Being Cited Was Never Proof of Anything
A sanctioned Wagner front group just showed why "generative engine optimization" was always measuring the wrong thing.
A new report from CASM, the Centre for the Analysis of Social Media at the UK think tank Demos, tested five leading AI chatbots against fifty propaganda claims sourced from a single outlet. That outlet, the Foundation to Battle Injustice, presents itself as a human rights NGO. It is, in fact, a Kremlin-linked information operation founded by the late Wagner Group leader Yevgeny Prigozhin, sanctioned by both the EU and the US. The claims the researchers selected were not subtle. Among them: that Ukraine is repurposing the bodies of dead soldiers, and that Ukraine's power grid failures are somehow tied to cryptocurrency mining. The chatbots cited the source anyway.
The report's authors describe how. Not persuasion, not ideology, not a model with a political lean. According to CASM co-founder Carl Miller, the operation succeeded through what he called technical spoofing and configuration: a long list of small, deliberate engineering choices designed to make a source appear citable to a model when it should never have qualified. The models did not decide the Foundation to Battle Injustice was credible. They were built to recognize citability as a signal, and the signal was faked.
The same playbook, run by the wrong side
Here is the detail that should stop anyone in the AI-visibility industry: the report doesn't treat this as an isolated propaganda story. It sits it next to the commercial practice of generative engine optimization, GEO, the growing discipline of engineering content specifically to be picked up and cited by AI models. The researchers count fifty companies doing this work globally, fifteen of them in the UK. The framing is explicit. State information operations and commercial visibility firms are now running variations of the same technique, because the underlying vulnerability is the same one.
That is worth sitting with. If a sanctioned Wagner front group can get itself treated as a legitimate source using the identical mechanics a legitimate brand pays a GEO firm to use, then citability was never evidence of legitimacy in the first place. It was a proxy. And a proxy that a Kremlin troll operation can game as easily as a Fortune 500 brand's marketing team is not a proxy worth optimizing for.
What citation actually tells you
This is the argument we have been making from the brand side for over a year, and it applies here without needing to stretch it. Being mentioned by an AI model tells you the model surfaced you. It does not tell you the model represents you accurately, represents you consistently, or that the mention will survive the next question a person asks. We have published research on this before under the heading "cited is not chosen": across real multi-turn conversations, the large majority of brands present at the first mention are displaced by the time a model reaches a final recommendation. Citation is the floor. It was never the ceiling, and it was never proof of trust.
The Foundation to Battle Injustice case is the same finding wearing a different, much starker coat. If a fabricated human rights NGO founded by a mercenary warlord can clear the bar that "citable" is supposed to represent, the bar was never measuring credibility. It was measuring whether someone had learned how to game the retrieval layer. Good actors and bad actors can both learn that game. Only one of them should be treated as having earned it.
The fix is not a better citation, it's an actual audit
None of this means AI visibility doesn't matter. It means visibility is table stakes, not the finish line, and treating it as the finish line is exactly the failure mode a state propaganda operation just demonstrated at scale. The real question isn't whether a model mentions you, or cites your competitor, or cites a source claiming to be a human rights group. It's what the model actually says once it's talking, whether that representation holds up when someone pushes back on it, and where the model is actually drawing its information from when it forms an opinion about you.
That last piece, source provenance, which outlets and domains a model is actually pulling from when it characterizes a subject, is itself measurable. It should be audited the same way a company audits its financials, not assumed. The CASM report is a rare, concrete demonstration of why: the alternative to auditing is trusting that citability means what it claims to mean, and we now have a documented case of a sanctioned propaganda front proving that it doesn't.
The throughline
Optimizing for citation and measuring representation are not the same discipline, and this report is the clearest evidence yet of why the difference matters beyond marketing. One discipline asks whether a model mentions you. The other asks whether what it says, once it does, is accurate, consistent, and actually yours. A Wagner-linked propaganda operation just showed that the first discipline can be gamed by anyone willing to learn the mechanics. The second one is what's left standing when it can.
Sources: CASM (Centre for the Analysis of Social Media, Demos), "GEO for Geopolitics"; reporting by Euronews and The Times, July 2026.