The X spam war previews what’s coming to your GBP
X removed 42,000 AI spam accounts in one sweep. The economic model behind it is coming for the review layer AI search actually reads.
Nikita Bier, head of product at X, spent 24 hours last week live-tweeting the platform's fight against AI-generated spam. Forty-two thousand accounts removed in a single sweep. One spammer who's pivoted methods 40 times in six months. Some of them using Grok — X's own AI — to generate replies at scale. Bier admitted the response is measured in hours now, down from days under the old Twitter, and framed the whole thing as an existential fight for platform authenticity.
Read it as a social media story and it's interesting. Read it as a distribution story and it's a preview.
Every platform where authenticity signals feed into a recommendation or discovery layer is heading into the same war. That includes yours. Reviews. Q&A on your Google Business Profile. Local citations. Reddit threads where your category gets discussed. Comment sections on industry publications where your links live. The infrastructure of trust that AI search actually reads to decide who to cite is being contaminated in real time, and the platforms mediating it are nowhere near ready.
The X story matters because it makes the economics explicit for the first time. Bier said 99.99% of the spam was economically motivated — grifters trying to grow accounts to sell paid promotion deals to AI companies looking to extend their influence. That's the loop. And we built it.
The economic model has flipped
The old spam economy was ideological or crude. Political operations, state actors, blackhat SEO farms churning out link networks. It was ugly but it was legible — you could roughly tell who was doing what and why.
The new spam economy has a cleaner motive: AI companies pay for influence over AI outputs, and the cheapest way to buy influence is to manufacture the signals AI systems use to decide what to trust. Grow an account. Sell access. Or manufacture the ambient noise that makes a brand seem consensus.
Bier's number is the key one. Ninety-nine point nine nine percent economic. Not politics. Not ideology. Money.
That reframes the entire conversation about platform authenticity. When the motive was ideological, platforms could partly rely on the fact that spam was expensive to run at scale and the payoff was diffuse. When the motive is paid promotion offers from well-funded AI companies, the payoff is immediate and the cost of generation has collapsed to near zero. You don't need a bot farm — you need a Grok subscription and a script.
Every platform that ranks or recommends based on engagement signals is now sitting on a pile of money for anyone who can fake those signals convincingly. That includes X. It includes Google. It includes the review layer that AI Overviews and ChatGPT actually read when someone asks who to hire.
Your review layer is next
This is the part the industry keeps not connecting. The review data on Google Business Profile, Trustpilot, Yelp, industry-specific directories, and the long tail of aggregators is the primary trust signal AI search uses when answering "who's the best plumber in Bristol." I've written before that the AI local search story is really a review data story — the data layer AI answers run on is not the layer you think it is.

Now add the X story on top. If economically-motivated actors are already using AI to auto-post at platform scale for the payoff of AI-company promo deals, why on earth would they stop at social? The payoff for gaming reviews is direct: leads, bookings, revenue. The barrier to entry has collapsed. And the platforms that host the reviews are running detection systems built for a slower, cruder era of spam.
Google Business Profile's review moderation was designed to catch obvious things — the same reviewer name across five plumbers, IP addresses from the wrong continent, reviews posted within seconds of each other. It was designed for humans doing bad things at moderate speed. It was not designed for a Grok script generating 400 subtly different, geographically plausible, temporally staggered reviews across a competitor's profile in a week, each one written to trigger authenticity heuristics.
I don't have to speculate about whether this is happening. The economic model has already been proven on X. The technical capability is trivial. The only question is how long before the local search world catches up to what X spent last week trying to survive.
The detection cycle is asymmetric
Here's the part of Bier's thread I keep coming back to. He described one spammer who's pivoted their method 40 times in six months, saying the pivots come so fast it feels like they're sitting inside the codebase. He was half-joking about hiring them. He wasn't joking about the speed.
The attacker moves once. The platform has to move continuously.
The attacker moves once. The platform has to move continuously.
That's the asymmetry. A spam operator generates variants at machine speed and tests them against the platform's live detection. Every time a variant survives, that's the new template. Every time one gets blocked, the next variant ships in hours. The platform, meanwhile, has to design generalised rules that don't false-positive on real users, run them through review cycles, deploy carefully, and monitor for downstream damage.
Even a well-resourced platform with a head of product live-tweeting the fight can only get response times down to 12-18 hours. That's the state of the art. And X is a company where the CEO cares about this problem visibly and personally.
Google Business Profile is not that. The review moderation team is buried inside a division that has bigger organisational problems to solve. Review disputes take weeks. Fake review reports go into a queue with unclear priority. Businesses that lose visibility to a coordinated attack have almost no recourse other than filing tickets and waiting.
What this means if you rely on review signals
If your business's discoverability in AI answers, local pack, or organic maps depends on your review corpus — and if you're a service business, it does — you now have a risk category that didn't exist eighteen months ago. Not "will competitors post a few fake negative reviews" (that risk always existed). The new one is: will a coordinated economic actor decide your category is worth manipulating at scale, on both sides — inflating some businesses, degrading others.
The counter isn't a tool you can buy. It's the same set of unfashionable practices that have always worked in categories where trust is contested:
Build review volume that's high enough and consistent enough that a spike of fakes is statistically obvious. A business with 400 reviews over four years is much harder to poison than one with 12 reviews over the same period.
Diversify the review surface. Google Business Profile matters most, but a business with Trustpilot, industry directory reviews, YouTube testimonials, and case studies on its own site has multiple independent trust signals. AI systems triangulate across these.
Monitor your own review corpus actively. Not annually. Weekly. Know what your baseline distribution looks like — star breakdown, language patterns, review length distribution — so anomalies are visible when they appear.
Build brand mentions off-platform. The X spam problem exists because attention is centralised on one platform where signals are easy to fake. Businesses that show up across podcasts, Reddit discussions, industry publications, and their own owned media are much harder to shift because the signal is distributed across systems no single attacker can flood. This is the same reason I keep coming back to brand mention monitoring as the closest thing GEO has to real measurement — mentions are the input side, and they're the thing AI systems triangulate against.
The platforms are not ready and won't say so
The part of Bier's thread I found genuinely refreshing was the honesty. He named the problem, put a number on the scope, admitted the response time, acknowledged the persistence of individual attackers, and did it all in public. That's not the norm. The norm is platforms pretending everything is fine while the spam load grows quietly in the background.
Google will not tell you when review spam attacks on your category are trending up. Meta will not tell you when your competitor's engagement is being artificially inflated. The directories will not tell you their moderation queues have blown past what their teams can handle. You'll only know because your traffic pattern will start to look strange, or a competitor will start showing up in AI answers where they didn't before, or a client will forward you a screenshot of a review that doesn't match reality.
The infrastructure layer that mediates AI discovery is running on trust signals that were never designed to withstand the current economic pressure to manipulate them. The X story is the first public admission from a major platform that the war is now full-time, expensive, and ongoing.
The honest limits
I'm making a prediction here, and I want to be clear about what it isn't. I'm not claiming coordinated economic review manipulation is already happening at X-scale in local search — I don't have that data and I don't think anyone does yet. I'm claiming the conditions are now in place: the economic incentive, the technical capability, the platform-side detection gap. When those three conditions align, activity follows. Usually faster than the platforms would like.
The counter-argument is that local review manipulation has always existed and platforms have always adapted. Fair. But the previous rounds were bounded by the cost and effort of running the operation. That constraint is gone. When something previously expensive becomes cheap, volume follows.
The other honest caveat: none of the defensive advice above is new. Build review volume, diversify signals, monitor actively, build brand off-platform. This has been sensible advice for years. What's changed is the urgency. The businesses that have been coasting on twelve reviews and hoping for the best are the ones most exposed to the next 18 months.
Close
The X spam story reads like a platform-specific problem. It isn't. It's the first visible skirmish in a much longer war over which signals AI systems can trust when they decide who to recommend, cite, or answer with. Every platform running on user-generated authenticity signals is now defending the same infrastructure against attackers with better economics than they had two years ago.
The businesses that survive this are the ones that treat their trust infrastructure — reviews, mentions, citations, brand references — as an actively defended asset rather than a set-and-forget metric. Bier is doing that work in public at X. Almost nobody is doing it in local search.
You should assume nobody's coming to protect your review corpus. Then act accordingly.
Ready to improve your visibility in AI search?
If you're an SME in Surrey or London and you want more qualified leads from search — including the growing AI answer layer — let's talk.
Book a discovery call