You can tell whether an AI visibility agency is legitimate mostly from things it published before you ever contacted it: a method written down where anyone can read it, numbers that arrive with dates and denominators, promises bounded by what a supplier can actually control, and a stated rule for where the claims under your name come from. Four habits, all of them checkable from a chair on a Tuesday night. None of them require you to understand how a language model assembles an answer.
This is a strange purchase to have landed on your desk. You have hired accountants, contractors and an SEO agency, and each of those came with something to check. A license. A reference. A rank tracker, and a bill you could argue with. Here the deliverable is a change in what a machine says about you. That does not hold up to the light.
So the instinct to feel underqualified is understandable. It is also wrong. You are not being asked to evaluate a technology. You are being asked to evaluate whether a supplier tells the truth under pressure, which is a judgment you have made a hundred times. The evidence is unusually public here, because a serious operator has to publish the standard it wants to be held to. The other kind has reasons not to.
One disclosure before the checklist. Probably Genius sells AI visibility work, so we are not a neutral referee here, and every test below is one you should run on us as readily as on anyone else. What follows is the legitimacy question specifically: the tells that separate an operator from a performance. If you want the shape of the engagement itself, what a month contains and what to ask in the room, that lives in what to expect before you hire AI visibility help.
The Vetting Happens Before the Meeting
Start with the structural fact that makes this feel harder than it is. Nobody licenses AI visibility work. There is no board, no examination, no register you can search, and nobody can be struck off for practicing it badly. The service arrived faster than any standard of care did. That is why the category feels like the Wild West even when the person across the table is entirely sincere.
What exists instead of a license is a trail. Almost every operator in this category has a public surface: pages describing what they do, articles arguing for their approach, a services page stating what a client gets. That surface was written before you were a prospect, without knowing which questions you would bring. It is an unprompted sample of their judgment. Reading it costs an hour.
It works as a filter because publishing is expensive for the wrong kind of operator. Words on a page can be checked. A written method can be quoted back at you when the results are thin. A stated standard can be measured against the work. Both are commitments. A defined boundary forecloses a sale that a vaguer boundary would have allowed. Everything a legitimate supplier publishes makes its own life harder, which is exactly why the publishing counts as evidence.
So run the first pass before you book anything. Look for four things on their site: how the work is done, what gets measured, what has to be true before something ships under a client's name, and what they will not promise. Four answers, four pages, no meeting required. A category with no license still leaves a trail, and the trail is public.
Tell One: A Method You Can Actually Read
The first tell is the difference between a method that is proprietary and a method that is merely unavailable. Those get confused constantly, usually on purpose. A recipe can stay the chef's while the ingredients are still printed on the box. That is roughly the standard to hold here. The workflow can be theirs. The rules should be yours to read.
Secret sauce is the polite name for the alternative. It sounds like confidence. It works like a shield, because a process nobody can describe is a process nobody can be held to. Watch for the version dressed as sophistication: a proprietary score with no stated inputs, an algorithm nobody will characterize, a framework that appears in a deck and nowhere on the internet. If the only place a method exists is a slide, the method is a slide.
Pay particular attention to the language of proof, because it carries legal weight most buyers do not realize. The FTC's long-standing policy on advertising substantiation says an advertiser needs a reasonable basis for objective claims before making them. It goes further on stated levels of support. When an ad expressly claims one, in phrases like "tests prove" or "studies show," the firm is expected to have at least that level of substantiation in hand. So "our proven method" and "data-backed process" are not decoration. They read as statements about the level of proof behind the service. It is fair to ask what the tests were.
Ours is published for the same reason we would want a supplier's published to us. The six methodology pages on this site set out how the work is done, and the methodology hub is where they start. You do not have to adopt anybody's method. You do need to read one. In public, before you pay for it.
Tell Two: How They Talk About Numbers
The second tell is the most reliable of the four, because it is difficult to fake for long. Legitimate measurement in this category sounds less certain than the pitch a buyer expects. That is because AI answers vary. Ask the same buyer question twice and the names can change, which repeated testing in this field keeps confirming. That is normal. Reporting that hides the instability is hiding the main fact about the thing it reports.
Which is why fake precision deserves more suspicion than obvious hype. A slide reading "37.2 percent AI visibility" tells you nothing without its denominator: which questions were asked, on which engines, on which dates, how many times each, and how the percentage was calculated. A number without a denominator is a mood. A qualified range with its conditions attached is a measurement, and it is the less impressive-looking of the two.
The platforms say as much about themselves, which makes a provider's framing easy to check against the source. Microsoft opened AI Performance reporting in Bing Webmaster Tools as a public preview on February 10, 2026. It stated directly that the aggregated citation data does not indicate ranking, authority or the role of any page within an individual answer, and that page-level citation counts reflect how often pages are cited, not page importance, ranking or placement. Read that carefully, because it is the closest thing to an official statement on the point. Citation counts are not a position. A share of answers across a stated panel of questions is a real thing to report; a rank inside an assistant's reply is not, because no assistant publishes one.
Three questions sort most reports quickly, and all three have plain right answers.
- Can I see the raw answers behind last month's chart, with dates? Preserved text can be compared against next month's run. A chart on its own asks you to trust the chart.
- Name the engine, the mode and the date. A provider who says "AI said" without naming the assistant and the date is generalizing from one product to a market of several.
- Ask how many questions, and how many runs each. One screenshot is an anecdote. The honest form of the number, and how to read one, is the whole subject of measuring whether AI visibility work is actually working.
None of this asks you to become a statistician. It asks you to notice one thing: whether the confidence in the room survives a follow-up question.
Tell Three: Where the Words Under Your Name Come From
The third tell concerns the part of this work that carries the most risk to you, and it is the one buyers ask about last. Almost every provider in this category will publish material under your name. That material becomes the public record of your expertise, quotable by every machine that looks you up. It outlasts the invoice.
So the question is not whether they use AI to help write it. Many do, ours included, and used well it is an excellent instrument. The question is narrower. What rule governs a sentence that cannot be sourced? A fluent draft will happily invent a credential, a case detail or a statistic that sounds exactly like something you would say. A proofreader is no defense against that, because the invented sentence is usually the one that reads best.
Ask the provenance question directly and listen for a rule rather than an adjective. Where does each claim come from, who confirms the ones only you can confirm, and what happens when a fact cannot be traced? "We are very careful" is not an answer. "It does not ship" is. The reasoning behind that standard, and what governed publishing looks like in practice, is set out in how to stop AI content from inventing your expertise.
The useful follow-up is to ask for a threshold with a number on it. Ours is a scored gate: every piece is scored 0 to 100 through the Integrity Gate, and nothing publishes under 80. You are welcome to disagree with the number. What you should not accept is the absence of one, because a standard nobody wrote down is a standard nobody can miss.
The Patterns Already Written Down as Violations
Here is the part almost nobody tells buyers, and it quietly changes the balance of power in a sales meeting. This category has no license. A large slice of the conduct question has still been written down, by a party with no service to sell you, and you can read it in ten minutes.
Google publishes third-party policies for any agency managing a client's Business Profile, and they are unusually blunt. Guaranteeing top placement is prohibited outright. So is representing a free Google product as a pay-for-insertion product, making excessive cold calls, putting undue pressure on a customer to sign up or stay, threatening that a client will lose its profile, and keeping a profile hostage in exchange for money. Each of those is a real practice, specific enough that somebody clearly had to write it down.
The ownership rules in the same document are the ones worth quoting to a prospective supplier. End customers must retain ownership or co-ownership of their Business Profile at all times. A client must have a quick and easy way to end the service. Within seven business days of notice, the third party has to let them disassociate the account and regain exclusive control. If a management fee is charged, the customer must be told in writing that the profile itself is provided at no extra cost.
Read that as a floor. Then apply the same shape to everything else on the table. Who owns the domain, the analytics, the content and the accounts during the engagement, and who owns them the week after it ends? An operator building an asset says yes without flinching. An operator building a dependency starts explaining.
The federal picture points the same way for the ugliest version of this. The FTC's Operation AI Comply sweep, announced on September 25, 2024, brought cases against firms using AI to supercharge deceptive schemes, including one selling a tool that let customers create fake reviews. As the Commission put it, there is no AI exemption from the laws on the books. So a provider offering to generate reviews for you is not offering a shortcut. It is offering a practice the Commission has already brought cases about, and the reviews would be published under your business's name rather than theirs.
What Legitimate Sounds Like When It Is Boring
Put the four tells together and a pattern shows up that is almost disappointing in person. The legitimate pitch is the quieter one. Boring, even. It names what can be built and measured, declines to promise the part that belongs to the model, and hands you more homework than a guarantee would.
The boundary is the clearest single marker. The defensible promise is readiness rather than causation: a supplier can make your business easier to verify, trust and recommend, then measure what happens against the same questions each month. Nobody outside the model companies controls the sentence an assistant produces. A provider who volunteers that limit before you press for it has shown you how they will behave in month nine, when something has not moved and there is a report to write.
Notice too that none of these tells are about size, price or polish. A small operator with a published method, honest denominators and a written provenance rule is a safer purchase than a large one with a proprietary score and a confident quarterly deck. Judge the habits. The habits are what you are actually buying, and they are the part that leaves a trail.
If this whole question arrived because your current SEO agency said they handle the AI work, start there rather than with a new supplier. Mapping what your incumbent already covers is a cheaper first move than hiring anyone, and we walked through that conversation in detail. Once you do get to proposals, the inventory of what a real program actually delivers each month sits in what you receive from a done-for-you program.