TL;DR
- The September 2026 spam update started on 24 September 2026, applies globally and to all languages, and "may take up to two weeks to complete", according to the Google Search Status Dashboard. Google has not marked it complete, has not named a target and has not said what share of queries it affects. It is the fourth spam update of 2026.
- It is not aimed at AI as a tool. Google's rule is that AI use is acceptable but that generating many pages "without adding value for users" is scaled content abuse. AI-assisted journalism that adds original reporting, carries real bylines and is edited by people is inside the rules; mass-produced rewrites, AI content on expired domains and paid links that pass ranking credit are not.
- The problem Google is trying to solve is manipulation of its rankings, and now of its AI answers, by operators who use cheap generative AI, borrowed domain authority and paid placements to outrank original work. Google's credibility with users, its AI Overviews and AI Mode products, and a live EU dispute over how it treats sponsored content on news sites all depend on how well it does this.
What Google has confirmed
Google's Search Status Dashboard entry, timed at 09:15 PDT on 24 September 2026, reads: "Released the September 2026 spam update, which applies globally and to all languages. The rollout may take up to two weeks to complete." On LinkedIn, Google Search Central added: "This is a normal spam update, and it will roll out for all languages and locations." There was no blog post, no new policy and no list of targets.
As of 28 September the dashboard has no completion entry, so the update is still rolling out. Two weeks from the start date points to completion by about 8 October. But. folks, that is an estimate. As ever with Google, it is a deadline, wrapped in a cryptogram, accompanied by a map with no compass. Google says it will update its ranking release history page when the rollout ends. Thanks for that G-Dawg.
John Mueller, a Google search advocate, confirmed to Search Engine Roundtable that the two-week window was not a typo: "Yes, it's likely to take longer than some of the previous ones." Barry Schwartz of Search Engine Roundtable reported that Google would not say what percentage of queries were affected, and that this update does not target link spam.
Google's standing documentation explains what a spam update is. Its automated systems for detecting spam run all the time, and a spam update is when Google makes "notable improvements" to them. The main system is SpamBrain, which Google describes as its "AI-based spam-prevention system". Google says sites that violate its policies "may rank lower in results or not appear in results at all", and that changes may help a site recover "if our automated systems learn over a period of months that the site complies with our spam policies".
Let's take a look at that timeline
The September update follows three others this year. The March 2026 spam update started on 24 March and finished in 19 hours and 30 minutes, the fastest on the dashboard's record. The June 2026 update ran from 24 to 26 June and took 2 days and 1 hour. The August 2026 update ran from 18 to 21 August and took 2 days and 16 hours. Google gave each of these a window of "a few days". So, the window for September suggests this update is a doozy.
Google ran three spam updates in 2024 (March, June and December) and one in 2025 (August 2025, which took 27 days, from 26 August to 22 September). Four in nine months makes 2026 the busiest year for spam updates since 2021.
So, why is this one is different?
To be completely upfront, nobody outside Google yet knows what September changes (despite what the myriad influencers/experts/gobby morons on the Tock and Insta might say) . But it does feel different to what came before.
The March 2024 update was a policy event. In tandem, Google launched a core update and a spam update together and announced three new spam policies: expired domain abuse, scaled content abuse and site reputation abuse. Google said at the end of that work that users would "now see 45% less low-quality, unoriginal content in search results", against the 40% it had expected. Those policies are still the core of the rulebook.
Site reputation abuse, often called parasite SEO, then went through several enforcement changes. Google enforced it through manual actions from May 2024. On 19 November 2024 it said third-party content used to exploit a host site's ranking signals broke the policy "regardless of whether there is first-party involvement or oversight". Manual actions followed against Forbes Advisor, CNN Underscored and WSJ Buyside, as reported by Glenn Gabe and Lily Ray. Google has said it does not rely only on host sites' own claims of editorial oversight.
This year has brought more policy changes. And it wasn't simply list of "normal" updates. On 13 April Google added "back button hijacking" to its malicious practices policy, with enforcement from 15 June. On 15 May it rewrote the opening definition of spam to cover "attempting to manipulate generative AI responses in Google Search", which brings AI Overviews and AI Mode inside the same rules. On 28 August, after talks with the European Commission, Google changed how site reputation abuse is enforced in the European Economic Area (EEA).
Then, from 30 August, manual actions under the policy still demote the affected section for users outside the EEA. For users inside the EEA the manual action has no ranking effect; instead the section "may be categorized as separate from the main domain" so that it ranks "on its own merits". Google also published four factors its human reviewers weigh: how the content is presented, its quality compared with the main domain, its stated or implied authorship, and whether the same content appears on other sites.
Against that background, September's spam update differs in three ways. It is the longest rollout window of the year. It is the first spam update since the EEA site reputation changes. And it is the second since the AI-answers wording, after June and August.
Let's be clear, Google has not linked the update to either change, and any claim that it does should be treated as speculation. Schwartz said after the first weekend that "it does feel like these spam updates are having more of an impact that the older spam updates from years ago", which is an observation, not data.
Enforcement methods also need to be kept separate. A spam update is algorithmic: a site that is hit gets no Search Console notice. A manual action is applied by a human reviewer and is named in Search Console's Manual actions report, with a route to a reconsideration request. Site reputation abuse is now handled through human review. Link spam is dealt with by separate link spam updates, and Google warns that when its systems neutralise paid links, "any ranking benefit the links may have previously generated for your site is lost" and cannot be regained.
Who and what it will affect
Google has named no targets for September, so the best guide is its written policies and what analysts saw in the updates just before it.
Search Engine Roundtable tracked sharp volatility across rank-tracking tools on Friday 25, Saturday 26 and Sunday 27 September, and said there is "more to come". No firm has yet published a list of winners and losers for this update. Search Engine Journal's summary on 24 September states: "Google hasn't provided additional details about what this update targets."
Fishing around to find some precedents
The August 2026 update provides a possible analogue (though we are reaching at this point). Still it merits some analysis. Glenn Gabe of GSQi published four anonymised cases. One site in a high-risk "your money or your life" niche mixed programmatic and AI-generated pages and "lost rankings for over 200K queries".
A programmatic Amazon affiliate site with AI text at the bottom of pages lost more than 14,000 queries, which Gabe linked to Google's "thin affiliation" policy.
A third site had more than 1.5 million URLs, about 85% of them programmatic, and was hit across all sections. A fourth combined scaled content with redirects to riskier sites. Gabe noted that sites hit by a spam update can drop "across surfaces, including AI Overviews and AI Mode". None of his cases was a news site.
Other changes
Lily Ray, of Amsive, tracked a separate change from about 20 January 2026. In her Substack post "It Works Until It Doesn't: AI Content Strategies That Backfire" (13 May 2026), she wrote that sites scaling self-promotional listicles "saw organic traffic declines between 40% and 95% over the Jan–April 2026 window"; across more than 220 domains she tracked, "54% lost 30% or more of their peak organic traffic... 39% lost 50% or more... 22% lost 75% or more", based on Ahrefs data checked against Sistrix. One company had published 2,000 articles that each ranked itself first. Google did not confirm that change as a named update; a secondary report citing The Verge says a Google spokesperson said in April 2026 that Google was targeting self-promotional listicle manipulation, but this has not been checked against The Verge.
On past spam updates, Sistrix described the August 2025 update as penalty-only: spam domains lost visibility, but there were no broad ranking shifts for clean sites. Sistrix closed its analysis of the March 2026 spam update because it was too short to measure and overlapped with the March 2026 core update.
By type of site, the risk under Google's written policies looks like this. Affiliate sites that republish merchant data with little of their own analysis fall under thin affiliation. Programmatic sites that generate pages for every keyword variation fall under scaled content abuse and doorway abuse. Third-party sections on high-authority domains, such as coupon and "best loans" pages run by outside operators, fall under site reputation abuse, which a spam update does not enforce directly but which human reviewers do. Expired domains bought to host unrelated content fall under expired domain abuse. Paid links that pass ranking credit, including "advertorials or native advertising where payment is received for articles that include links that pass ranking credit", fall under link spam. News publishers are not a target category, but news sites that host rented sections or AI-rewritten copy face the same rules as anyone else.
Is it aimed at AI slop?
Not by name, is the simple answer (but with the opaque world of Google search, who knows?). Its position has been stable since February 2023, when Danny Sullivan and Chris Nelson wrote that Google rewards "high-quality content, however it is produced" and that "appropriate use of AI or automation is not against our guidelines". The same post said: "Using automation, including AI, to generate content with the primary purpose of manipulating ranking in search results is a violation of our spam policies."
Scaled content abuse policy is where that line sits
Google defines it as "when many pages are generated for the primary purpose of manipulating search rankings and not helping users", and says this is spam "no matter how it's created". Its first listed example is "using generative AI tools or other similar tools to generate many pages without adding value for users". Its guidance on generative AI repeats the point.
So the test is purpose, scale and added value, not the tool. In practice, generative AI is the cheapest way to produce content at scale, so AI-written sites make up a large share of what gets caught. Analysts such as Gabe and Ray link recent losses to scaled AI content, but that is third-party analysis. Google has not said this update targets AI-generated content, and a Google statement to Press Gazette in July 2025 described its policies as covering content "regardless if it's produced by humans or AI".
There are signs Google is building more tools aimed at this problem. Glenn Gabe drew attention to a Google Research paper, "The Synthetic Gap: Automating Forensic Investigation of 'AI Slop' with the Scaled Abuse Forensics Examiner (SAFE)", which PPC Land dates to 28 May 2026 and which describes "an automated multi-agent architecture designed for the scalable forensics of adversarial synthetic media"; Gabe called it Google's "second system identified in 2026 designed to catch AI slop". The paper studies YouTube channel clusters, and there is no evidence it is used in Search ranking.
Will AI-assisted journalism survive?
For a nascent media outlet running AI-assisted news sites with sponsored content, the answer depends less on the use of AI than on four things: what the content adds, who stands behind it, how much is published, and how paid content and links are handled.
The evidence in the news itself is about bad actors, not about legitimate AI-assisted newsrooms.
Press Gazette reported in October and November 2025 that AI-written fake stories on newly registered or lapsed domains had reached millions of readers through Google Discover.
One false story about driving licence rules for over-62s was estimated to have been viewed 41 million times. Google told Press Gazette it was "actively working on a fix that will better address the specific type of spam that's being referenced here".
Futurism reported in May 2025 that WECB.fm, the expired domain of an Emerson College student radio station, was running AI content in Google News. Google told Futurism: "Our spam policies prohibit using expired domains in an effort to manipulate Search rankings, and our systems detect and consider domain ownership changes."
Futurism reported that the site was demoted. On 16 October 2025, Ben Paviour of Nieman Lab named other "zombie" news sites on lapsed domains, including Dixie Sun News, "on a URL that once hosted a college newspaper", and found a Guardian column republished "at least a dozen times" across such outlets. NewsGuard's tracker, last updated on 23 June 2026, lists 3,749 "AI content farm" news and information sites.
Enforcement is uneven
On 17 September 2026 Futurism reported that Brown Brothers Media, which buys established publications and fills them with AI content, still draws an estimated 64.7 million visits a month according to Similarweb. No Google penalty against it has been reported. The subagent-level search for this piece found no named, legitimate AI-assisted news brand confirmed as hit or spared by a 2026 spam or core update.
On what separates compliant AI-assisted journalism from spam, Google's own documents give clear signals. Content should be "original, high-quality, people-first" and show experience, expertise, authoritativeness and trustworthiness (E-E-A-T). Google says publishers in Google News "should use bylines and author information", that AI disclosures are useful where readers might ask "How was this created?", and that "giving AI an author byline is probably not the best way to follow our recommendation".
Google News can remove content that breaks its policies, including its transparency policy, and says that "in cases of repeated or egregious violations, a site may be no longer eligible to appear on our news surfaces". The February 2026 Discover core update aimed to reward "more in-depth, original, and timely content from websites with expertise in a given area" and to reduce "sensational content and clickbait".
In practice, a news site using AI to draft stories, which an editor then checks against the filing and adds analysis to, is on the right side of the line. A site that publishes hundreds of AI rewrites of other outlets' stories a day, under invented bylines, is not.
What problem is Google trying to solve?
Google's own statement of the problem is manipulation. Its spam policies define spam as "techniques used to deceive users or manipulate our Search systems into featuring content prominently", and since May 2026 that includes attempts to manipulate its AI answers. When it introduced the 2024 policies, Google said it wanted users to see "fewer results that feel made for search engines". Pandu Nayak, Google's chief scientist for Search, called the site reputation policy "essential to how we fight deceptive pay-for-play tactics that degrade our results".
Credible outside analysis explains why this has become urgent. The first reason is a documented quality complaint. The study "Is Google Getting Worse? A Longitudinal Investigation of SEO Spam in Search Engines", by Janek Bevendorff, Matti Wiegmann, Martin Potthast and Benno Stein of Leipzig University, Bauhaus-Universität Weimar and ScaDS.AI, presented at ECIR 2024, looked at 7,392 product-review queries over a year on Google, Bing and DuckDuckGo and found that higher-ranked pages were "more optimized, more monetized with affiliate marketing" and showed "signs of lower text quality"; the authors concluded that "dynamic adversarial spam in the form of low-quality, mass-produced commercial content deserves more attention". The second is cost. Generative AI has cut the cost of producing pages at scale close to zero, which is why scaled content abuse has become the central policy. The third is Google's shift to AI answers. AI Overviews and AI Mode draw on the same index, so spam that reaches the index can reach the answers. The May 2026 policy change and Gabe's observation that spam hits carry through to AI surfaces show Google treating the two as one problem.
There is also a commercial side, which Google does not state but which the data supports. Publishers are losing traffic whether or not they spam. Chartbeat data cited by Search Engine Journal shows Google Search referrals to publishers fell 40.2% between July 2025 and July 2026, and Discover referrals fell 34.3%. Google has an interest in showing that the traffic it still sends goes to trustworthy sources, and in keeping its AI answers from citing spam.
Regulatory side pulls the other way
On 13 November 2025 the European Commission opened a Digital Markets Act investigation into whether Google's site reputation abuse policy unfairly demotes news publishers that carry content from commercial partners. Teresa Ribera, the Commission's executive vice-president, said: "We are concerned that Google's policies do not allow news publishers to be treated in a fair, reasonable and non-discriminatory manner in its search results." Nayak said the probe "risks rewarding bad actors and degrading the quality of search results". The August 2026 EEA changes followed. Google said it remains "concerned that an overbroad application of the DMA could prevent us from addressing real threats to the integrity of our search results".
Put simply, Google is trying to stop cheap, scaled and paid tactics, many now powered by AI, from winning rankings and AI citations that original work should win. It is doing this at a time when publishers depend on it less, trust it less, and have regulators willing to challenge where it draws the line.
What to do now
Do not make large changes while the rollout is running. Google says the update may take up to two weeks, and measuring impact before completion will mislead. Check Search Console's Manual actions and Security issues reports first, because those are the only places Google names a problem.
Then audit against the policies, not against rumours. Mark every paid or sponsored link rel="sponsored". Make sure sponsored content is written for your readers, is clearly labelled, sits in your own design, and is not syndicated across many sites. Put named, real journalists on every article, with author pages and a corrections policy. Cut or consolidate AI-drafted pages that add nothing to the original source. If you run sites on bought or expired domains, make sure the content has a real connection to the domain and serves readers who would find it without Google.
Caveats
Google has confirmed only the start time, scope and expected length of the September 2026 spam update. Everything about its targets and impact is third-party analysis or inference, and early volatility data can reflect other changes. Some claims about AI-detection systems come from research papers with no evidence of use in Search. Much of the commentary on 2026 spam updates comes from SEO vendors with commercial interests and should be read with that in mind. The European Commission's investigation is still open, and the EEA enforcement rules could change again.
About the author: Ian Lyall is veteran business journalist-turned-tech nerd, whose interest in SEO is based on its practical application in this change-by-the-millisecond era of AI. Did I write this article? Yes, with the help of AI. Did I research this subject matter? To the point of nervous exhaustion.