Gli assistenti AI di coding sono sicuri? Il caso xAI


Gli strumenti di AI per lo sviluppo software promettono di aumentare la produttività degli sviluppatori, ma una recente analisi indipendente riaccende il dibattito sulla sicurezza dei dati affidati agli assistenti di coding. Al centro della vicenda c’è Grok Build, il tool a riga di comando di xAI, accusato di aver trasmesso (in chiaro) ai server dell’azienda interi repository Git, cronologia compresa, insieme a file contenenti credenziali e altri dati sensibili. Secondo il ricercatore che ha condotto l’analisi, inoltre, il comportamento sarebbe avvenuto anche dopo aver attivato l’opzione di esclusione dall’addestramento del modello.

Un’analisi del traffico di rete fa emergere il problema

La vicenda nasce dall’analisi del traffico di rete effettuata dal ricercatore noto come cereblab, che ha instradato Grok Build attraverso mitmproxy per osservare nel dettaglio le comunicazioni tra il client e i server remoti. L’obiettivo era verificare quali dati venissero realmente inviati durante una normale sessione di sviluppo. I risultati non sono stati quelli sperati. Secondo il report, il software avrebbe aperto due canali distinti di comunicazione: uno destinato alle richieste del modello AI e un secondo utilizzato per il caricamento del codice (un comportamento decisamente non atteso e che ha allarmato il ricercatore).

Nel test effettuato su un repository Git di circa 12 GB, il traffico destinato al modello AI sarebbe stato limitato a circa 192 KB, mentre il canale di storage avrebbe trasferito 5,10 GiB di dati suddivisi in 73 blocchi da circa 75 MB ciascuno. Il rapporto tra i due flussi supera le 27.800 volte, un valore incompatibile con il semplice invio del contesto necessario alla conversazione con il modello e che di solito giustifica connessioni parallele. L’analisi sostiene inoltre che il contenuto inviato corrispondesse a un bundle Git completo, comprendente non solo i file correnti ma anche la cronologia del repository.

Anche i segreti sarebbero finiti nel trasferimento

Ancora più delicata è la parte relativa ai secret presenti nel progetto. Durante il test il ricercatore ha inserito volutamente un file .env contenente chiavi API e credenziali fittizie facilmente identificabili. Secondo quanto documentato, tali informazioni sarebbero state trasmesse integralmente durante la comunicazione con i server di xAI. Inoltre, ricostruendo il bundle Git catturato durante il trasferimento, il ricercatore afferma di aver recuperato anche un file che l’agente era stato esplicitamente istruito a non leggere, suggerendo che il caricamento del repository fosse indipendente dalle operazioni realmente effettuate dal modello.

Uno degli aspetti più controversi, secondo cerelab, riguarda l’impostazione “Improve the model”, utilizzata per escludere i propri dati dall’addestramento dell’intelligenza artificiale. Secondo la sua analisi, la disattivazione di questa opzione non avrebbe impedito il trasferimento del repository, ma soltanto il suo eventuale utilizzo per l’addestramento del modello. In altre parole, il codice continuerebbe comunque a lasciare la macchina dello sviluppatore per essere archiviato sui sistemi remoti. Si tratta di una distinzione importante, perché trasmissione, archiviazione e addestramento rappresentano tre aspetti differenti dal punto di vista della sicurezza e della conformità normativa.

xAI avrebbe già modificato il comportamento del servizio

La vicenda, tuttavia, sembra aver avuto un’evoluzione molto rapida. Nei giorni successivi alla pubblicazione del report, lo stesso ricercatore ha ripetuto i test osservando un comportamento differente. In sei prove consecutive non sarebbe più stato rilevato alcun caricamento del repository tramite l’endpoint dedicato allo storage. Al suo posto sarebbero comparsi nuovi flag server-side, tra cui disable_codebase_upload, che sembrerebbero disattivare la funzione senza richiedere un aggiornamento del client. Al momento, però, xAI non ha pubblicato alcun advisory di sicurezza, né un changelog che spieghi ufficialmente la modifica o chiarisca quale sia stato l’impatto del problema sugli utenti che hanno utilizzato Grok Build prima della mitigazione. Anche le note di rilascio più recenti del progetto non fanno riferimento alla questione.

Una lezione per tutti gli agenti di coding

Al di là del singolo caso, l’episodio evidenzia una criticità destinata a diventare sempre più rilevante con la diffusione degli AI coding agent. Molti sviluppatori tendono infatti a considerare questi strumenti come semplici assistenti locali, mentre nella maggior parte dei casi il lavoro viene svolto su infrastrutture cloud. Per le organizzazioni questo significa che repository, codice proprietario, segreti applicativi e informazioni sensibili potrebbero lasciare il perimetro aziendale se non vengono definite precise policy di utilizzo. E addirittura, questo potrebbe succedere anche se le opzioni di non condivisione sono attive, richiedendo una infrastruttura di controllo che vada oltre la semplice policy.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2026/07/14/gli-assistenti-ai-di-coding-sono-sicuri-il-caso-xai/?utm_source=rss&utm_medium=rss&utm_campaign=gli-assistenti-ai-di-coding-sono-sicuri-il-caso-xai




La guerra ucraina cambia la cybersecurity delle infrastrutture critiche


La guerra in Ucraina non si combatte solo sul terreno, nel mare o nello spazio aereo. Il cyberspazio è uno degli scenari più attivi, dove vengono perpetrati quotidianamente decine di attacchi mirati alle infrastrutture civili e militari. Il continuo bersagliamento di infrastrutture energetiche, reti di comunicazione e servizi pubblici ha praticamente trasformato l’intero Paese in un enorme laboratorio dove si sviluppa la cyber-resilienza. Ma una cosa è proteggere le infrastrutture critiche civili, un’altra quelle militari e, ovviamente, l’Ucraina non ha abbastanza risorse interne per far fronte all’enorme numero di problemi da affrontare. Per questo è stato creato il Tallinn Mechanism, un’iniziativa internazionale nata per sostenere la resilienza digitale delle infrastrutture civili del Paese e che, indirettamente, sta contribuendo ad accrescere anche le capacità difensive delle aziende europee. Ne abbiamo parlato con Alessio Aceti, CEO di HWG Sababa, azienda impegnata in prima fila.

Cos’è il Tallinn Mechanism

Nonostante il nome possa trarre in inganno, il Tallinn Mechanism non è un organismo con sede in Estonia. Il nome deriva semplicemente dalla città in cui si è svolto il primo incontro istituzionale. Si tratta di un programma internazionale di cooperazione civile che coinvolge diversi Paesi europei, insieme a Stati Uniti e Canada, con l’obiettivo di sostenere la digitalizzazione e la sicurezza delle infrastrutture civili ucraine, comprese quelle considerate critiche. Un elemento distintivo dell’iniziativa è la sua natura prettamente civile. Pur essendo presente come osservatore, la NATO non partecipa direttamente alle attività operative.

Il meccanismo funziona come una piattaforma di collaborazione tra settore pubblico e privato. Le istituzioni ucraine pubblicano le proprie esigenze attraverso un portale dedicato, mentre aziende e organizzazioni dei Paesi aderenti partecipano a bandi finanziati dai governi per fornire competenze, tecnologie e servizi. Dal 1° luglio al 31 dicembre, inoltre, l’Italia assume il coordinamento del programma, con il compito di facilitare la collaborazione tra istituzioni e industria.

La formazione OT per le infrastrutture ucraine e il ritorno per l’Italia

Come già accennato, tra le realtà coinvolte figura HWG Sababa che insieme al Competence Center Cyber 4.0 e a partner francesi si è aggiudicata un progetto dedicato alla formazione sulla sicurezza OT (Operational Technology). L’attività è rivolta ai tecnici che operano nelle infrastrutture critiche ucraine, in particolare nei settori della produzione e distribuzione dell’energia.

L’approccio adottato si discosta dalla formazione tradizionale. Le esercitazioni sono infatti costruite attorno a laboratori pratici nei quali gli operatori lavorano direttamente su PLC, sistemi SCADA e digital substation, simulando attacchi realistici e imparando tecniche di rilevamento, contenimento e risposta in uno scenario caratterizzato da minacce costanti. L’aspetto forse più interessante emerso dall’esperienza raccontata durante l’intervista riguarda il valore che queste attività generano anche per il sistema Paese. L’Ucraina rappresenta infatti uno degli ambienti in cui vengono sperimentate per prime nuove tecniche, tattiche e procedure (TTP) adottate dagli attaccanti. Molte delle infrastrutture utilizzate nel Paese impiegano gli stessi sistemi industriali presenti anche nelle aziende italiane, inclusi prodotti di vendor internazionali come Schneider Electric e ABB. Questo consente agli specialisti coinvolti di osservare direttamente modalità di attacco che potrebbero arrivare successivamente anche nell’Europa occidentale. L’esperienza maturata sul campo permette quindi di anticipare le difese, identificando vulnerabilità e sviluppando contromisure prima che determinate campagne diventino una minaccia concreta anche per le organizzazioni italiane.

La guerra cambia anche il cybercrime

Un altro elemento evidenziato durante l’intervista riguarda l’evoluzione delle minacce. Le tecniche sviluppate dai gruppi riconducibili agli Stati-nazione tendono infatti, con il passare del tempo, a essere riutilizzate anche dalla criminalità informatica tradizionale. Secondo gli esperti, questo fenomeno rischia di accelerare ulteriormente con la diffusione dell’Intelligenza Artificiale, che potrebbe abbassare le competenze necessarie per sviluppare campagne offensive sempre più sofisticate. Di conseguenza, strumenti e metodologie oggi osservati in scenari di guerra potrebbero trasformarsi domani nelle tecniche utilizzate dai gruppi ransomware contro aziende di ogni dimensione.

Cybersecurity e sovranità digitale viaggiano insieme

L’esperienza del Tallinn Mechanism alimenta anche una riflessione più ampia sul tema della sovranità digitale. Secondo quanto emerso nell’intervista, costruire competenze nazionali, sviluppare servizi ad alto valore aggiunto e rafforzare la collaborazione tra imprese italiane rappresenta un elemento fondamentale per ridurre la dipendenza tecnologica dall’estero. In quest’ottica, la federazione di competenze e servizi diventa un fattore strategico non soltanto per la cybersecurity, ma anche per la competitività industriale del Paese.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2026/07/10/la-guerra-ucraina-cambia-la-cybersecurity-delle-infrastrutture-critiche/?utm_source=rss&utm_medium=rss&utm_campaign=la-guerra-ucraina-cambia-la-cybersecurity-delle-infrastrutture-critiche




Google’s New Merchant Listing Structured Data Improves SEO via @sejournal, @martinibuster

Google made a major change to their Merchant Listing structured data requirements in addition to adding clarification on how to use structured data to indicate how long a sale prices will last. In total, there are three new additions but the biggest change by far is the addition of a new Category property. While it’s not a “required” structured data property it’s still a recommended one.

New Category Property

In Schema.org structured data, a Type is a classification of an entity, to say what something is. A structured data Property is an attribute of the Type, it can say what kind of type or add other descriptive details about the Type.

Google added a new category property to the Product structured data, which enables merchants to more granularly classify products directly in markup rather than relying solely on feed attributes. It also gives merchants a way to tie the web page structured data to Google’s own product taxonomy, closing a gap between what’s marked up on the page and what’s submitted through the Merchant Center feed.

Google’s new category property accepts either plain text or a CategoryCode object.

Plain Text

Plain text works like the existing product_type attribute in product feeds. It’s a custom category label that merchants define themselves.

CategoryCode

CategoryCode is a structured object that lets you declare a Google Product Category (GPC) directly in markup, using inCodeSet to point to Google’s taxonomy and codeValue to specify the category, either by numeric ID or full path. The CategoryCode object directly corresponds to the merchant feed specific Google Product Category (GPC). CategoryCode enables merchants to put that same GPC value directly into their on-page structured data instead of it only appearing in the merchant feed.

Here is example structured data showing how it works:

"category": [
{ "@type": "CategoryCode", "inCodeSet": "https://www.google.com/basepages/producttype/taxonomy-with-ids.en-US.txt", "codeValue": "2271"
},
{ "@type": "CategoryCode", "inCodeSet": "https://www.google.com/basepages/producttype/taxonomy-with-ids.en-US.txt", "codeValue": "Apparel & Accessories > Clothing > Dresses"
}, "Dresses", "Special Occasion > Wedding & Bridal Party Dresses"
]

Google’s new guidance explains:

“Text or CategoryCode

Specifies the product’s categories. This property can accept an array of values, mixing plain text strings and CategoryCode objects.

Custom product types: Plain Text values represent your custom product category, similar to the product_type attribute in product feeds. We recommend keeping custom product types under the 750-character limit.

Google Product Category (GPC): To specify a GPC, similar to the google_product_category attribute in product feeds, use the CategoryCode type.

Set @type to CategoryCode.

Set inCodeSet to a Google Product Taxonomy URL (for example, “https://www.google.com/basepages/producttype/taxonomy-with-ids.en-US.txt”).

Set codeValue to the GPC ID (for example, “2271”) or the full category path (for example, “Apparel & Accessories > Clothing > Dresses”).

When using the path format, use > as the separator between levels. Each segment in the path must contain at least one letter. Numeric IDs are also accepted.
You can provide multiple category values. For example, you can include several GPC codes or paths and several custom product type strings.”

Sale Duration Structured Data

Google also added a new section to the Merchant Listing structured data documentation that enables merchants to express how long a sale will last. It adds new documentation about three properties:

  • priceValidUntil
  • validFrom
  • validThrough

Here are the new explanations:

“priceValidUntil

Date

The date and time after which the price will no longer be available, in ISO 8601 format. Your listing may not display if the priceValidUntil property indicates a past date. For details and markup examples, see Sale duration.

validFrom
DateTime or Date

The start date and time when the price is valid, in ISO 8601 format. For details and markup examples, see Sale duration.

validThrough
DateTime or Date

The end date and time when the price is valid, in ISO 8601 format. For details and markup examples, see Sale duration.”

Sale Duration

Lastly there is an entirely new section about Sale Duration. Sale duration is just the date that corresponds to the three structured data properties, priceValidUntil, validFrom, and validThrough. It tells Google exactly when a sale price starts and ends. It’s meant to keep sale pricing accurate in search results, so a listing doesn’t keep showing a deal after it’s expired.

The new documentation explains:

“Sale duration
To specify the period when a sale price is active, use the following schema.org properties in ISO 8601 format (for example, 2025-12-31T23:59:59+01:00):

Start date and time: Use the validFrom property.
End date and time: Use either the validThrough property or the priceValidUntil property.

Best practices:
Provide both a start and an end date/time to clearly define the sale period.
Ensure the start date/time (from the validFrom property) is earlier than or equal to the end date/time (from the validThrough property or the priceValidUntil property).

We recommend including the time and timezone in the ISO 8601 format for accuracy in Google systems.

Where to place the properties:
On the Offer node: You can add the validFrom property and (the validThrough property or the priceValidUntil property) directly to the Offer node. These dates apply when the price property on the Offer node represents the current active sale price.

On a PriceSpecification node: If the sale price is defined within a PriceSpecification node (typically one without the priceType property when a StrikethroughPrice value is also present), add the validFrom property and the validThrough property to that specific PriceSpecification node. Note that the priceValidUntil property isn’t applicable to the PriceSpecification type.”

How It Benefits Merchants

Google’s new documentation for the Merchant Listing Structured Data enables merchants to express category and sale pricing details directly in structured data, which helps Google display accurate product information in the search results. The new structured data properties create unity between the Schema.org structured data and the Merchant Feed Google Product Category (GPC) data. Category now matches product_type and google_product_category from Merchant Center feeds, and Sale Duration matches sale_price_effective_date, so merchants have a page-level way to express them instead of relying solely on the feed.

Featured Image by Shutterstock/allegro

https://www.searchenginejournal.com/googles-new-merchant-listing-structured-data-improves-seo/581879/




YouTube Moves Ahead of Spotify As UK’s Top Podcast Service via @sejournal, @MattGSouthern

YouTube has become the top podcast platform in the UK, surpassing Spotify for the first time on record, according to Edison Research. Among weekly podcast listeners aged 15 and over, 29% now cite YouTube as their preferred service, compared to 28% for Spotify.

The one-point gap is quite small, and Edison describes the outcome as a first “on record” rather than a confirmed new trend. Edison Research at SSRS previewed YouTube’s rapid rise to become the top podcast service in the UK, ahead of a more detailed report expected later this month.

What the Data Shows

Edison’s trend data shows YouTube’s growth in the UK over four key periods. In 2023, YouTube held 19% of the primary platform share, increasing modestly to 20% in 2024, then rising to 25% in 2025, and reaching 29% in the first quarter of 2026. Meanwhile, Spotify’s share declined over the same timeframe, starting at 33% in 2023, slightly increasing to 34% in 2024, then dropping to 30% in 2025, and finally down to 28% currently.

BBC Sounds is the third most-used service, with 15% in the current reading, maintaining that share from 2024 and 2025, after 13% in 2023. Apple Podcasts holds 10%, a decrease from 12% in 2023. The remaining apps are grouped into an “Other” category, which makes up 18%.

Edison Podcast Metrics UK is based on interviews with 8,000 UK podcast listeners aged 15 and over each year. Edison did not disclose the sample size behind the Q1 2026 reading.

The US Crossover Came First

YouTube reached the top of the US podcast rankings about two years before the UK. In Edison’s US reading from October 2024, YouTube took 31% of primary-platform share among weekly podcast listeners aged 13 and over, against Spotify’s 27% and Apple Podcasts’ 15%. Edison tied much of the US move to younger listeners and video, reporting that 84% of Gen Z monthly podcast listeners ever listen to or watch podcasts with a video component.

SEJ has covered how YouTube reported more than one billion monthly active viewers of podcast content and became the platform Americans use most. The UK reading extends that same video-native pattern to a second major market.

Why Edison Says the UK Trailed the US

Edison points to the UK’s public-media presence as a possible reason YouTube climbed more slowly in the UK than in the US. BBC Sounds draws 15% of UK podcast consumers as their main service, a level Edison says has no equal among US public-media podcast offerings. A UK listener choosing among YouTube, Spotify, Apple Podcasts, and BBC Sounds weighs a different set of options than a US listener choosing among the first three, which Edison gives as part of why the two markets moved at different speeds.

Why This Matters

The UK now looks like the US did two years ago, and the direction of Edison’s trend line matters more than the one-point margin. For a show deciding where to make its main home, YouTube is now the platform the largest share of UK weekly listeners name.

BBC Sounds is the caveat when you compare the UK with the US. A UK plan built on American platform-share assumptions understates how much of the domestic audience sits with a public-service option the US market doesn’t have. The Edison data gives a UK-focused show a reason to invest in video, as long as that BBC Sounds share stays in the model.

Looking Ahead

Edison will host a webinar on July 16, 2026, at 2pm BST and 9am EDT to present the full UK Podcast Consumer 2026 report. The session will also explore UK audience opinions on AI in podcasting, which will be of interest once the data is publicly available.

The lead is one point, and Spotify has slipped from 34% in 2024 to 28% now while YouTube’s gains have held across the series. The next reading will show whether the order holds beyond this first crossover.


Featured Image: sitthiphong/Shutterstock

https://www.searchenginejournal.com/youtube-moves-ahead-of-spotify-as-uks-top-podcast-service/581832/




Google Search Hits All-Time Usage Record During World Cup via @sejournal, @MattGSouthern

Nick Fox, Google’s senior vice president of Knowledge & Information, said that Google Search reached its highest usage ever on July 7, coinciding with Argentina’s comeback victory over Egypt at the World Cup.

In the post, Fox wrote: “Google Search broke all prior usage records and saw its highest usage in history right after Argentina scored their winning goal in yesterday’s match!”

Robby Stein, vice president of product for Google Search, amplified the post, writing that Search “hit all time high in usage yesterday.”

Fox didn’t share any specific figures or methods for the record, and Google hasn’t released a blog post or data about it.

The statement is consistent with Google’s public messaging this year. During its Q1 2026 earnings call, Pichai mentioned that “Search queries are at an all-time high,” though specific numbers weren’t shared.

Google has pointed to a World Cup traffic record before. In the 2022 final, Pichai stated that Search reached its highest traffic in 25 years, again without providing exact figures.

Argentina defeated Egypt 3-2 in the Round of 16 on July 7, overturning a two-goal deficit with Enzo Fernández scoring a stoppage-time winning header. Their quarterfinal against Switzerland is next, which tracks with Fox’s line about looking ahead to “the semis and final.”

Why This Matters

There’s been a lot of talk recently about whether AI answers are changing the way we search. A record day, if it holds up, is a reminder that Google is still where people turn the moment something happens live.

Keep in mind that ‘record usage’ and ‘record queries’ refer to Google’s side, not clicks to publisher sites. It’s possible for search usage to increase even when outbound clicks to your pages remain low.

Fox also didn’t define how “usage” is counted, or say whether the figure excludes bots. Imperva, which sells bot-management tools, estimated that automated traffic made up more than 53% of web traffic in 2025, up from 51% in 2024. None of that shows Google’s record was driven by bots. Without a clear methodology, it’s hard for external readers to understand exactly how Google counts automated traffic.

Looking Ahead

Google put no figures behind the 2022 claim and none behind this one, so whether it backs the record with data is the thing to watch. Argentina’s quarterfinal is next, and another usage spike is possible if the run continues.

https://www.searchenginejournal.com/google-says-search-hit-all-time-usage-high-during-world-cup/581796/




Google Ads Expands Travel Campaigns To Things To Do And Events via @sejournal, @brookeosmundson

Google Ads is expanding its Search campaigns for Travel beta to two additional verticals: Things to Do and Events.

Google announced the update in a post on X and LinkedIn on July 8, 2026. Advertisers selling attractions, tours, and event tickets can now access the campaign type through an open beta, although availability remains limited.

The expansion gives eligible advertisers another campaign option to test alongside existing Search ands Performance Max campaigns.

What’s Changing With Search Campaigns For Travel

Search campaigns for Travel is a Google Ads campaign type designed for travel-related advertisers. It first appeared as Google expanded AI-powered campaign types across Travel and Shopping earlier this year.

With this update, the beta now extends beyond traditional travel categories to include Things to Do and Events. That means advertisers promoting attractions, guided tours, and event tickets may now be eligible to use the campaign type.

The announcement came as part of a five-post thread. At the time of writing, Google has not shared complete details around eligibility, supported features, or geographic availability.

Why This Matters

Attractions, tours, and event tickets share many of the same characteristics as hotel or airline bookings. Availability changes frequently, pricing can fluctuate, and purchase decisions are often tied to specific dates or locations. Those are all areas where Google’s newer campaign types have increasingly relied on automation to determine which searches are most likely to convert.

Until now, advertisers in these verticals have generally relied on standard Search campaigns or Performance Max. Expanding the Travel campaign type suggests Google sees these businesses as a natural fit for a more specialized campaign format.

The update also aligns with Google’s broader push toward AI-driven campaign management. Over the past year, the company has introduced AI Max across additional campaign types while continuing to consolidate older campaign formats.

While Google hasn’t explained why it selected these verticals, they fit naturally alongside other travel-related advertisers already using the campaign type.

What Advertisers Should Do

If you’re eligible for the beta, treat it as a controlled test rather than a replacement for your existing campaigns.

Review your current Search and Performance Max performance, set aside a limited testing budget, and compare booking or ticket sales against your existing campaign mix. Since Google has not released complete feature details, it’s also worth setting expectations internally that functionality may continue to evolve throughout the beta.

What’s Still Unknown

Google has not yet confirmed which bidding strategies, assets, reporting capabilities, or feed requirements will be available for the Things to Do and Events verticals. It also remains unclear how these campaigns will interact with existing AI Max for Travel functionality.

We’ll update this article as Google shares additional details about eligibility, features, and availability.

Featured image: Master1305 / Shutterstock

https://www.searchenginejournal.com/google-search-campaigns-travel-things-to-do-events-beta/581816/




AI Search Is Exposing SEO’s Risk Of Losing Ownership Of GEO Outcomes via @sejournal, @martinibuster

Tom Critchlow, a longtime search marketer with deep experience, recently shared his opinions of where the SEO industry is today, saying that AI Search is changing business priorities in a way that exposes the weaknesses inherent in SEO today. This transformation means that search marketing professionals need to evaluate the services they offer in order to align better with what is useful for today’s modern search surfaces.

Brand Marketing: The Hidden Pillar Of SEO

Google’s algorithms have long relied on user behavior signals. Google’s founders said that PageRank could “be thought of as a model of user behavior,” showing that user behavior relative to content was important to Google at the very dawn of Google.

What people respond to most online are brands. People could be said to be hardwired to respond to products and service providers they are already familiar with. This phenomenon is called Familiarity Bias, a tendency to prefer things one is already familiar with. Making potential site visitors familiar with a brand is a powerful marketing activity, and that approach aligns perfectly with what we know about Google’s algorithms relative to Navboost and branded search.

SEO Fundamentals Are A Foundation

In an interview with Ross Hudgens, Critchlow observed that the foundations of SEO remain the same in AEO/GEO. Google consistently says that the fundamentals of SEO remain the same. Critchlow’s view of AI Search goes beyond that by showing that SEO is more like a foundation.

Critchlow explained:

“And it points to something very important, which is I think that GEO, AI Search, is much more like brand marketing than it is SEO, in my opinion.

Right now, there is an underpinning, obviously, of the technical foundations and crawling and indexing that is kind of the same, or the same kind of discipline, right?

That is equally important before and after.”

It is at this point that Critchlow develops the idea that what is built on top of that foundation goes beyond just classic SEO, with the implication being that failing to anticipate this change could pose a career risk.

People Who Drive Outcomes Are Not SEO

Critchlow continues his thoughts, building on the idea of SEO being a starting point and going further by saying that the outcomes in AI Search are not driven by SEO. He describes this as contrarian, which is someone who holds an opinion contrary to what is commonly accepted. But as you’ll see, Critchlow’s ideas are founded on a more practical view of what drives ranking in both classic and AI Search.

Here Critchlow considers the questions that all SEOs need to be asking as the industry transitions to a post-Search AI-driven environment:

“But a lot of what you do, back to that question of like, okay, you put in a prompt and you say, do you recommend brand A or brand B?

And it says your competitor.  What do you do about that, right?

And so like, and this, I’m a little contrarian, so forgive me, but like this was true in classical SEO and I think is increasingly true in the GEO world.

The people that drive SEO outcomes are not SEO professionals, by and large.

It’s painting with a broad brush and there are exceptions. …Both in the old SEO world and in the GEO world, the people that drive out the outcomes are the brand, product, PR and editorial teams, not the SEO teams.

And that was true in a classical SEO world. And I think it’s going to be increasingly true in a GEO world.

If I’m a CEO and I’m sat looking at my organization and I’m like, who’s going to do this GEO thing for me?

  • Is it the SEO team?
  • Or is it the brand team?
  • Or is it the product team?

And your answer to that question is going to depend a little bit on what kind of business it is and what industry you’re in, but there’s a real risk for the SEO industry, which was also a risk in classical SEO days…

…Because again, SEO has done a great job of being like, we’ve got to produce great content. We’ve got to have a good brand. We’ve got to have like strong branded search. We’ve got to be mentioned in all these places. We’ve got to have like positive reputation.

But does an SEO team do any of those things? In most organizations, the answer is no.

In most organizations, those outcomes are owned by other teams. That’s a real, I think of that as a career risk.”

Takeaway

Critchlow’s observations raise many questions that SEOs need to consider today:

  • Who drives SEO outcomes today in AI Search?
  • Is there a risk for the SEO industry as GEO becomes more important?
  • What does SEO emphasize organizations should do, and does SEO actually own those activities?
  • Who owns the outcomes that matter in most organizations, and how should SEO fit into that?
  • If SEO doesn’t drive the outcomes that matter, is there a career risk, or should SEO transform to encompass more?

Looked at another way, it could be we are in a liminal state where we are neither here nor there, where what was SEO is transforming and becoming something else.

Watch the interview here:

[embedded content]

https://www.searchenginejournal.com/ai-search-is-exposing-seos-risk-of-losing-geo-outcomes/581805/




Google Clarifies Smart Bidding Update After Advertiser Concerns via @sejournal, @brookeosmundson

Google is clarifying its Smart Bidding update after advertisers questioned how budget-limited campaigns will behave beginning August 17.

The original announcement around Smart Bidding changes was June 22. The update essentially changes how Target CPA and Target ROAS campaigns behave when they’re limited by budget.

Today, many budget-limited campaigns outperform their bidding targets. Smart Bidding often enters only the auctions most likely to convert efficiently, producing stronger-than-expected CPA or ROAS.

Google says that wasn’t the intended behavior.

Instead, Smart Bidding will optimize more closely toward the Target CPA or Target ROAS advertisers actually set. Campaigns that currently outperform those targets may move closer to them after the update.

The announcement immediately raised questions across the PPC industry. Advertisers wanted to know why Google would reduce efficiency in campaigns that were already exceeding expectations.

Google’s follow-up comments answer many of those questions. They also explain why the company believes the change will make campaign scaling more predictable.

What’s Changing On August 17?

The update affects campaigns using Target CPA or Target ROAS that are limited by budget.

Historically, those campaigns often outperformed their bidding targets. A campaign with a $50 Target CPA, for example, might consistently generate conversions at $35.

Beginning August 17, Google will optimize those campaigns more closely toward the Target CPA or Target ROAS advertisers set. The company says this should create more predictable performance when advertisers adjust campaign budgets.

Google also clarified several points after announcing the update:

  • Budgets will not automatically increase
  • Google won’t automatically change Target CPA or Target ROAS settings
  • Advertisers who want to maintain current performance may need to lower their bidding targets before the rollout
  • Google is rolling out account notifications and a Bid Target Adjustment Tool to identify affected campaigns

Those clarifications addressed some of the initial confusion. They also sparked a broader discussion about how the update could affect campaign performance in practice.

The Biggest Concern: Is Google Becoming Less Efficient?

One question surfaced repeatedly as advertisers discussed the update: Is Google making Smart Bidding less efficient?

Kirk Williams summed up that concern in a LinkedIn post.

He wrote:

…How and why will the system stop trying to be as efficient as possible… Does that mean smart bidding when limited by budget will no longer be trying to find better auctions?… So does that mean they’re building the system to literally choose to be dumber when limited by budget?

Williams questioned why Google would move campaigns closer to their stated targets if Smart Bidding could already deliver stronger performance.

Mike Ryan offered one of the most detailed explanations in the comments.

Ryan argued that Google isn’t making Smart Bidding less intelligent. Instead, he believes the system has become too conservative in budget-limited campaigns.

According to Ryan, Smart Bidding has favored exploitation over exploration. Rather than entering more auctions that still satisfy an advertiser’s target, the system has focused on the safest opportunities. That produced stronger-than-expected efficiency. It also meant campaigns didn’t consistently optimize toward the Target CPA or Target ROAS advertisers actually set.

Ryan believes the updated system will follow those bidding targets more closely. That may reduce the overperformance many advertisers have seen in budget-limited campaigns, but it also aligns with Google’s stated goal of making bidding targets behave more predictably.

Predictable Scaling vs. Peak Efficiency

Aaron Levy focused on a different part of the update: campaign scaling.

He described a campaign with an $8 CPA and a $12 Target CPA. If an advertiser doubled the budget today, the CPA might unexpectedly climb to $16 instead of remaining near the target.

Levy believes the update should make that behavior more predictable. Rather than introducing large swings in efficiency, Smart Bidding should continue optimizing toward the advertiser’s Target CPA as budgets change.

Kirk Williams questioned whether that tradeoff benefits advertisers. If Smart Bidding can already outperform a target, he argued, some advertisers may prefer that extra efficiency over more predictable budget increases.

Google has consistently framed the update around predictability. They say campaigns should optimize toward the targets advertisers actually set, making budget changes easier to manage and forecast.

Whether advertisers agree with that tradeoff will likely depend on how their campaigns perform after the rollout.

Google Clarifies Several Misconceptions

Google Ads Liaison Ginny Marvin responded directly to several concerns advertisers raised after the announcement.

One of the biggest misconceptions was that Google was encouraging advertisers to simply spend more money.

Responding to Barry Schwartz, Marvin wrote:

To be clear, this won’t result in campaign spend changes… Our guidance for those with budget-constrained campaigns currently over-performing on their target is to ensure the targets are in line with your goals.

She also emphasized that advertisers will only spend more if they choose to raise their campaign budgets. The update itself does not change campaign budgets or automatically adjust bidding targets.

Jack Carr raised a similar concern, arguing that budget constraints have historically acted as an efficiency lever and that Google’s recommendation effectively removes that advantage.

Marvin responded with a longer explanation:

Our advice is not to ‘let the system spend more money’… this change won’t result in spend changes on a campaign already budget constrained.

She also explained why Google is making the change.

Performance has often fluctuated unexpectedly… especially with budget changes. That’s not been a great experience for advertisers & made it challenging to scale campaigns with confidence.

According to Google, the backend update will make Smart Bidding optimize more consistently toward the Target CPA or Target ROAS advertisers actually set, even when campaigns are limited by budget.

Kristen Kelleher questioned whether the change would simply push campaigns into lower-quality traffic.

Marvin pushed back on that assumption as well.

The system sets bids to find as many conversions as possible at the ROAS/CPA target you set… With this update, advertisers can also expect this same behavior in budget-constrained campaigns with targets.

She added that advertisers who want to maintain today’s stronger-than-target performance should consider updating their Target CPA or Target ROAS before the rollout.

Google’s position has remained consistent throughout the discussion. The company says the update changes how closely Smart Bidding follows bidding targets. It doesn’t change campaign budgets or automatically modify campaign settings.

What This Means For Advertisers

Not every advertiser will need to make changes before August 17.

Campaigns already hitting their intended Target CPA or Target ROAS may continue operating much as they do today. The biggest impact will likely fall on budget-limited campaigns that have consistently outperformed their bidding targets.

For example, if a campaign has averaged a $20 CPA against a $35 Target CPA, Google says advertisers should consider whether $20 is now the more appropriate target. Leaving the original target unchanged could allow performance to move closer to $35 after the update.

Before the rollout, review any budget-limited campaigns that consistently outperform their Target CPA or Target ROAS. Compare current performance against your configured targets and decide whether those targets still reflect your business goals.

The update also changes how advertisers should think about bidding controls. Many advertisers have treated limited budgets as an efficiency lever because campaigns often outperformed their targets. Google has made it clear that budgets and bidding targets serve different purposes. Budgets control spend. Target CPA and Target ROAS control efficiency.

If Google’s explanation plays out as expected, advertisers who keep bidding targets aligned with actual performance should see fewer surprises when adjusting campaign budgets after August 17.

What Happens Next

Google has explained how Smart Bidding should behave after August 17. The remaining question is how closely those expectations match real-world campaign performance.

Advertisers with budget-limited Target CPA or Target ROAS campaigns will likely be watching those accounts closely after the rollout. Campaigns that have consistently outperformed their bidding targets may provide the clearest indication of how much the update changes day-to-day performance.

Google has also encouraged advertisers to review bidding targets before the rollout if current performance already aligns with their business goals. As more accounts transition to the updated bidding behavior, advertisers should have a better understanding of how the change affects campaign efficiency and budget management in practice.

Featured image: Roman Samborskyi / Shutterstock

https://www.searchenginejournal.com/google-clarifies-smart-bidding-update-after-advertiser-concerns/581804/




OpenAI GPT-Live Brings Search Into ChatGPT Voice via @sejournal, @MattGSouthern

OpenAI has begun rolling out GPT-Live, a new generation of voice models that power ChatGPT Voice. During a conversation, GPT-Live can hand a question to its latest frontier model, such as GPT-5.5, for heavier reasoning or a web search.

What Launched

GPT-Live-1 becomes the default model powering ChatGPT Voice for Go, Plus, and Pro users, and GPT-Live-1 mini becomes the default for Free users.

OpenAI describes the models as full-duplex, meaning they can take in audio and produce speech at the same time, interrupt less, and wait when a user pauses.

Search and Visual Answers Move Into the Conversation

When a spoken question needs deeper reasoning or current information, GPT-Live can hand it to a frontier model, GPT-5.5 at launch, and bring the answer back into the conversation.

ChatGPT Voice can also show visual cards for topics like weather, stocks, and sports, and OpenAI said Voice continues to support search, memory, images, and file uploads. Users can set a reasoning level, with Instant for fast replies and Medium or High for more involved questions. OpenAI said Instant replies and the mini model run on GPT-5.5 Instant, while Medium and High use GPT-5.5 Thinking.

How OpenAI Measured It

In OpenAI’s own head-to-head evaluations, GPT-Live-1 and GPT-Live-1 mini were preferred over its Advanced Voice Mode in conversations lasting five to ten minutes. OpenAI said the evaluations looked at overall preference, turn-taking, interruptions, conversational flow, and how natural the interactions felt. The company said more than 150 million people talk to ChatGPT each week using features like Voice and Dictation.

What It Doesn’t Do Yet

At launch, GPT-Live does not support voice with video or screen sharing in ChatGPT. OpenAI said it is working to add those capabilities, and that its earlier Standard and Advanced Voice Modes stay available where video and screen sharing are supported.

Why This Matters

Now, when you ask a question aloud, you might see an answer directly in the voice flow, sometimes accompanied by a visual card on the screen. This provides ChatGPT with another way to present an answer without visiting a source site. Since the reasoning and search process happens behind the scenes on GPT-5.5, what shows up there depends on how the model retrieves information and cites its sources.

Looking Ahead

OpenAI said the rollout is beginning globally, and that video and screen sharing are not in this release but are being worked on.

OpenAI’s post doesn’t say how GPT-Live handles citations when it answers a spoken question from a GPT-5.5 web search. ChatGPT’s text answers show source links next to the response. Whether a spoken answer names its sources, shows them on screen, or leaves them out is the detail to watch. That’s what decides whether a search inside a voice conversation can still send a reader to your site.


Featured Image: OpenAI

https://www.searchenginejournal.com/openai-gpt-live-brings-search-into-chatgpt-voice/581773/




An Easy Digital PR Strategy For AI SEO via @sejournal, @martinibuster

I had a conversation with an old friend from my WebmasterWorld Forum days about PR marketing for AI search. The friend had contacted me to hear my thoughts about it. The discussion seemed useful, so I rewrote it into an article.

Digital PR Outreach Because Links Matter Less

The friend I had this conversation with is Alistair White (LinkedIn profile), a search marketing professional based in Australia who has decades of experience.

White asked me:

“I was wondering if you have any thoughts on performance based digital?”

My response was, yes, I have a load of thoughts on the topic. The following is one of them. In the future, I will do a follow-up on more ideas.

I used to do PR outreach slash brand marketing for a B2B starting around 2004. But I scaled it up for another company around 2013 because I saw the writing on the wall that links were already on the decline. So my approach grew out of link building, but my intuition was that links did not matter. It was about putting the company in front of ten thousand, twenty thousand, sixty thousand potential customers and doing it in a way that makes it clear that this company solves the problem that these professionals have.

Strategy: Outreach Directly To Potential Customers

What I did was narrowly focus on a specific demographic that strictly lined up with their target customer. So, one typical customer was the head of IT and IT workers at a large corporation. Another demographic was the department manager. Two different demographics that both needed the same solution. So the campaign was split into two parts, one for each demographic.

It was essentially a PR campaign that was focused on identifying associations and organizations. Virtually every industry has an association of professionals. So, what I did was first target the organizations at the national level. The reason is that once you do a project with the national level, getting similar projects done at the state level was ten times easier. You just show them the national level article that featured the company, and the state-level organizations would almost always say yes.

Once you got that state-level project done, getting to yes with the individual chapters at the regional or county level became ten times easier. Each time I got a project done, it put the client in front of thousands of potential customers. Eventually, everyone knew who my client was and getting projects done became easier.

What were these projects?

  • Newsletters
  • Organization magazines
  • Website articles
  • Interviews

Every organization was different. So I would click around and see what they were up to and create the pitch to fit with what they were publishing.

Attribution Is Not Always Possible

This was not about building links, it was about building customers, making money.

And that’s not something that any SEO thirteen years ago would ever consider doing because there isn’t a clear way to track that the client spent X this month and earned Z the next month because of that activity. An SEO would never consider it because there’s no way to directly track the ROI.

You can track some of it with the “how did you hear about us” question. But how will you know if a customer heard of the company because a colleague at a conference who saw the client’s propaganda told them about it?

Not everything can be tracked. That’s why everyone else in SEO did not pursue these opportunities because they were like, where is the link, where is the attribution? Well, now the secret’s out. It’s infinitely adaptable, too.

Both companies that I did this for experienced year-over-year steady growth, and both were eventually acquired and made a lot of money for the founders. And how did I know it worked? Because this is how I promoted some of my websites, by building top-of-mind awareness, the kind that makes people type a domain name into the search box.

Google has algorithms that track things like branded navigation. You can’t build that kind of user behavior with links. You cannot build branded navigation with SEO. And yet, these are things that have been a part of Google’s algorithms since 2004 with the Navboost algorithm and in 2012 with Google’s branded navigation.

Brand Marketing And PR… And SEO?

SEOs have historically been about five to ten years behind the actual algorithm developments at Google. And I get it that ideas that a five year old can understand, like “adding EEAT” to articles, that’s easy to understand. Everyone else is doing it. But you know, everyone who did that knows now it was a grand waste of time.

And it’s not that I am a contrarian. It’s just that most of the time SEOs chase these ephemeral tactics with an SEO hammer, going bang, bang, bang. But it’s becoming clearer now that SEO for AI search is not the nail that building links used to be.

Like, how are you going to encourage people to do a branded search on Google? How are you going to get people to know about your brand in the first place? How are you going to target the office manager that makes the decisions at a company? Well, I shared an idea about that, right?

Those are the kinds of things that are going to trigger a positive ranking factor at Google, and yet none of those are a part of the SEO toolbox.

Back in 2015 I raised the idea that content is king misses the point of being successful online.

I wrote:

“If content is king, how come the top Internet businesses sites are not in the content business? What about Netflix? You think that’s content you are paying a monthly subscription for? Or is it convenience?

Netflix is not in the content business. They are in the convenience business. Anyone can provide content but nobody delivers convenience the way Netflix does. That’s because their focus is and always has been the user experience. Convenience, the user experience, is why customers pay Netflix. If Netflix had followed the Content is King strategy it would have been Blockbuster.

…Don’t focus on cranking out content. Focus on understanding what the user wants and your content strategy follows.

I cannot overstate the importance of understanding that the user experience underlies many of Google’s important decisions related to its algorithm.”

These are not new ideas that I’m presenting, but they were ahead of their time, maybe still are. Yet, they are as relevant today as they were in 2015 or 2004. Some are saying they are more relevant today because of AI Search.

Featured Image by Shutterstock/Mer_Studio

https://www.searchenginejournal.com/an-easy-digital-pr-strategy-for-ai-seo/581710/