Google SAFE (Scaled Abuse Forensics Examiner) is a four-agent AI system Google uses to investigate networks of channels that mass-produce low-quality AI content, commonly called AI slop. In late September 2026, Search Engine Journal reported that Google had deployed the system, just as the September 2026 Google Search spam update began rolling out on 24 September. Several commentators quickly tied the two together, as if Google had gained a new AI-content detector for websites.
TOS read the original Google research paper, and the key point is this: SAFE was built to investigate YouTube channels, not to score websites in Google Search. That said, the way SAFE identifies AI slop reveals a great deal about how Google thinks about AI-generated content. Any business using AI to produce content should understand it.
In short:
- What Google SAFE is: a multi-agent AI system that helps human investigators examine clusters of YouTube channels suspected of coordinated AI slop distribution.
- Is it live: the paper mentions “initial deployment results” but publishes no specific figures.
- Does it affect websites: the source document never mentions Google Search, websites or rankings.
- What websites should watch: Google Search’s policy on producing content at scale to manipulate rankings (scaled content abuse).
What is Google SAFE?
Google SAFE is a multi-agent system. Rather than handing everything to one model, it splits the investigation across several AI agents: each handles one class of evidence, and a coordinating agent assembles the findings into a conclusion. The goal is to automate investigative work that analysts previously did by hand.
The system is described in the paper “The Synthetic Gap: Automating Forensic Investigation of ‘AI Slop’ with the Scaled Abuse Forensics Examiner (SAFE)”, written by seven Google authors. The document runs to just three pages; the PDF on Google Research’s repository carries a creation date of 28 May 2026.
How Google defines AI slop
According to the authors, AI slop is mass-produced, low-quality AI-generated content released in high volume to overwhelm a platform’s review systems. These campaigns typically use a coordinated network of accounts, each posting a slightly different variation. Because the videos are not identical, duplicate filters struggle to catch them, yet the accounts’ behaviour gives away a great deal.
The authors call the lag between a new AI content technique appearing and a platform’s ability to respond the “synthetic gap”. Manual investigation cannot keep pace with these campaigns, and SAFE exists to close that gap.
A real example: YouTube’s policies point the same way. On 15 July 2025, YouTube renamed the “repetitious content” policy in the YouTube Partner Program to “inauthentic content”, making clear that mass-produced or repetitive video does not qualify for monetisation (YouTube channel monetisation policies). Policy draws the line; systems like SAFE find the networks crossing it at scale.
How does Google SAFE investigate a channel cluster?
Google SAFE takes a suspected group of channels as input. The root agent assigns work to three specialist agents, each using its own tools to pull channel data, account behaviour and video content. The output is a verdict plus an investigation report for a human analyst.

Traditional classifiers usually return a single probability score. Google SAFE behaves more like an investigator: it gathers several kinds of evidence, cross-references them, then explains why a cluster looks coordinated. Dividing work across agents this way is the multi-agent pattern increasingly used in AI products.
Root agent
This is the system’s brain. It receives the cluster under investigation, assigns work to the other three agents, checks what they return, then combines the evidence to answer one question: is this a coordinated AI content campaign, or normal activity?
Content analysis agent
This agent separates seriously produced AI content from mass-produced slop, and identifies prohibited categories of AI content. It uses two large language models:
- An LLM fine-tuned with LoRA to catch known policy violations precisely.
- A few-shot LLM that recognises content which breaks no explicit rule but runs against the policy’s intent, including material that slipped past the first model.
It also compares the visuals, audio and speech of videos across channels using embeddings, looking for traces of the same production line, particularly slop scripts repeated in many places. The result indicates whether content is genuine or AI-generated, which abuse category applies (impersonation, for example) and where current policy still has gaps.
Behaviour analysis agent
This agent looks at when and from where channels operate, hunting for signs of coordination. It checks whether channels share network infrastructure (ASN) or device fingerprints, and looks for unusual patterns such as simultaneous uploads or burst publishing.
A real example: the paper gives a sample finding this agent might produce: “100% of the channels use the same operating-system version and uploaded within the same 5-second window.” Independent creators almost never align that closely, so this is strong evidence of a single operator behind the cluster.
Channel network analysis agent
This agent uses graph data on the relationships between channels to map connections and find shared infrastructure. That lets the investigation cover an entire network rather than handling channels one at a time.
Getting it right: Google SAFE does not score your website
Search Engine Journal’s headline, “Google Has Deployed A New AI Spam Detector Called SAFE”, is not wrong, but it is easy for SEOs to misread. Compared with the source document:
| Question | What the paper says |
|---|---|
| What data does SAFE analyse? | Channel cluster data. The architecture diagram names the sources as “YT Channel signals”, “YT Channel Connections” and video metadata. |
| Is SAFE connected to Google Search? | The paper never mentions Google Search, websites or rankings. It does not even use the word “spam”. |
| Has SAFE been deployed? | Yes. The abstract refers to “initial deployment results”. |
| How effective is it? | Not disclosed. The evaluation section only lists the metrics to be used: agreement with human analysts, new abuse trends surfaced, and reduction in handling time. |
| What is the human role? | SAFE supports human investigators. Even when the evidence is inconclusive, its report helps analysts work faster. |
In other words, Google SAFE is a YouTube trust-and-safety tool, not a Google Search ranking signal. Linking SAFE to Google Search spam updates remains speculation.
Google SAFE and the 2026 spam updates: a timeline
A real example: by the end of September, Google had released four spam updates in 2026: in March, June, August (18–21 August, running 2 days 16 hours) and September (starting 24 September, potentially lasting up to two weeks). SEO specialist Glenn Gabe noted that the SAFE paper dates from late May 2026, before both the August and September updates. Even so, Google has not said what role, if any, SAFE plays in Google Search. If your site moved sharply during the September 2026 update, look for the cause in Google Search’s spam policies rather than attributing it to SAFE.
Which rules apply to websites using AI content?
For websites, the relevant rules are Google Search’s spam policies. The most directly relevant is scaled content abuse. Google does not penalise the use of AI. What it acts on is content produced at scale primarily to manipulate rankings without adding value for readers, whether written by AI, by people, or by both.
Google has held this position since February 2023, in its guidance on AI-generated content: using AI or automation appropriately does not violate Google’s guidelines; using them primarily to manipulate rankings does.
What counts as scaled content abuse
Under the policy, typical behaviours include:
- Using generative AI tools to produce many pages without adding value for users.
- Scraping feeds, search results or other sites’ content to generate pages at scale.
- Stitching together content from several pages without adding value.
- Creating multiple sites to disguise scaled content production.
A real example: when Google announced the March 2024 core update alongside three new spam policies (scaled content abuse, site reputation abuse and expired domain abuse), it expected a 40% reduction in low-quality, unoriginal content in search results. On completion, Google reported the actual figure was 45% (Google’s announcement).
What SAFE and Google Search policy have in common
Different platforms, but the same target behaviour:
| What SAFE looks for on YouTube | The equivalent under Google Search policy |
|---|---|
| The same slop script appearing across many channels | Many pages built from one template without added value |
| Channel networks sharing infrastructure | Creating multiple sites to disguise scaled content production |
| Content that runs against the intent of policy | Google weighs the purpose behind content, not just the tool used to make it |
One caveat: burst publishing is a signal SAFE uses when assessing YouTube channel clusters. Google has not stated that publishing frequency is a spam signal for websites; what matters is the value of each page.
A tool from TOS
How often does AI mention your brand?
That number is not in Google Analytics or Search Console. Enter a domain in AI Visibility Check to see how ChatGPT, Gemini and Perplexity cite the brand, next to three competitors in the same industry.
Score your AI presenceFree, no account required.
What should businesses using AI for content do?
Treat AI as a support tool; accountability, facts and lived experience must come from people. These five principles keep a site safe through spam updates while making it easier for AI tools to cite.
- Make it clear who is accountable. Every article needs a real author with a bio and relevant expertise; in-depth pieces should add a reviewer. In its guidance on creating helpful, reliable content, Google encourages being clear about who wrote the content, how, and why.
- Add what AI cannot invent. Your own data, client case studies, real screenshots, lessons from delivered projects: that is the Experience in E-E-A-T.
- Do not clone one template across hundreds of pages. Auto-generated location, product or keyword pages are only safe when each carries its own data. Hundreds of near-identical pages are exactly what the scaled content policy targets.
- Verify every figure and cite the original source. AI can produce wrong numbers, or invent them outright, so check against official documents and primary research.
- Avoid building satellite networks. Multiple sites or channels sharing infrastructure and content to occupy search results is what both SAFE and Google Search policy target.
Monitoring your site during a spam update
Whenever Google announces a spam update, work through this sequence:
- Check the start and completion dates on the Google Search Status Dashboard.
- In Google Search Console, open Security & Manual Actions, then Manual actions, to confirm the site has no manual penalty.
- Once the update has completed, open the Performance report and compare two equal-length periods: before the start date and after the completion date.
- Filter by page to find the content groups that declined, then review that group against the five principles above.
Lessons from CNET and Sports Illustrated
A real example: two cases in US media show the cost of being opaque about AI. From November 2022, CNET quietly published 77 financial explainer articles written by an AI tool, credited collectively to “CNET Money Staff”. When errors surfaced, the newsroom had to review the set and issue corrections on 41 of them (CNN).
In November 2023, Futurism found Sports Illustrated publishing product reviews under “authors” such as Drew Ortiz, whose headshots were on sale on a site selling AI-generated portraits. Sports Illustrated said the content came from partner AdVon Commerce, which had assured it the work was human-written, but the magazine removed the articles and the associated author profiles (CNN).
By contrast, Healthline names the medical reviewer directly beneath the headline on health articles, a transparency practice many reputable health sites follow.
If you publish AI-assisted video on YouTube
YouTube is where Google SAFE has direct effect. Even so, SAFE targets clusters of channels coordinating AI slop distribution, not a brand channel using AI to make worthwhile video. To stay clear of the slop category, businesses should:
- Build one brand channel rather than several satellite channels posting near-identical videos.
- Avoid running many channels from shared accounts, devices and infrastructure, since that is precisely what the behaviour and network agents look for.
- Ensure every video carries its own angle, data or experience, rather than one script with a few details swapped.
- Turn on disclosure when a video contains AI-generated or edited material that looks real.
If you are starting out on YouTube, our guide to creating YouTube content will help you plan properly.
A real example: since March 2024, YouTube has required creators to disclose synthetic or altered content when it looks realistic and could mislead viewers, such as cloned voices, face swaps or reconstructions of events that never happened. When a creator discloses, YouTube adds the label automatically. Using AI to draft scripts, generate ideas or produce automatic captions needs no disclosure.
Frequently asked questions about Google SAFE
Does Google SAFE affect website rankings in Google Search?
There is no evidence that it does. The paper describes SAFE as a system for investigating YouTube channel clusters and never mentions Google Search, websites or rankings. For websites, the rules that apply are Google Search’s spam policies, particularly scaled content abuse.
Does Google penalise AI-written content?
No, provided the content is genuinely useful to readers. Google acts on content produced at scale primarily to manipulate rankings without adding value, whether written by AI or by people.
How does Google SAFE detect AI slop?
It combines three classes of evidence: content (LLMs detecting known violations, content against policy intent, and slop scripts shared across channels), behaviour (network infrastructure, devices, synchronised upload times) and the relationships between channels. The root agent assembles this evidence to decide whether the activity is a coordinated campaign or normal.
How do I tell whether the September 2026 spam update affected my site?
First check Manual actions in Google Search Console to rule out a manual penalty. Once the Google Search Status Dashboard reports the update complete, compare clicks and impressions across two equal-length periods before and after, then filter by page to find the content groups that declined.
Will a YouTube channel using AI be caught by Google SAFE?
According to the paper, SAFE targets clusters of channels coordinating AI slop distribution, based on signals such as shared infrastructure, synchronised uploads and repeated scripts. A brand channel using AI to make video with its own value, disclosed correctly, is not what the paper describes.
What Google SAFE tells businesses
Google SAFE shows that Google is not hunting for “words written by AI”. What it looks for are the signatures of mass production, coordination and content without value, on YouTube as in Google Search. Content with a named expert behind it, verified figures and real experience is both safe through spam updates and the kind of material AI tools prefer to cite. That is the same principle TOS applies when delivering GEO work for clients.
Is your business using AI to produce content? The TOS team can review your site against Google’s spam policies and GEO signals, and identify the page groups that need more value before the next update.
Sources:
- Google: The Synthetic Gap: Automating Forensic Investigation of “AI Slop” with the Scaled Abuse Forensics Examiner (SAFE) (PDF, 2026)
- Search Engine Journal: Google Has Deployed A New AI Spam Detector Called SAFE
- Google Search Central: Spam policies for Google web search
- Google Search Central: Google Search’s guidance about AI-generated content (February 2023)
- Google: New updates to address spam and low-quality results (March 2024)
- YouTube Help: YouTube channel monetisation policies
- YouTube Help: Disclosing altered or synthetic content
Get fresh SEO & AI insights — every day
Curated, practical, no spam. Join marketers who read TOS first.