11/10/2026
Google's September 2026 spam update hit thin content. Here's what startups using AI should check
Google's September 2026 spam update hit thin content. Here's what startups using AI should check


Rucha Bhatt
Founder
Oct 11, 2026
Search Presence (SEO, AEO, GEO)
Google's September 2026 spam update ran from 24 September to 8 October. Google hasn't said what it targeted, but SEOs report more manual actions against established businesses for thin and scaled content.

Rucha Bhatt
Founder
Oct 11, 2026
Search Presence (SEO, AEO, GEO)
Google's September 2026 spam update ran from 24 September to 8 October. Google hasn't said what it targeted, but SEOs report more manual actions against established businesses for thin and scaled content.
Google's September spam update finished rolling out on 8 October, after 13 days and 16 hours. That made it the longest spam update in more than a year, and Google has not said what it targeted.
The clearest account so far comes from the people doing the clean-up. Marie Haynes, who has handled manual action cases for about two decades, posted on X on 7 October that requests for help had jumped. She later told Search Engine Roundtable they had gone from essentially none to several a week. Most of the sites had been hit for thin content, scaled content or outright spam, and most of them, in her words, were "legitimate long standing businesses".
That should worry any startup whose blog grew faster than its team did.
Our view is that the AI part of this story is a distraction. Google's documentation, rewritten over the same fortnight, takes aim at pages published without a reason and without anyone accountable for them. AI made those pages cheap enough to produce by the hundred. Sort out the reason and the accountability, and the question of which tool drafted the copy mostly goes away.
In short: Google's September 2026 spam update ran from 24 September to 8 October. Google hasn't said what it targeted, but SEOs report more manual actions against established businesses for thin and scaled content. Google's own guidance now calls human fact-checking of AI content critical and, according to SEO consultant Marie Haynes, describes fabricated author profiles as deception. If your startup scaled its blog with AI, run the 15-minute content check below this week.
What did Google change in October 2026?
Google tends to say things in its documentation before it does them in the rankings. This time three edits arrived close together.
On 1 October it rewrote its guidance on generative AI content to say it is "critical to manually factcheck and review all AI-generated content for accuracy and trustworthiness before publishing". The review covers more than body copy: page titles, meta descriptions, structured data and image alt text are all named. Critical is a strong word for a Google help page, and it changes what sign-off means. Whoever approves a post is now expected to have checked it, not skimmed it.
The underlying rules haven't moved. Google's guidance on generative AI content says that using AI to generate many pages without adding value for users may breach its scaled content abuse policy. When Google introduced that policy in 2024, it said the policy applies whether pages are produced by automation, by people or by a mix of the two. The October edits sharpen how that policy is read; they don't replace it.
On 2 October, Haynes reported a new sentence on Google's page about creating helpful, reliable, people-first content. Reading it aloud in a video, she said it calls fabricated creator profiles, meaning AI headshots, made-up names and false credentials, "a form of deception" that makes a page untrustworthy to readers and to Google's automated systems. Her reading is the only public record of the wording, since the captured page shows just its opening section. By her account, the same edit rates large volumes of unchecked AI text as low effort. For a startup, that turns what used to be a cosmetic shortcut into a trust problem.
On 8 October the spam update closed. Google's spam policies cover scaled content abuse, expired domains, site reputation abuse and doorway pages, among others, and since May they have applied to AI Overviews and AI Mode as well. Google named none of them as the target, so the only signal you'll get about whether the update touched you is your own traffic.
We read this as Google putting its reasoning on the record so that it doesn't have to explain individual penalties. It ran the longest spam update of the year and named nothing. Nobody is going to publish a list of what was hit, so the documentation is the only map available. Right now it happens to be unusually specific.
Where startup blogs went wrong
Very few of the startups we'd worry about set out to cheat. They followed advice that was everywhere in 2024 and 2025: publish often, cover every keyword in your category, and use AI so a small team can keep pace with bigger competitors.
That advice produced exactly the patterns Google has now written down. Daniel Foley Carter, an SEO consultant tracking the manual actions, tied the rise to businesses that cut their SEO budgets because they assumed AI could do the job. Some of those sites, he said, lost 90% or more of their traffic overnight.
The invented team is the problem we'd fix first, because it costs almost nothing to fix and is the hardest to defend. A three-person company gives its blog a Head of Content with a generated headshot and a bio nobody can verify. Until this month you could call that harmless window dressing. Google's own page now calls it deception.
Haynes herself is careful to say that bylines aren't a ranking factor, so it's fair to ask why an invented author should worry anyone. Our answer is that the risk was never a missing ranking point. Google's own wording frames it as a trust problem, for readers and for its automated systems alike. A reader who looks up your Head of Content and finds nobody stops believing the rest of the page. And once a site has been caught faking one thing, a reviewer has little reason to give the rest of it the benefit of the doubt.
Programmatic pages come next. One page per city, per industry or per competitor, built from a single template with a few words changed, is what the scaled content policy was written for.
There's also a cost founders tend to miss. Since December 2024, Google Ads has disapproved ads that point to pages removed from Search by a manual action, a rule set out in Google's Search spam policy for advertisers. If paid search feeds your pipeline, a content problem can turn into a revenue problem in the same week.
What turned up when we checked 20 startup blogs
To see how common these patterns are, we looked at 20 blogs run by startups and young software companies on 11 October. We took them from the first page of search results for seven questions a buyer might ask, across climate software, B2B SaaS, AI tooling and sales tech, and checked one ranking guide on each, along with whatever its page and blog index showed publicly. We couldn't see anyone's Search Console, so this says nothing about who has been penalised. It shows what a reviewer, human or automated, would see.
Sixteen of the 20 showed at least one of the patterns Google's documentation now describes.
What we checked | Result |
|---|---|
Blogs showing at least one pattern Google's documentation describes | 16 of 20 |
Readable bylines with no identifiable person behind them | 9 of 19 |
Readable bylines naming an author whose stated role matched the subject | 2 of 19 |
Sites with the same guide at two addresses, or overlapping guides on one topic | 4 of 20 |
Pages with leftover template code, placeholders, instructions or keyword lists | 5 of 20 |
Method: 20 blogs from first-page search results for seven buyer questions, checked on 11 October 2026. One ranking guide per site, each loaded in full; bylines read on 19 (the 20th was assessed from its blog index). No company is named.
Authorship was the most common gap. We could read the byline on 19 of the pages, and nine of those had no identifiable person behind them: a company or "team" byline, an empty author box, or no author at all. One guide was written throughout in the first person, complete with "the biggest mistakes I see founders make", with no name anywhere on the page. Only two of the 19 credited a named author whose stated role matched the subject.
Duplication came next. Four sites had the same guide at two addresses or overlapping guides on one topic. On one of them, two near-identical "complete guides" to the same subject cited different benchmark studies for the same claim. Another had a copy of its guide live on a staging server, where it was turning up in search results. Two sites we first suspected turned out to be doing it properly: the second address simply redirected to the original, which is exactly the fix.
Five pages showed signs that nobody had read the finished version: placeholder headings left in a table of contents, raw template code in an image's alt text, raw HTML pointing to a staging site inside a meta description, a sentence that reads like a leftover writing instruction, and a block of about 25 keyword variations printed in plain view under the introduction. Another attributed precise savings figures to two well-known listed companies without citing anything.
Every page we checked was still on the first page for its query, and as far as we know none of these sites has been penalised. That cuts against a tidy story, so it's worth being straight about what it could mean. Either enforcement simply hasn't reached these pages yet, or Google weights these signals less heavily than its documentation suggests.
We lean towards the first. Spam updates and manual reviews move through the web unevenly, and Google has spent October writing these exact patterns into its guidance. Still, the honest reading of our sample is that it shows risk, not damage. Nobody should treat it as proof that a penalty is coming, and nobody should treat page-one rankings as proof that they're safe.
A faster lane for content from real people
On 8 October, the day the update closed, Google also published documentation for its UGC Fresh Data Program. Approved forums and social platforms can now push user posts straight to Google, ideally within minutes of publishing. Only platforms can apply, and Google says inclusion doesn't guarantee anything will appear in Search.
The detail worth noticing sits in the eligibility rules: every post has to be attributable to a creator with a public profile. So in one week Google made fake people riskier and made it quicker for real, named people to be found. That's our interpretation rather than a stated policy, but we don't think the timing is an accident.
That makes the named people on your team an asset a content farm can't copy, as long as they're willing to put their names to what you publish.
How to check if the spam update hit your site: the 15-minute content check
Before changing anything, find out whether you've been affected. All you need is access to Search Console and your CMS. If we were looking at your site tomorrow, we'd open the author pages before Search Console. They take two minutes to check, and they tell you more about how the content was made than any traffic chart.
In Search Console, open Security & Manual Actions and then Manual actions. A notice there will name the issue and the pages affected, while a clean report rules out only the manual kind.
In the Performance report, compare clicks for 17–23 September with the days from 9 October. A drop spread across many pages is the one to take seriously, since algorithmic demotions arrive with no message at all.
Look at every author page and confirm each belongs to a real person whose photo and credentials can be checked. Remove any invented profile and move its posts to someone who will stand behind them.
Sort your posts by publish date and look for batches that went live together or share a template. Those are the pages to merge, rewrite or take out of the index.
Spot-check titles, meta descriptions, image alt text and structured data, which Google's new guidance names and which AI tools often fill in without anyone reading them.
If you run Google Ads, make sure none of your landing pages sits in a section flagged for a manual action.
Clean results mean you're probably fine for now. Haynes said on 2 October that she expects a core update soon, while allowing that it may not arrive, and she has pointed out that Google tends to change its documentation shortly before major updates.
If you'd rather have someone run the 15-minute content check with you and work through what it turns up, that's where our Search and AI visibility work starts.
If you've already been hit
First work out which kind of penalty you're dealing with.
A manual action shows up in Search Console. A human reviewer has looked at your site, the notice names the problem, and once you've fixed it you can ask for a reconsideration. Fixing means the affected pages are removed or properly rewritten. In forum threads collected by Search Engine Roundtable this month, one site owner who had removed 4,000 URLs still carried a thin content action, and another had cleaned up more than 6,000 and seen three reconsideration requests rejected. Partial clean-ups don't appear to get through, so do the whole job once and describe it precisely in the request.
An algorithmic drop arrives silently and there's nobody to appeal to. You improve the site and wait for Google's systems to look again. Google's standard line is that recovery can take many months, so plan for a long haul rather than a quick fix.
Start with a strategy, and keep the thinking with people
The fix most founders reach for is to keep the same publishing schedule and add a human editor. That deals with the symptom. The sites in trouble had a volume target and no answer to a more basic question: why does this page need to exist?
A content strategy for a small company fits on a single page. It lists the handful of questions your buyers ask before they choose a supplier, what you know about your market that competitors don't, and who on your team is credible enough to say it. Startups that write this down usually end up publishing less. Each piece then has a specific job. One might answer the question every prospect asks on a first call. Another might be the page you'd want an AI assistant to quote when someone asks about your category.
The thinking and the writing belong to the people named in that plan. They're the ones who have sat in the sales calls, know which claims they can back up, and will answer for what goes out under their name. AI can help around the edges. Google's own guidance says it can be particularly useful for researching a topic and adding structure to original content, and the word that matters there is original. Used well, a tool might pull together background reading or point out a gap in an outline. The argument, the examples and the final words should come from someone who knows the subject. No tool can supply judgement or accountability, and those are exactly what Google's documentation now asks for.
So run the 15-minute content check this week, then write the one-page plan before you publish anything new. If a scheduled post doesn't answer a real buyer question, or nobody on the team would put their name to it, take it off the schedule.
Frequently asked questions
Does Google penalise AI-generated content? Not for being AI-generated. Google judges quality, not how a page was produced. Using AI to publish many pages without adding value can breach its scaled content abuse policy, and since 1 October its guidance says a person should fact-check AI content before it goes live.
How do I know if the September 2026 spam update affected my site? Check the Manual actions report in Search Console first. Then compare your clicks for 17–23 September with the period from 9 October. A broad, sustained drop that starts inside the 24 September to 8 October window is the main sign.
Are fake author profiles against Google's guidelines? According to SEO consultant Marie Haynes, who read the new wording aloud on 2 October, Google's helpful content page now calls fabricating creator profiles through AI-generated headshots, made-up names or false credentials "a form of deception" that makes a page untrustworthy.
What is a manual action? A penalty applied by a human reviewer at Google when a site breaks its spam policies. It appears in Search Console under Security & Manual Actions, names the issue and the pages affected, and can be appealed with a reconsideration request once the problem is fixed.
How long does it take to recover from a Google spam penalty? It depends on the type. A manual action is lifted when a reconsideration request is accepted, and forum reports suggest requests are often rejected when the clean-up is partial. An algorithmic drop has no appeal route, and Google says recovery can take many months.
More latest insights

Tell us what you are working on

Tell us what you are working on


