Claude Penland

By Claude Penland - marketing and business strategy for companies that are good at what they do and hard to find.

Your Compliance Department Is Your AI Search Problem

A negotiation guide for the meeting you are about to have with your own lawyer.

When you were seven you wanted to be an astronaut or a fireman. So did the person across the table in that review meeting. One of you grew up to write marketing copy. The other grew up to be the fireman, and the fireman’s job is to look at your beautiful new page and ask what happens when it catches. Hold that thought. The astronaut comes back at the end, and the astronaut wins you the argument.

PART ONE: THE PROBLEM, STATED PLAINLY

1. What is the problem in one sentence?

The strongest lever in AI search is specificity, and specificity is exactly what your reviewer is trained to delete. Real numbers, named humans, dated claims, hard percentages. Those four make a passage retrievable. They are also four substantiation obligations, so out they go, and you ship a page that survives audit forever and gets skipped by every retrieval system on earth.

2. How much does specificity actually move the needle?

The foundational study is GEO: Generative Engine Optimization (Princeton, Georgia Tech, Allen Institute for AI, IIT Delhi) at ACM KDD 2024. GEO-bench ran 10,000 queries across 25 domains, fed the top five Google results to a generator, and rewrote one source nine ways. The metric is share of the answer attributed to you, discounted the lower down you appear. Five sources, so neutral is 19.3.

Table 1. What each rewrite did to a source’s share of the AI answer.  GEO-bench, 10,000 queries, 5 seeds. Aggarwal et al., KDD ’24, Tables 1 and 3.

Rewrite applied to the pageAnswer sharevs. baselineSubjective impressionWhere it worked best
No optimization (baseline)19.3โ€”19.3Reference condition
Keyword stuffing (classic SEO)17.7โˆ’8.3%20.2Nowhere. It went backwards.
Easy-to-understand22.0+14.0%20.5General explainers
Authoritative tone21.3+10.4%22.9Debate, history, science
Fluency optimization24.7+28.0%21.9Business, science, HEALTH
Cite sources24.6+27.5%21.9Facts, LAW & GOVERNMENT
Statistics addition25.2+30.6%23.7LAW & GOVERNMENT, debate
Quotation addition27.2+40.9%24.7People & society, explanation

Read the last column again. The three tactics regulated marketers find hardest to approve are the three that won, and the best domain for Statistics Addition was Law & Government. Retrieval systems are hungriest for hard numbers exactly where hard numbers are hardest to publish. Two more for the meeting: on live Perplexity, adding statistics lifted subjective impression from 24.7 to 33.9, a 37% gain, while keyword stuffing scored 10% worse than doing nothing. And it favors the underdog. A source sitting at rank five gained 115.1% from citing sources and 97.9% from adding statistics, while the rank-one source lost 30.3%.

3. Before I quote 40% at my general counsel, is that number honest?

Not as usually stated, and you need to know that first. A July 2026 survey of 45 GEO studies is blunt: the 40% is a relative gain on one metric, on a source already placed in the context window. It says nothing about getting retrieved at all.

Table 2. The honest version of the evidence, with the caveats your reviewer will find anyway.  Via Martinez, A Critical Survey of GEO 2023-2026, arXiv:2607.14035.

Study and scaleWhat it foundWhat that means in the meeting
Puerto et al. 2025, C-SEO Bench: 6 domains, ~1,900 queries, 16,360 documentsOnly 3 of 54 method-and-domain combinations were significantly positive. None in question answering.Do not promise a universal lift. Promise a tested lift in your own vertical.
Kim et al. 2026, SAGEO Arena: 171,003 documents, 2,700 queriesBody-only rewrites cut top-20 retrieval ~9% and post-rerank top-10 by 16%, even while helping citation.A rewrite can win the citation and lose the retrieval. Measure both stages separately.
Vishwakarma et al. 2026: 252,000 trials, 6 LLMs, 18 factorsRelevance and position dominate. Explicit prices and recent dates show real effects. Formatting alone is weak.Dates and numbers are the durable part. Pretty formatting is not the win.
Liu et al. 2023: four generative engines auditedOnly 51.5% of sentences were fully supported; 74.5% of citations actually supported their claim.Being cited is not being cited correctly. Naming that risk first buys you credibility.

Walk in with the marketing-blog version of that 40% and counsel finds the footnote in ninety seconds, and you lose the room for a year.

4. Then why fight this fight at all?

Because the traffic math went from uncomfortable to structural. Pew Research Center tracked 900 US adults across 68,879 searches in March 2025. 58% hit an AI summary. When one appeared they clicked a traditional result 8% of the time, versus 15% without, a 47% relative collapse. Clicks on links inside the summary: 1%. Ahrefs put position-one click-through down 34.5% with an AI Overview in April 2025 and 58% by February 2026. SparkToro found fewer than a third of Google searches now send a click anywhere.

Here is the number that flips you from defense to offense. Seer Interactive found brands cited inside an AI Overview earn 35% more organic clicks and 91% more paid clicks on the same query. Citation is a multiplier on media you already pay for.

PART TWO: WHY YOUR INDUSTRY, SPECIFICALLY

5. Show me what the compliance edit does to a sentence.

Table 3. Four real review edits and what each one costs at retrieval.  Every edit is one a working reviewer would defend.

What marketing wroteWhat came back from reviewWhat was actually deleted
โ€œMedian claim settles in 11 days.โ€โ€œClaims are typically resolved promptly.โ€The only extractable number on the page. โ€œPromptlyโ€ matches no query anyone types.
โ€œDr. Elena Marsh, board-certified in nephrology, reviewed this page on March 4, 2026.โ€โ€œReviewed by our clinical team.โ€A named human and a date. Load-bearing trust signals, and both cheap to substantiate.
โ€œOur 2025 book was 38% commercial auto, 22% general liability.โ€โ€œWe write a diversified book across commercial lines.โ€Aggregated operational data you already file with a regulator. Zero forward-looking risk.
โ€œCited in Journal of Risk & Insurance, 2024, Vol. 91, pp. 412-438.โ€โ€œSupported by peer-reviewed research.โ€A third-party citation, the lever that lifted a rank-five source by 115%.

Not one of those edits reduced a real regulatory exposure. Each swapped a verifiable historical fact for an unverifiable adjective. That is the whole pathology, and most reviewers recognize it the moment you say it out loud, because it is not what they were trained to do.

6. Is my regulator genuinely getting more aggressive?

Table 4. The enforcement environment your reviewer is actually reacting to.  Sources: King & Spalding FDA 2025 Year in Review; FINRA 2025 Industry Snapshot; SEC risk alerts.

RegulatorWhat changedThe number
FDA, Office of Prescription Drug PromotionFive letters a year became a flood inside one week of September 2025.5 letters in 2023 and 5 in 2024. Over 200 in 2025, including 74 to drug and biologic makers (10 Warning, 64 Untitled).
FINRA, Advertising RegulationFiling volume jumped after four flat years. Web content is now the largest category.63,046 filings in 2020 to 71,875 in 2024, up 13.0% in one year. 30,533 of those (42.5%) were public-access web content.
SEC, Division of ExaminationsThree Marketing Rule risk alerts in thirty months, plus sweeps on hypothetical performance.Risk alerts June 2023, April 2024, December 2025. Five advisers settled April 2024, nine more September 2024.
FINRA, influencer supervisionPaid promotion without review became a named enforcement theme.M1 Finance fined $850,000 in March 2024. Public.com fined $350,000 for paying 110+ promoters.

Your reviewer is not being difficult. Your reviewer read the September 2025 news and concluded, reasonably, that the safest page is the emptiest one. A Comply survey found 44% of compliance leaders name marketing oversight a top exam-day concern and 15% say it eats more time than any other compliance task. In pharma, promotional review commonly runs 50 to 60 days per item. You are asking an overloaded person to take on more work.

7. How much AI exposure does my vertical have right now?

Table 5. AI Overview coverage by query type across the three biggest regulated verticals.  BrightEdge 18-month tracking, via Search Engine Land YMYL analysis, June 2026.

Vertical and query typeMay 2024Dec 2025ChangeTop-10 overlap
Health: conditions and symptoms82%93%+11 pp24.0%
Health: general education50%74%+24 pp24.0%
Finance: cash management13%79%+66 pp11.3%
Finance: financial planning6%73%+67 pp11.3%
Finance: tax planning0%63%+63 pp11.3%
Finance: credit and debt5%62%+57 pp11.3%
Finance: stock tickers (real-time)โ€”8%flat11.3%
Insurance: all query typesโ€”โ€”โ€”22.4%

Tax planning went from zero to 63% in nineteen months. But the column that matters is the last one. Top-10 overlap is the share of AI citations that also rank on organic page one. In finance it is 11.3%, so 88.7% of finance citations come from somewhere other than the results you spent a decade optimizing, and BrightEdge found 65.7% come from pages ranking nowhere in the top 100. An audit of 4,706 queries by Kirsten et al. found 53% of AI Overview domains absent from the organic top 10 entirely. Your existing rank is not protecting you.

PART THREE: THE NEGOTIATION

8. What do I actually put on the table?

Do not ask permission to be specific. Ask for standing pre-clearance on four defined classes of claim where the substantiation already exists somewhere in the building. That reframes the ask from โ€œtrust meโ€ to โ€œstop re-litigating facts we already proved.โ€

Table 6. The four claim classes to negotiate, ranked by how easily they get approved.  All four are specific about the past rather than suggestive about the future.

Claim classWhy counsel can defend itWhat to hand them
Aggregated operational dataHistorical, internal, auditable, often already filed. No forward-looking promise attached.Source system, the query, refresh cadence, and exact wording of the period qualifier.
Published methodologyYou disclose how you calculate, not what a customer gets. Disclosure is the regulator’s own preferred remedy.A standing methodology page with a version number and last-updated date, linked from every claim using it.
Cited third-party researchLiability sits with the publisher. You are quoting, not asserting.Full citation, DOI, access date, and one line on what the study does and does not establish.
Dated disclosures and filingsAlready public, already reviewed, already survived a filing process once.A map of each claim to the filing that supports it, with the filing date visible on the page.

9. What is the one legal fact most marketers walk in not knowing?

That the rule often does not say โ€œbe vague.โ€ It says close to the opposite, and the disclaimer is the sanctioned way to keep your number. ABA Model Rule 7.1, Comment 3 states that an appropriate disclaimer or qualifying language may preclude a finding that a statement creates unjustified expectations. The Comment contemplates publishing the result and attaching the qualifier.

Insurance is blunter. The NAIC’s Model 570 is adopted in some form across most states, and Virginia’s version, 14VAC5-41-40(A), requires that disclosed information โ€œshall not be minimized, rendered obscure, or presented in an ambiguous fashion.โ€ Ambiguity is the violation. Softening a claim into mush sits closer to the prohibited thing than the specific claim did. You are not asking counsel to bend. You are showing that the reflex drifted from the text.

10. What do I give up in return?

A negotiation where one side concedes nothing is a request, and requests lose. Offer these before you are asked:

1. Substantiation files, not arguments. Every pre-cleared number gets a one-pager: source system, query, owner, refresh date, expiry date. No file, no publication.

2. Automatic expiry. Every dated claim carries a review date. When it passes, the number reverts or comes down. This is the concession that wins the room, because it converts an open-ended risk into a bounded one.

3. No comparative superlatives, ever. Surrender โ€œbest,โ€ โ€œfastest,โ€ โ€œleadingโ€ permanently. You lose nothing, since those were already invisible to retrieval systems. Trade a worthless asset for a valuable one.

4. Fidelity monitoring. Check quarterly whether AI systems quote you accurately and escalate misattribution. With only 51.5% of generated sentences fully supported, this is a real risk you are volunteering to watch, and it is the most persuasive thing you can offer.

11. How does this run week to week, and what do I measure?

Build a pre-cleared claim library: a versioned registry with an owner, where each entry holds the approved sentence, the substantiation file, the effective date and the expiry date. Report the risk side first every quarter, before a single traffic number. Claims published against claims expired on time. Misattribution incidents found. Files complete versus outstanding. Then show citation rate by engine and the Seer multiplier on paid performance for cited versus uncited queries.

One warning, because someone will raise it if you do not. Visibility is unstable. Kirsten et al. found two-month page overlap in AI Overviews of just 18%, against 45% for organic Google, and Schulte et al. found 57.8% of ChatGPT repetitions did not trigger a web search at all. Measure across repetitions, paraphrases, dates and engines, or you will present noise as a result and lose the room on slide two.

12. And if the answer is still no?

Narrow it to one page and one quarter. One asset, one claim class, most likely aggregated operational data because it frightens people least. Instrument it properly and report risk metrics beside retrieval metrics. Ninety days of clean evidence moves a compliance department further than nine months of argument, because you stop asking them to trust a theory and start handing them a record.

Now the astronaut. NASA is among the most risk-averse institutions ever built, an organization whose entire culture is organized around not killing anyone, and it did not reach the moon by writing that the vehicle performs reliably under most conditions. It got there on published, dated, specific, auditable numbers, reviewed to death and then printed anyway. Precision and caution are not opposites. Precision is what caution looks like when it is done properly, and vagueness is what caution looks like when it has quietly stopped doing the work.

Your reviewer is the fireman, and a fireman is a genuinely good thing to have in the building. But the fireman’s job was never to remove all the furniture. It was to know where the exits are and make sure the sprinklers work. Bring him the sprinkler plan and he will let you put the furniture back.

SOURCES

1. Aggarwal et al., GEO: Generative Engine Optimization, ACM KDD 2024. https://arxiv.org/pdf/2311.09735

2. Martinez, A Critical Survey of Generative Engine Optimization 2023-2026, arXiv:2607.14035. https://arxiv.org/html/2607.14035v1

3. Pew Research Center AI Overviews click analysis, via Search Engine Land, July 2025. https://searchengineland.com/google-ai-overviews-hurting-clicks-study-459434

4. SparkToro, Less than One Third of Searches Still Send a Click, June 2026. sparktoro.com/blog โ†’ one-third-of-google-searches-send-a-click

5. Zero-click statistics aggregation (Ahrefs, Bain, Seer, Semrush), Omnibound, 2026. https://www.omnibound.ai/blog/zero-click-search-statistics

6. Search Engine Land, What gets cited most in health, finance and YMYL in AI Overviews, June 2026. https://searchengineland.com/guide/ai-overviews-ymyl

7. FINRA 2025 Industry Snapshot (advertising filing volumes). https://www.finra.org/sites/default/files/2025-07/2025-Industry-Snapshot.pdf

8. King & Spalding, 2025 Year in Review: FDA Advertising Enforcement. kslaw.com โ†’ 2025 Year in Review: FDA Advertising Enforcement

9. Comply, The SEC’s Marketing Rule Risk Alert, December 2025. https://www.comply.com/resource/sec-marketing-rule-risk-alert/

10. ABA Model Rule 7.1, Comment on Rule 7.1. americanbar.org โ†’ Model Rules โ†’ Rule 7.1 โ†’ Comment

11. Virginia Administrative Code 14VAC5-41-40 (NAIC Model 570). regulations.justia.com โ†’ Virginia โ†’ 14VAC5-41-40

12. SEC Division of Investment Management, Marketing Compliance FAQs. sec.gov โ†’ Staff Guidance โ†’ Marketing Compliance FAQs

13. Sedric, Marketing Review: A Compliance Guide for Regulated Industries, July 2026. https://www.sedric.ai/blog/marketing-review

14. Aprimo, Accelerate Pharma Review Cycles (MLR cycle-time benchmarks), June 2026. https://www.aprimo.com/blog/life-sciences-accelerate-approval-cycles

15. BrightEdge, AI Search Citations: How Much Do They Change Week to Week? brightedge.com โ†’ weekly-ai-search-insights โ†’ citation changes


Discover more from 1000 Startups

Subscribe to get the latest posts sent to your email.

Claude Penland

Claude Penland builds the marketing and business strategy for companies that are good at what they do and hard to find. Thirty years operating, one exit, eight of them as a practicing casualty actuary.

The free two-page read is genuinely free. Email claude@1000startups.com and I'll send back what I can see from the outside. Or see the work samples and how to work with me.

Leave a Reply