AI Visibility

Grounding, Shaping, Poisoning: The Three AI Visibility Strategies Every Marketer Needs to Know

Faro Editorial

June 30, 2026 · 9 min read

Three-tier AI visibility framework: Grounding, Shaping, Poisoning

Most marketing teams are running three different AI visibility strategies at the same time. They don't know it, because nobody has named them clearly. One of those strategies is the right thing to do. One is common and widely accepted, but carries real risk. One is black hat and, in some jurisdictions, potentially illegal.

The framework that makes sense of all three comes from how AI systems actually process information: they look for evidence they can verify, they absorb positioning they can repeat, and they reject or ignore signals that appear manipulative. Understanding which category your activities fall into changes how you think about AI visibility entirely.

What Is AI Visibility and Why Does the Strategy Question Matter?

AI visibility refers to how accurately and favorably AI systems represent your business when users ask questions about your category, competitors, or specific problems you solve. It matters because AI traffic grew roughly 10x in the past 12 months while average organic click-through rates from Google fell 58% as AI Overviews absorb more queries. Traffic is now flowing through AI answers before it reaches your site, which means the question isn't just "how do we rank?" but "how does AI describe us?"

The strategy question matters because businesses pursuing AI visibility are doing different things to earn it, and the risks and returns attached to each approach are not equivalent. A structured taxonomy helps you evaluate what your team is actually doing and whether it's sustainable.

Strategy One: Grounding

Grounding means publishing verifiable evidence that AI systems can inspect, confirm, and confidently repeat. It's the only AI visibility strategy that works with how AI systems are actually designed to operate, because grounded claims can be cross-referenced against multiple independent sources.

Grounding activities include: publishing llms.txt with accurate business context; adding valid structured data markup so AI can parse your pricing, product details, and organization type without guessing; maintaining an accessible robots.txt that lets AI crawlers read your canonical pages; publishing agents.json so AI knows what actions it can take with your business; and creating an OKF knowledge bundle so AI systems have a structured, navigable representation of your full knowledge base.

The defining characteristic of grounding is that it improves how accurately AI represents you, not just how positively. A well-grounded site will appear correctly even in adversarial prompts, because the evidence is verifiable rather than position-dependent. This is the layer Faro's AI Readiness Scan measures directly.

What grounding does not do

Grounding does not guarantee positive sentiment. If your product has real problems that appear in trusted reviews and community discussions, better structured data will not suppress those signals. What it does is ensure that accurate positive information competes on equal footing with negative signals, rather than being absent from the evidence pool entirely.

Strategy Two: Shaping

Shaping means creating AI-facing content that carries the positioning claims you want AI to repeat. This includes llms.txt files that mix accurate context with carefully chosen framing, blog content written specifically to establish category authority in AI training data, press releases with narrative positions attached to factual announcements, and "best in class" framing on pages you know AI crawlers will index.

Shaping is not inherently deceptive. Humans read marketing copy and understand it as positioning. The same logic arguably applies to AI systems that read web pages. But there are meaningful risks:

  • AI systems are increasingly good at identifying positioning language versus verifiable claims, and they weight them differently. Pure positioning without underlying evidence is less sticky than positioning backed by grounded data.
  • If the claims in your shaping content are inaccurate or misleading, the resulting AI outputs could constitute false advertising in some jurisdictions, depending on how the claims are structured and how they influence purchasing decisions.
  • Shaping is legible to competitors. If your category-authority content is the only credible source of a claim, that claim is fragile.

The practical test for shaping: if you stripped the positioning language from your AI-facing content and replaced it with verifiable evidence, would the claim survive? If yes, it's grounding with persuasive framing (fine). If no, it's pure positioning without an evidence base (higher risk, lower durability).

Strategy Three: Poisoning

Poisoning means injecting hidden or misleading content into sources AI systems trust, in order to change their outputs without users knowing it happened. It is the black-hat category of AI visibility, and the research on how effective it can be is genuinely alarming.

A 2025 study from the arxiv research archive found that a 13-word Reddit comment was sufficient to reliably change the outputs of ChatGPT and Gemini in their deep-research modes. The same study found that Reddit accounts for 54 to 71 percent of all user-generated content URLs retrieved by deep-research agents, making it a high-leverage attack surface.

Poisoning tactics include: creating fake review content at scale designed to manipulate AI training or retrieval; injecting prompt injection instructions into web pages or documents that AI systems process; creating AI-facing "honeypot" pages with hidden instructions; and coordinating UGC at a scale and speed that outpaces AI moderation, with the goal of establishing a false consensus.

The risk profile of poisoning is categorically different from shaping. It is not a gray area. Depending on jurisdiction and implementation, it can implicate consumer protection law, computer fraud law, and advertising regulations. Platforms whose systems are targeted have strong incentives to detect and exclude sources that appear to be engaged in manipulation. The 13-word attack described in the research is not a permanent feature of AI systems: it is a vulnerability that is being actively patched.

Why the line between shaping and poisoning matters

The line can blur in practice. A coordinated review campaign that involves real customers writing authentic reviews is shaping. A coordinated review campaign that involves fake accounts posting fabricated experiences is poisoning. The difference is the authenticity of the source and the accuracy of the claim. This distinction matters both legally and practically: AI systems are being trained to detect coordinated inauthentic behavior, and sources identified as manipulative tend to be downweighted across all outputs, not just the targeted ones.

Where Most Marketing Teams Actually Are

Most marketing teams are running grounding and shaping simultaneously, often without distinguishing between them. A well-written llms.txt file with accurate context is grounding. The same file with positioning language designed to make the AI repeat specific comparative claims is shaping. Both can appear in the same 50-line document.

The risk from shaping is generally low if the underlying claims are accurate and the content otherwise meets quality standards. The larger risk for most teams is the opposite: not enough grounding. AI systems that cannot find verifiable evidence for your category leadership will underrepresent or misrepresent you, regardless of how good your positioning content is. Faro's AEO Citation Monitor runs real checks across Claude, ChatGPT, Perplexity, and Gemini to show you how each platform currently describes your business, so you can see where the evidence gaps are.

A Practical Audit Framework

Run your current AI visibility activities through this three-question audit:

First, what evidence layer does this activity produce? Grounding activities produce structured data, verifiable context, and machine-readable signals. Shaping activities produce positioning content without an independent evidence base. Poisoning activities produce fabricated signals designed to be mistaken for authentic ones.

Second, would an AI system produce the same output about you if this activity didn't exist? If yes, the activity is duplicating existing evidence (sometimes useful for redundancy, sometimes wasteful). If no, the activity is producing new signal.

Third, if the activity was disclosed publicly, would it be defensible? Grounding is always defensible. Shaping is usually defensible if the claims are accurate. Poisoning is not defensible.

The Priority Order for Most Businesses

For the majority of companies, the AI visibility gap is a grounding problem, not a shaping problem. AI systems know less about most businesses than they know about category leaders, not because the businesses are poorly marketed, but because their signals are thin: no llms.txt, incomplete structured data, AI crawlers blocked, no agents.json, no OKF knowledge bundle. Fixing these gaps produces durable, compounding returns in how AI represents you, without any of the risks associated with shaping or poisoning.

Shaping on top of solid grounding is a reasonable strategy. Shaping instead of grounding is fragile. Use Faro's AI Readiness Scan to identify your current grounding gaps before investing in positioning content.

In Short

Grounding, shaping, and poisoning are the three categories of AI visibility strategy. Grounding is the only one that works with how AI systems are designed: it provides verifiable evidence that AI can confidently use. Shaping is common and generally acceptable if claims are accurate, but it is less durable than grounding and carries regulatory risk if claims are false. Poisoning is black hat and increasingly detectable. Most businesses have an underinvestment in grounding and an overinvestment in shaping. Addressing that imbalance is where most AI visibility work should start.

Frequently Asked Questions

Is writing blog content designed to rank in AI answers considered shaping or grounding?

It depends on the content. If the article contains verifiable information, original data, and accurate claims, publishing it is a grounding activity: you are adding evidence AI can inspect and confirm. If the article is primarily keyword-optimized talking points without substantive information gain, it leans toward shaping. The best AI-facing content does both: it provides genuine information (grounding) with clear framing about your position (shaping), backed by verifiable sources.

Can competitors poison AI representations of my brand?

Yes, and the research suggests it is easier than most people assume. The arxiv study showing a 13-word Reddit comment can alter AI outputs is directly relevant here: well-funded competitors with bad faith intent could use UGC channels to introduce false negative signals about your brand. The defense is grounding: AI systems that have access to strong, consistent, verifiable evidence about your brand are harder to manipulate via external UGC injection.

How do I know if AI is currently representing my business accurately?

Run a citation check across the major AI platforms. Faro's AEO Citation Monitor runs your business name and category through Claude, ChatGPT, Perplexity, and Gemini and shows you exactly how each platform describes your business, what sentiment it expresses, and whether you appear in top recommendations. It is the most direct way to measure whether your grounding is working.

Does this framework apply to local businesses as well as SaaS and enterprise?

Yes. Local businesses face the same AI visibility dynamics: AI-powered local search tools are increasingly surfacing recommendations based on structured data, review signals, and entity completeness rather than just proximity. The grounding checklist is slightly different (Google Business Profile, local schema, consistent NAP data across directories) but the three-strategy taxonomy applies in the same way.

Related Reading

← Back to Blog

The Faro platform

Every tool you need to be found, understood, and chosen by AI.

Faro is building the complete infrastructure layer for AI discoverability. Scan first, then fix, monitor, and stay ahead. All from one platform.

AI Readiness ScanLive

Run 30+ checks across 6 categories. Get a score, a grade, and a prioritized fix list in 30 seconds.

Use tool →
llms.txt GeneratorLive

Give AI agents a structured map to your most important content. Download your file in under 60 seconds.

Use tool →
AI Schema CreatorLive

Paste your URL and get the exact JSON-LD markup your site is missing. No developer required.

Use tool →
robots.txt AnalyzerLive

See exactly which AI crawlers you're blocking and why. Get the precise fix lines in under 60 seconds.

Use tool →
Competitor IntelligenceLive

Side-by-side AI readiness scores across up to 3 competitors. See exactly where you lead and where you lag.

Use tool →
Pricing Clarity AuditorLive

Find out if AI agents can actually read and compare your pricing. 6-dimension check in seconds.

Use tool →
OKF GeneratorLive

Build the machine-readable knowledge bundle that tells AI agents exactly what your business does.

Use tool →
Revenue CalculatorLive

Calculate the monthly revenue gap between your current AI readiness and a fully optimised site.

Use tool →

One-Click Fix Engine

Connect your GitHub repo. Faro opens pull requests with every code fix automatically.

New tools ship continuously. Free tier always available.

Browse all tools →