Trellner Research published an analysis on Tuesday documenting what appears to be the first large-scale infrastructure built specifically to game AI citation systems rather than traditional search engines. Analysing 7,534 Perplexity citations across 380 software categories, the researchers found that nearly 60 per cent of cited sources ranked outside the top 100,000 websites globally — a distribution that would be anomalous in any traditional authority-based ranking system.
The core finding concerns three interconnected domains — worldmetrics.org, wifitalents.com, and gitnux.org — that collectively published 215,128 generated "best software" listicle pages between December 2023 and mid-2024. The three domains share identical NameCheap registration, Cloudflare nameservers, and page templates. A fourth site, guideflow.com, ranked as Perplexity's third-most cited source overall with 194 citations — ahead of Gartner — despite being a vendor marketing blog publishing content across 96 categories in which it has no operational expertise. Twenty-three per cent of citations point to completely unranked domains; 16.6 per cent of unranked sources were first archived in 2025 or later, suggesting content created specifically for AI ingestion after observing which types of pages AI systems retrieve.
The tell in the source architecture is the meta description pattern. Pages on these domains describe themselves as "Facts & Grounding Page" in their metadata — language that appears designed not for human readers navigating search results but for AI retrieval systems parsing page-level signals. It is the meta-tag equivalent of writing a cover letter to a screening algorithm rather than a human recruiter.
The implications extend beyond Perplexity. Perplexity is the named system because it was the one studied, and because its RAG-based architecture retrieves from the open web in ways that make it susceptible to this kind of source gaming. The vulnerability is architectural, not specific to Perplexity: any AI system that retrieves from the open web without robust authority signals will face this attack surface. The difference between traditional search spam and what Trellner documented is the sophistication of the targeting. These pages were not built to rank in Google — the domains have no traditional SEO value. They were built to rank in the specific format that AI retrieval systems reward: structured listicles with clear entity mentions, in categories where no single authoritative source dominates, with meta-level signals designed for machine parsing.
The GEO strategy implication is direct and uncomfortable: the citation environment that legitimate brands are investing in optimising is also being gamed by synthetic infrastructure specifically designed to displace authoritative sources. The CLS metric framework — provider diversity, semantic breadth, late citation share — is a legitimate defence against this dynamic, because synthetic pages built for AI citation tend to exhibit high spike patterns and low provider diversity. But the volume of synthetic content entering the AI citation ecosystem is now large enough that practitioner awareness of the threat, and AI provider responses to it, will define the reliability of AI citations as a marketing channel over the next 12 to 18 months.