September 2026 Spam Update, Explained

Google's September 2026 spam update is still rolling out. What Google actually confirmed, what the SAFE system is, and how to check if your site was hit.

By Dalin de Graff

On September 24 at 9:15 AM Pacific, Google posted four sentences on its Search Status Dashboard and the SEO industry panicked again. Here is the entire announcement, quoted from Search Engine Land's coverage: "Released the September 2026 spam update, which applies globally and to all languages. The rollout may take up to two weeks to complete."

That was it. No blog post. No target list. No named villain.

Within hours, the takes were everywhere: this is the AI content purge, Google finally banned AI-written pages, your blog is toast. Here is what I am not going to do: tell you which AI tool got you penalized. Google never said it penalized AI content, and nobody outside Google can tell you what this update targets yet. Anyone who says otherwise with certainty is selling you something.

I run content audits the same way for clients at First Rank, where I lead LLM and search work: separate what was confirmed from what was inferred, and grade the two with different confidence.

What Google actually confirmed

The counted facts are short. This is the fourth spam update of 2026, after March, June, and August. The three earlier ones each finished in under three days. This one gets up to two weeks, so rankings will keep moving through early October, and John Mueller confirmed to Search Engine Roundtable that the long window was not a typo. TechDefused has the full breakdown

Two more confirmed details from Search Engine Roundtable: Google would not say what share of queries this affects, and this update does not target link spam. Everything else you have read about this update is inference. Keep that sentence in your pocket. It will save you from most of the panic.

The SAFE story, with the part everyone skips

The loudest inference right now is Google's new AI spam detector, SAFE, the Scaled Abuse Forensics Examiner. It comes from a Google Research paper dated May 28, 2026 about automating forensic investigation of what the paper calls "AI slop." The system uses multiple AI agents to investigate coordinated networks of AI-generated content. TechWyse covered the paper in detail

It is the second such system Google has published about this year. The first, the Scalable Cluster Termination System, terminated 50,000 clusters and 130,000 channels over six months. Google is clearly building serious machinery to find synthetic content produced at scale.

Now the part the panic posts skip: the SAFE paper studies YouTube channel clusters. As TechDefused points out, there is no evidence SAFE is used in Search ranking at all. A research paper circulating during a spam update is a coincidence of timing, not proof of a target. Saying "this update is an AI content ban" is an inference layered on top of Google's silence, not something Google stated. The two should never be quoted with the same confidence.

AI detection orbs scanning clusters of duplicate pages while one original high-quality page glows gold

The one policy that actually matters

If you want one document to read during this update, it is Google's scaled content abuse policy: "many pages generated for the primary purpose of manipulating search rankings and not helping users," applied regardless of how the content is created. The first listed example is using generative AI to generate many pages without adding value for users.

Read that twice, because it is the whole game. The line is not human versus machine. A hand-written content farm with five hundred interchangeable pages is not safe, and an AI-assisted page with real reporting, original data, or expert judgment is not doomed. The trigger is volume plus low value, not the tool.

Google says the same thing in its guidance on generative AI content: automation used to produce helpful, original content is not against policy. Wise Media published a clean summary of the 2026 policy position on September 30 The method is not the violation. The intent and the value are.

This is the same argument I have been making about AI search. In my piece on what generative engine optimization actually is, the through line is that AI surfaces reward pages that add something new, not pages that multiply something old. This update is the enforcement arm of that same idea.

What to actually do this week

First: do not rewrite anything yet. The rollout runs until roughly October 8, and rankings will keep moving while it is open. Daily dips during a rollout are noise, not a diagnosis. Rewriting your homepage on day three of a two-week rollout is how you fix a problem that was never yours.

1. Mark the dates. Open Search Console and mark September 24 on your charts. Any change that started before that date is not this update.

2. Rule out the boring stuff. Confirm your important pages are still indexed. Rule out technical problems and bad deploys before diagnosing content. Every audit I run at First Rank starts here, because the number of "algorithm penalties" that turned out to be a staging noindex is embarrassing.

3. Audit for patterns, not pages. Scaled content abuse is a pattern charge. Look for identical location pages, auto-generated FAQs with no original answers, templates where only the keyword changed. The fix is consolidation and original value, not another plugin.

4. Run the named-person test. Wise Media frames it as a rule: if a named person on your team cannot defend every claim on the page, do not publish it. Apply it to your top fifty pages and you will find your thin content faster than any tool will.

5. Watch the new data. Search Console added a multimodal filter for image-based searches: Google Lens, Circle to Search, image uploads, Chrome's right-click image search. Query data is not available, but it is a new window into how people find you visually. Search Engine Journal has the details

The part nobody wants to hear

Spam updates are not the enemy of legitimate sites. 2026 is the most active year for spam updates since 2021, and every cycle does the same thing: it raises the price of publishing without thinking. If your content strategy is "publish more," this update is a tax on you. If your strategy is "publish better," it is a tailwind.

That is the same argument I made in Rankings Are Not Revenue. Traffic you can defend beats traffic you rent from a loophole. The sites that survive every spam update are boring in the same way: every page earns its place, and someone with a name stands behind every claim.

So here is my quotable close. Google did not ban AI content. It banned the business model of saying nothing at scale. The panic is optional. I will keep tracking this rollout on dalindegraff.com as the data settles.


About the author: Dalin de Graff is an LLM + Search Engine Marketing Specialist at First Rank, where he built the agency's GEO department and trains its SEO team. He writes about SEO, AI search, and profitable e-commerce at dalindegraff.com.

Dalin de Graff

About the author

Dalin de Graff is the LLM + Search Engine Marketing Specialist at First Rank, where he built the agency's Generative Engine Optimization (GEO) department.

About Dalin de Graff ยท Contact