The short version
- AI reputation defense is a distinct problem from not being recommended and from a stale fact. Here the model repeats something actively damaging — a defamatory claim, a fake review, a fabricated quote — and cites a source to back it.
- You cannot defend an answer you can only see the surface of. The unit of work is the answer plus the source: the damaging claim, and the specific cited post or domain feeding it.
- There are two levers, and they are different work. A counter publishes authoritative content from your own verified record so the engine has a source to cite instead. A report is a takedown or report-request aimed at the source carrying the false claim.
- The counter is almost always faster and more durable than the report, because it is entirely within your control and it re-weights which source the model trusts — but for defamation, impersonation and synthetic media the report route matters and the evidence has to be preserved.
- The threat is shaped by who you are: false claims and fake reviews for brands, mis-selling and false rate or fee claims for financial firms, misinformation and impersonation for public bodies, defamation and deepfakes for public figures. The method is the same; the levers are tailored.
- Defense is not spin. Every counter is built only from facts you approve — never invented, and never an attack on anyone else. You are defending your own record, not manufacturing a narrative.
Absence is quiet. A damaging answer works against you.
Most of the conversation about AI search is about being left out — the model recommends a competitor and never names you. That is a real loss, and we cover it in AI search for brands. But there is a second, louder failure mode. The model names you, and then repeats something that damages you: a claim you are a scam, a fabricated review, a quote you never said, an allegation lifted from a complaint forum. From the outside it can even look like presence. In practice it is worse than absence, because the model has handed the reader an authoritative reason to avoid you, and you were never in the room to answer it.
The reason this matters more than a simple stale fact is intent and stickiness. A stale price is an honest lag that refreshes when your page does. A damaging claim is often being actively repeated because a source the model trusts keeps saying it. Left alone, it compounds: each engine that reads the same poisoned source repeats the same answer, and the claim hardens into what 'the AI says about you'. Defending against it means treating the answer and its source as a single unit of work.
You will not get a ticket that says 'an AI called us a scam'
The reader simply believes the model, quietly crosses you off, and you never learn why. Damaging answers do not announce themselves — which is exactly why reputation in AI answers has to be actively monitored, not assumed.
Defense starts with the source, not the sentiment
A sentiment score tells you the tone soured. It does not tell you what to do, because it does not tell you why. The actionable unit is not 'sentiment is down 12 points' — it is 'this answer repeats this claim, and here is the cited post or domain feeding it'. An AI assistant composing an answer about you leans on the sources it judges authoritative; a damaging answer survives because a specific source keeps supplying the damaging claim. Find that source and you have something you can act on. Stop at the sentiment number and you have an anxiety, not a plan.
So the first move in reputation defense is to capture the damaging answers verbatim across every engine, and for each one, trace it back to the source it is drawing from — the forum thread, the review-site profile, the syndicated article, the impersonating page. That trace is what turns a vague 'the AI is negative about us' into a short, concrete list of sources to counter or report. Everything downstream depends on it.
Lever one: counter — give the engine a better source to cite
The counter is the workhorse of reputation defense, and it is the one most people underuse. When an engine repeats a damaging claim, the durable fix is usually not to argue with the claim but to publish an authoritative, machine-readable source of truth that the model can cite instead — and to make it clearly the most current, most extractable version available. Models weigh corroboration and authority; when your own official record is the cleanest, best-structured source on the question, it becomes the one the answer converges on.
Crucially, a counter is built only from facts you actually hold and approve. This is not writing a rebuttal or seeding praise — it is publishing your verified record in a form a machine can lift a fact straight out of: plain server-rendered text, structured data, an llms.txt entry, each dated so the current version is unambiguous. For a false 'you don't support X' claim, the counter is the extractable fact that you do. For a fake-review narrative, it is the authoritative record that the engine can weigh against the fabrication. The counter works because it is true, structured and fresh — which is exactly why a model keeps it while it discounts the poisoned source over time.
A counter re-weights trust; it does not shout louder
You are not trying to drown out the damaging source with volume. You are making your own record the cleanest, most authoritative, most machine-readable answer to the exact question — so the model has a better source to prefer. One well-structured canonical page often moves an answer that a dozen blog posts never would.
Lever two: report — when the source itself has to come down
Some damaging content should not merely be out-competed; it should be removed or reported. A defamatory post, a page impersonating your organisation, a fabricated clip or a fake review that breaches a platform's own policies is a candidate for a report or takedown request aimed at the host — the platform, the review site, the search engine, or the channel carrying it. This is the second lever, and it is a different kind of work from the counter: it is a request to a third party, and it has to be evidenced.
That means preserving the material before it changes: the verbatim answer, the source it cited, the URL, the timestamp, and where synthetic media is involved, the original file and its metadata held intact so it stands up on the formal route. A report-request draft assembles that evidence into the shape the recipient expects. The report lever is slower and less certain than the counter — you do not control the outcome — which is why for most damaging claims the counter runs first and in parallel, and the report is reserved for content that is genuinely removable: defamation, impersonation, deepfakes, and clear policy violations.
For public figures in particular, the report route and evidence preservation are the centre of gravity rather than an afterthought — a fabricated quote or a manipulated clip is handled by capturing and preserving it for counsel, not by re-sharing or re-cutting it. We go deeper on that in when AI repeats a fabricated quote.
The threat is shaped by who you are
The method — find the damaging answer, name the source, counter and report — is the same for everyone. What changes is the threat, and therefore what the levers are tuned to.
- Brands face false claims and fake reviews: a defamatory forum post, a fabricated one-star review, a 'they don't do X' claim that costs a shortlist spot. The counter is your verified product record; the report targets the fake review or the false post. See AI search for brands.
- Financial firms (BFSI & fintech) face mis-selling allegations and false rate or fee claims — a 'hidden fee' or 'scam' narrative lifted from a complaint forum. The counter must be a compliance-safe statement drawn only from approved facts and mandated disclosures, never a marketing rebuttal and never advice.
- Public bodies — ministries and government organisations face misinformation and impersonation: an unofficial post spreading a wrong rule, or a page impersonating the department that an engine answers from. The counter is the authoritative official record; the report targets the impersonating page. The vocabulary stays accuracy and evidence — never ranking, never a competitor.
- Public figures and leaders face defamation and deepfakes: a defamatory claim or a fabricated quote the model repeats as fact. The counter is drawn strictly from their own public statements; the report and the preserved evidence drive the takedown. Opponent-neutral by design — it acts on the false source and the figure's own record, never on anyone else.
The loop: measure, trace, counter or report, prove
Reputation defense is not a one-time cleanup; it is a loop you run on a cadence, because damaging sources reappear and new ones surface. The steps are distinct, and skipping any one is where a defense stalls.
- 1Measure. Capture how every engine answers the questions people actually ask about you, verbatim and with the sources each answer cites — the same discipline as measuring AI-search visibility, pointed at damage rather than absence.
- 2Trace. For each damaging answer, identify the specific cited post or domain feeding it. This is the step that turns a sentiment worry into an actionable source list.
- 3Choose the lever. Counter almost always (publish the authoritative record so the engine has a better source), and report where the content is removable (defamation, impersonation, deepfakes, policy-breaching fake reviews), preserving evidence first.
- 4Prove. Re-ask the same questions across the same engines and confirm the damaging answer gives way to the accurate one. A published counter or a filed report is a hypothesis until the answer moves.
2 levers
counter (publish a better source) and report (take the false source down) — different work, run in parallel
The source
not the sentiment score — the unit of reputation defense is the damaging answer plus the exact source feeding it
Re-measure
the only proof a defense landed — a published counter or filed report is a hypothesis until the answer changes
Defense is not spin
The line that keeps reputation defense legitimate — and effective — is that everything you publish is true and yours. A counter is assembled only from facts you approve; it never invents a claim, seeds a fake positive, or attacks the author of the damaging source. There are two reasons this is not merely an ethics footnote. The first is trust: manipulated or fabricated content is what a model eventually learns to discount, so spin does not hold. The second is durability: an authoritative, accurate, well-structured record is the thing an engine keeps citing, which is precisely what you want it to do.
So the goal is not to make the AI say something flattering. It is to make the accurate version of your own record the easiest, cleanest, most current source for the model to reach — and, where a source is genuinely defamatory or impersonating, to get it reported through the proper channel with the evidence intact. Start where the damage is: capture the harmful answers, trace them to their sources, counter the ones you can out-source and report the ones that must come down, then prove the answer moved. For the wider programme, our verified record guide and when AI gets your brand facts wrong lay out the foundations the counter is built on.
You don't win a damaging AI answer by shouting at it. You win it by becoming the more authoritative source — and, where the content is genuinely removable, by reporting it with the evidence intact.