan-Out into a Landing-Page Factory

Generative search unexpectedly returns practitioners to rules that have existed for more than a decade. Google has long fought doorway pages. Modern versions look more polished: instead of thousands of pages titled “laptop repair Moscow,” “laptop repair Khimki,” and “laptop repair Mytishchi,” creators are now encouraged to publish thousands of pages targeting questions an AI might supposedly generate. The mechanics remain unchanged.

Google’s spam policies specifically address scaled content abuse. It does not matter whether pages are written by humans, templates, or generative models. The problem arises when a site produces large volumes of low-originality content primarily to manipulate search coverage.

Landing Pages Are Not Dead — Poor Landing Pages Simply Became Weaker

Good landing pages solve the user’s task directly rather than serving as doors to other pages. The typical commercial landing page suffers from informational emptiness: vague promises, identical benefits, hidden pricing, and missing limitations. For a generative system such a document is almost useless.

Google recommends creating non-commodity content — information that cannot be easily replaced by dozens of similar publications. Own experiments, statistics, interviews, product tests, and detailed real-world implementation analyses are far harder to substitute.

Technical Optimization Starts with Basics

Before experimenting with GEO techniques, site owners should open Search Console and perform a standard technical audit: verify indexing of important URLs, check robots.txt and CDN protections, review noindex and canonical tags, ensure correct server response codes, maintain an up-to-date XML sitemap, and confirm mobile usability. No special technical requirements have been introduced for generative features.

Structured Data Remains Useful but No AI-Specific Schema Exists

Google states that structured data are not a separate requirement for AI Overviews or AI Mode. Standard Schema.org markup for Product, Person, Article, Organization, and LocalBusiness continues to help the engine understand content and participate in rich results.

Measurement and Future Outlook

Google has begun rolling out dedicated reporting in Search Console for generative visibility. Site owners are advised to track indexing, generative impressions, ordinary search performance, traffic from AI services, and downstream conversions rather than relying on a single metric. The next evolution involves AI agents that not only answer questions but also perform actions, making semantic HTML, accessible forms, and clearly structured data even more valuable.

Related articles

Habr•Other

Good Bear 1.0 Released: Firefox-Based Browser with Isolated Russian PKI Trust Container

Good Bear 1.0 is a Russian-language browser built on Firefox 156.0 that provides an isolated container for handling Russian PKI certificates without mixing trust contexts or user data with the standard browsing session. The release includes .deb packages for Ubuntu 24.04 LTS amd64 and Windows x64 installers, using Mozilla Public License 2.0 and reproducible build processes from pinned Firefox sources. Instead of globally importing root certificates, the browser performs secondary chain validation only inside a dedicated userContextId container with strict OriginAttributes isolation for caches, storage, and connections. Password autofill and sensitive session data are disabled in the container when separation cannot be guaranteed, and POST requests trigger explicit user choice before reopening in the isolated context. The interface shows both a persistent container marker and a separate RU indicator only when Russian PKI is actively used, along with detailed security panels explaining the trust source. Updates, crash reporting, and automatic MAR mechanisms are intentionally omitted to avoid creating unverified trust chains for the distribution itself.

Habr•Other

Survey of 254 Russian Domains Shows 89% DMARC Adoption but Highlights Gaps in Reporting and Subdomain Policies

A manual review of public DNS records across 254 prominent Russian domains from 17 sectors found strong baseline adoption of email authentication mechanisms. MX records appeared in 96.1% of domains, SPF in 93.7%, DMARC in 89.0%, and DKIM records via common selectors in 62.2%. Among domains with DMARC, 40.7% published a reject policy and 42.9% used quarantine, while 16.4% remained at none. Notably, 19% of DMARC-enabled domains lacked any rua address for aggregate reports, including 33 domains enforcing reject or quarantine. The study also identified cases of inconsistent policies between parent domains and subdomains, as well as SPF records ending in ~all paired with strict DMARC settings. Researchers emphasized that DNS data alone cannot confirm actual mail flow alignment or report consumption.

AntiMalware•Other

Server Outage Halts Vehicle Registration Across Smolensk Region

A technical failure on a unified server has temporarily suspended vehicle registration services in the Smolensk region of Russia. The outage affects the interdistrict traffic police department No.1 located on Lavochkina street, preventing new registrations from being processed. Regional UMVD officials confirmed that the problem impacts the single server used for the entire oblast's registration system. According to department head Maxim Zykov, the disruption is considered temporary, though no precise restoration timeline was provided. Applicants who submitted requests through the Gosuslugi portal will receive services in the first working days after the system is restored. The UMVD plans to issue an additional announcement once operations resume.

Securitylab•Other

Pivoting in Legacy Hell: Navigating MIPS Servers, BusyBox, and 2014 Kernels During Internal Network Assessments

The article details a complete methodology for pivoting from an initial SSH compromise on an old Debian MIPS server to reach a hidden web admin panel inside a segmented network. It covers environment enumeration with commands like uname -a and ip route, followed by setting up a Chisel-based SOCKS5 proxy when standard SSH dynamic forwarding is disabled by server configuration. Scanning proceeds via proxychains with nmap using -sT, -Pn, and -n flags or by deploying static MIPS binaries directly on the host. Traffic is then routed through Burp Suite chained to the SOCKS proxy for password guessing against the web interface. The piece emphasizes practical constraints such as BusyBox limitations, kernel version incompatibilities with modern binaries, and the need for careful subnet identification. Readers are directed to replicate the full chain in the Forgotten Server task from the free White Hacker Profession course.